Cyber Insurance Readiness
The cyber-insurance questionnaire, decoded
Carriers stopped taking your word for it. Here's the control-by-control reality of what they now verify — and how to answer each with evidence instead of a promise.
Three years ago a cyber-insurance application was a formality. Today it's an audit — and if what you attest doesn't match what your environment actually does, a denied claim is waiting on the other side of an incident.
We fill these out with clients every renewal. Here's what carriers actually check, in the order they weight it.
1. MFA — everywhere, not just email
The single biggest lever. Carriers no longer ask "do you have MFA?" They ask where: email, remote access, privileged accounts, and backup infrastructure. A "yes" that covers Microsoft 365 but misses your VPN is the gap that becomes a coverage fight later.
2. EDR / managed detection
Antivirus doesn't count anymore. Carriers want endpoint detection and response with someone actually watching it — a 24/7 SOC, in-house or managed. This is where a small business either builds a security team it can't afford or runs on a managed platform with the SOC included.
3. Tested, immutable backups
- Immutable — ransomware can't encrypt or delete them.
- Offsite — separate from the environment they protect.
- Tested — the word carriers underline. A backup you've never restored is a hope, not a control.
4. Security-awareness training
Documented, recurring, with phishing simulations. Carriers ask for completion rates. "We sent an email once" is not a program.
Answer with evidence
The rule that keeps you covered: attest to what you can prove with a screenshot. If you can't produce the evidence in sixty seconds, don't check the box. Our insurability self-check walks the same controls and shows you where you'd pass or fail before your carrier does.
Before your renewal
Run the 3-minute insurability self-check
See where you’d pass or fail your carrier’s questionnaire, with a control-by-control gap list.
Start the self-check