If your cyber insurance renewal arrived with a questionnaire twice as long as last year, you are not alone. Insurers spent years paying out ransomware claims, and now they underwrite like it. The questions are specific, the answers are binding, and wrong answers have voided real claims.
The questions that decide your premium
The forms vary, but insurers consistently zero in on the same controls:
- Multifactor authentication, everywhere that matters. Email, remote access, and admin accounts. A no here can mean a declined application, not just a higher price.
- Backups that are tested and separated. They ask when you last restored from backup and whether a copy is offline or otherwise out of an attacker’s reach. Untested backups do not count.
- Endpoint detection and response. Antivirus alone stopped impressing underwriters a while ago. They want to see modern detection with someone responding to it.
- Patching cadence. How fast do critical fixes get applied, and can you prove it.
- Security training. Documented, recurring, with phishing simulations.
Answer honestly, then fix the gaps
The worst move is optimistic answers. If a claim investigation finds the MFA you attested to was not actually everywhere, the policy you paid for may not pay you. The better move is using the questionnaire as a free gap list: every no is both a premium reduction and a real security improvement waiting to happen.
We fill these forms out with and for our clients regularly. Book a free consultation before your renewal and the answers can all be yes.