ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

How to Prepare Before the Cyber Insurance Application Arrives

Cyber insurance applications ask detailed technical questions. Learn which controls underwriters commonly ask about and how to answer accurately at renewal.

3 min readBy Counsel Cyber Team

Many firms meet their cyber insurance application the same way: an email from the broker lands two weeks before renewal, the managing partner forwards it to whoever handles IT, and everyone scrambles to answer questions they have never seen. Applications are getting more technical, and the answers you give matter. Inaccurate statements can create problems at claim time, so the goal is to answer precisely and to have the controls in place before you are asked.

This guide walks through how to prepare well ahead of renewal, so the application becomes a confirmation of work you have already done.

Start early and gather the facts

Begin at least 60 days before renewal. Last year's application is your best starting point because it shows the questions your carrier asks. Pull out every technical question and mark which ones you can answer with confidence and which need verification.

Do not guess. If the form asks whether multi-factor authentication is enforced on all email accounts, the honest answer depends on a setting you can check, not on what the firm believes it configured years ago.

Controls underwriters commonly ask about

Every carrier has its own form, but these topics come up repeatedly.

  • Multi-factor authentication. For email, remote access, administrator accounts and often backups. Be ready to say whether it is enforced for everyone or merely available.
  • Endpoint protection. Whether laptops and servers run modern endpoint detection and response and who monitors the alerts.
  • Backups. Whether backups are offline or immutable, whether they are separate from your network credentials and when you last tested a restore.
  • Email security. Filtering for phishing and malicious attachments, and protections against spoofed domains such as SPF, DKIM and DMARC.
  • Patching. How quickly critical updates are applied to operating systems, firewalls and applications.
  • Training and phishing simulations. How often staff are trained and how results are tracked.
  • Incident response plan. Whether a written plan exists, who is on it and whether it has been rehearsed.
  • Wire transfer controls. Whether the firm verifies payment instructions by calling a known number before moving money.

Verify instead of assuming

For each control, find evidence. A screenshot of the Microsoft 365 conditional access policy, a backup report with a recent successful restore, or an endpoint console showing device coverage is stronger than a recollection.

Look for gaps in coverage

Partial deployment is the most common surprise. MFA may be on for attorneys but not for the shared mailbox the front desk uses. Endpoint protection may cover laptops but not the old server in the closet. Treat anything labeled "most" as a gap to close or to disclose accurately.

Fix what you can before you submit

If you discover a gap, the best time to fix it is before the application goes out. Some fixes are quick: turning on MFA for remaining accounts, removing departed employees, or enabling logging. Others take longer, such as replacing unsupported systems. For those, be honest on the form and document your remediation plan. Brokers can often tell you how a carrier is likely to treat a gap that is being actively addressed.

Answer honestly and consistently

The application is typically signed by a partner or officer. Misstatements, even well-meaning ones, can be a basis for a carrier to dispute a claim. Have your IT lead or provider review the technical answers and have a partner read the final version. Keep a copy of exactly what was submitted.

Keep a reusable evidence folder

Clients are increasingly sending security questionnaires too, and many of the questions overlap with insurance applications. Create one folder that holds your current policies, network diagram, backup test records, training logs and MFA screenshots. When the next questionnaire arrives, you will be assembling answers instead of starting over.

Questions to ask your broker

  • Which controls does this carrier treat as required rather than recommended?
  • Does the policy cover incident response services, and do we have to use the carrier's panel vendors?
  • How does the policy treat funds transfer fraud and social engineering losses? These are often handled separately or with sublimits, so read the terms carefully.
  • Are there conditions tied to our answers, such as a requirement to keep MFA enforced?

How Counsel Cyber helps

Counsel Cyber supports law firms through renewal season by checking the controls the applications ask about and assembling the evidence. If your application is coming up, we can run a readiness review beforehand so your answers are accurate and your gaps are on a plan.