Cyber insurance applications used to be a few yes-or-no questions. Today they often read like a security audit, and the answers matter. A misstatement on an application can complicate a claim later, so the person who signs it needs to know the answers are accurate. Preparing early makes renewal less painful and can strengthen your position when pricing and terms are discussed.
This is general information, not insurance or legal advice. Your broker and counsel should guide the specifics for your policy.
Start 90 days out
Do not wait for the carrier's questionnaire to arrive. Begin about three months before renewal so there is time to fix gaps. Ask your broker for last year's application and any new forms. Underwriters regularly update their questions, so expect new topics.
The controls underwriters ask about most
Applications vary, but several controls appear again and again.
Multi-factor authentication
Expect questions about MFA on email, remote access, administrator accounts and backups. Answer precisely. "We use MFA" is not accurate if it covers email but not the VPN or the backup console. List exactly where it is enforced and where it is not.
Endpoint detection and response
Carriers often ask whether you run more than basic antivirus, and whether anyone monitors alerts around the clock. Managed detection and response services are designed for that purpose.
Backups
Questions focus on whether backups are offline or immutable, whether they are tested, and how quickly you could recover. See your documented restore test results.
Email security and phishing training
Underwriters ask about filtering for phishing and malicious attachments, and whether staff receive regular awareness training. Keep attendance records and phishing simulation results.
Wire-transfer and payment verification
Because trust-account and closing funds are attractive to fraudsters, some applications ask about callback verification for payment instructions. A written procedure that requires verifying changes by phone using a known number is the kind of control carriers want to see.
Incident response planning
Ask yourself whether you have a written plan with contacts, roles and a notification process, and whether it has been rehearsed.
Patching and inventory
Expect questions about how quickly critical updates are installed and whether you maintain a list of devices and software.
Build an evidence folder
For every answer, keep a document that supports it: screenshots of MFA settings, a training roster, a backup test report, a copy of your incident response plan. When a question is answered "yes," you should be able to produce proof quickly. This folder also helps with client security questionnaires, which ask many of the same things.
Mistakes to avoid
- Rounding up. If a control is half-deployed, say so and explain the plan.
- Letting one person guess. Involve whoever actually runs your systems, whether an internal administrator or your managed provider.
- Ignoring the fine print. Read exclusions and conditions, including requirements about maintaining certain controls. Ask your broker what must stay in place for coverage to apply.
- Waiting for a claim to read the policy. Know whether the policy covers incident response costs, business interruption, social engineering and funds-transfer fraud, and what the sublimits are.
- Skipping the post-renewal follow-up. Put any commitments you made on a project calendar.
Use the process as a roadmap
Gaps found during renewal prep are a free security assessment. If the questionnaire exposes that you lack MFA on a key system, fix it before the application is submitted when possible. Even controls rolled out after the application can often be discussed with your broker as improvements.
Questions for your broker
- Which controls are conditions of coverage?
- Does the policy cover wire-fraud losses and under what verification requirements?
- Do we get access to a panel of incident response providers, and do we have to use them?
- How are claims affected if an answer is later found inaccurate?
Counsel Cyber helps firms review renewal questionnaires with the people who run their systems, gather the supporting evidence, and close gaps before the application is signed. If renewal is coming up, we can sit down with you and your broker and work through it.