InsightsCybersecurity & RiskField Note

The cyber-insurance questionnaire, explained for non-technical leaders

The short version

A cyber-insurance questionnaire is a risk audit you fill out under oath: answer wrong and a claim can be denied when you need it most. Every question maps to one of five plain-language controls, and the honest path to “yes” answers is a documented posture, not optimistic guessing.

Why does this form matter so much?

Because it is not marketing paperwork. It is underwriting. Your answers set your premium, your coverage limits, and whether a future claim is paid. Carriers now investigate after incidents, and a control you attested to but never verified is grounds for denial. Treat the questionnaire as a sworn statement, because functionally it is one.

What is the insurer actually asking?

Nearly every questionnaire, whatever its length, is probing five controls. Here is the translation.

What the form says What it means in plain language
Do you enforce MFA on all remote access and email? Is a password alone ever enough to get into your systems from outside? It should not be.
Do you maintain offline or immutable backups, and test restoration? If ransomware encrypted everything tonight, do you have a copy it cannot touch, and have you actually practiced restoring it?
Do you deploy EDR across endpoints? Is there software on every computer watching for break-in behavior, or would an intruder work unobserved?
Do you have an incident response plan with defined roles? If something happens at 2 a.m., does a written page say who does what, or does everyone improvise?
Do you conduct security awareness training and phishing simulation? Are staff taught to spot the fraudulent email that starts most incidents, and is that teaching tested?

How do we answer honestly without a technical staff?

Do not guess, and do not let the form be filled out by the vendor whose work it grades. Your IT provider attesting to its own controls is a conflict of interest. Have someone independent verify each answer against evidence: screenshots, logs, a restore test with a date on it. This verification is part of what a Technology Assessment produces, and keeping the file current is standing work for the seat described in What a vCIO does. Professional practices feel this most acutely at renewal. See how the seat handles cyber-insurance readiness for practices.

What if the honest answer is “no”?

Say no, and fix it before binding. Most of these controls cost far less than the coverage gap they close. MFA, for instance, is often a configuration change you already have the tools to make. A no that becomes a documented yes in sixty days is a better position than a yes the carrier disproves after a loss.

Five questions to ask before you sign

  1. Ask your carrier: “Which of these five controls carries the most weight in a claim decision?”
  2. Ask your IT provider for hard evidence: a screenshot, a log, a dated restore test.
  3. Ask internally: “Who signs the attestation, and have they personally verified every line?”
  4. Ask before binding: “If we answer honestly today, what changes if we fix the gaps in sixty days?”
  5. Ask after any incident: “Would our answers on this form hold up to a claims investigator?”

Get ahead of the next questionnaire.

No preparation needed. We'll tell you honestly which controls need work before your carrier asks.

15 MINNO PREPHONEST ANSWER
Book the call