ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Cyber Insurance Applications: Answer Accurately, Not Optimistically

A cyber insurance application is a representation about your controls. Learn how to verify your answers before you sign so a claim is not jeopardized later.

3 min readBy Counsel Cyber Team

The cyber insurance application often lands on a managing partner's desk with a request to sign by Friday. The questions look technical, someone assumes the IT person has it covered, and the form gets returned with a few optimistic checkmarks. That habit is a risk in itself.

Insurers rely on your answers to price and issue the policy. If a claim comes later and an answer turns out to have been inaccurate, the carrier may dispute coverage. Policy language varies, so read yours and ask your broker how misrepresentations are treated. The safest approach is simple: only answer yes to a control you can prove.

Why accuracy matters more than the premium

It is tempting to treat the form as a hurdle. But a policy that does not respond when you need it is worth very little. Consider a hypothetical firm that checks "MFA enabled for all email accounts" when MFA is actually enforced for most users, with an exception for two long-tenured staff and a shared mailbox. If an attacker enters through one of those exceptions, the gap between the application and reality becomes a problem exactly when the firm can least afford one.

The controls insurers commonly ask about

Applications differ, but certain topics come up again and again.

  • Multi-factor authentication on email, remote access and administrator accounts.
  • Endpoint detection and response or similar monitoring on laptops and servers.
  • Backups, including whether they are offline or immutable and whether restores have been tested.
  • Email filtering and protection against phishing and impersonation.
  • Patching timelines for operating systems and applications.
  • Security awareness training and phishing simulations.
  • An incident response plan.
  • Procedures for verifying wire transfer instructions and changes to payment details.
  • Retirement of unsupported software.

A verification process before signing

Do not rely on memory or on a quick hallway conversation.

  1. Assign each question to an owner. IT answers technical controls. The firm administrator answers policy and training questions. Accounting answers payment verification.
  2. Ask for evidence. A screenshot of the MFA policy report, a recent backup restore log, a training completion export. Save these.
  3. Look for exceptions. "All" and "every" are risky words. If there are exceptions, say so or fix them first.
  4. Have a second person review. Someone other than the person who completed the form should read the answers.
  5. Sign with knowledge. The person who signs should understand what they are attesting to.

When the honest answer is "not yet"

Many small firms will not meet every expectation on day one. That is common, and it is better to say so. Ask your broker what the carrier would require to move from "no" to "yes," and whether a remediation plan with dates is acceptable. Underwriters often respond better to a documented plan than to a surprise discovered after a loss.

Questions to put to your broker

  • What do the policy exclusions say about failure to maintain stated controls?
  • Does coverage include wire fraud or funds transfer fraud, and under what conditions? Some policies treat social engineering losses differently or sublimit them.
  • Which incident response vendors does the carrier require or prefer, and when must we notify them?
  • Does the policy cover business interruption and regulatory costs?
  • What are the retention and limit amounts, and are they appropriate for our size?

Do not guess at the answers. Get them in writing.

Keep the application as a living record

After you submit, file the completed form, your supporting evidence and the policy together. When something changes, such as switching backup vendors or retiring MFA exceptions, note it. Many policies and renewals ask whether material circumstances have changed, and a running record makes that easy to answer.

The same evidence tends to help with client security questionnaires, which often ask overlapping questions. Building one clean set of proof saves work in both directions.

Where Counsel Cyber fits

We help law firms review their controls before they fill out an application, document what is true and close the gaps that are easy to fix. If your renewal is coming up, a short pre-application review can make the form far less stressful and the answers far more reliable.