Ransomware or a breach right now? Don't wait. Call our incident line.+1 587 208 3742What to do first →

Cyber insurance questionnaires: the 7 controls insurers ask about

If your cyber insurance renewal arrived with a longer questionnaire than last year, you are not imagining it. Ransomware claims have pushed insurers to ask detailed questions about security controls before they will offer cover, and to price policies on the answers.

The good news is that the questions are predictable. Wording varies by insurer, but almost every application comes back to the same seven controls.

1. Multi-factor authentication (MFA)

What they ask: Is MFA enforced for email, remote access (VPN, remote desktop) and privileged or admin accounts?

Why it matters: Stolen passwords are one of the most common ways attackers get in. MFA blocks most of those attempts even when the password is known.

Answering honestly: “Enforced” means every account, not most of them. Watch for shared mailboxes, service accounts, old admin accounts and legacy protocols that bypass MFA. In Microsoft 365, conditional access policies and blocking legacy authentication are what make MFA truly enforced.

2. Endpoint detection and response (EDR)

What they ask: Do you use EDR on all endpoints and servers? Is it monitored 24/7?

Why it matters: Modern attacks often use legitimate admin tools that antivirus will not block. EDR records behaviour and allows an analyst to isolate a compromised machine.

Answering honestly: Check coverage. A single unprotected server is often how ransomware spreads. If the question asks about 24/7 monitoring, an EDR product alone is not enough. Someone has to be watching the alerts at night. That is what managed detection and response provides.

3. Backups that survive an attack

What they ask: Are backups offline, immutable or otherwise separated from your network? How often are they tested?

Why it matters: Ransomware operators deliberately look for and destroy backups before encrypting your systems.

Answering honestly: A backup on a network share that your domain admin account can delete does not count as separated. You also need a recent, documented restore test. See backup and disaster recovery.

4. Patching and vulnerability management

What they ask: How quickly are critical security patches applied? Do you scan for vulnerabilities?

Why it matters: Attackers exploit internet-facing vulnerabilities, such as VPNs, firewalls and remote access portals, within days of disclosure.

Answering honestly: Know your actual patch timelines, especially for internet-facing devices, which are often missed by workstation patching tools. Regular vulnerability scanning gives you evidence.

5. Security awareness training

What they ask: Do employees receive security awareness training at least annually? Do you run phishing simulations?

Why it matters: Phishing and fraudulent payment requests remain leading causes of claims.

Answering honestly: Keep completion records. Simulations with measurable results are stronger evidence than a once-a-year video. See security awareness training.

6. Email security

What they ask: Do you filter inbound email for malicious links and attachments? Are SPF, DKIM and DMARC configured?

Why it matters: Email is the most common entry point, and spoofed domains enable invoice fraud.

Answering honestly: Check that your DMARC policy is actually enforcing (quarantine or reject), not just set to p=none for monitoring.

7. An incident response plan

What they ask: Do you have a documented incident response plan? Has it been tested?

Why it matters: The first hours of an incident decide how much it costs. A plan says who to call, what to preserve and who makes decisions.

Answering honestly: A plan nobody has read is not much of a plan. A short tabletop exercise with leadership once a year turns a document into a capability. A vCISO can build and run this with you.

Before you sign the renewal

  1. Go through each question with whoever runs your IT, and check the answer against the actual configuration, not memory.
  2. Where a control is partly in place, talk to your broker about how to describe it accurately.
  3. Fix the gaps that are cheap and quick, usually MFA coverage and DMARC, before you submit.
  4. Collect evidence such as reports, restore tests and training records, so next year’s renewal takes an hour instead of a week.

If you would like a second opinion on your questionnaire, send it to us. We will tell you which answers are solid and which are at risk.

Frequently asked questions

What happens if I answer an insurance questionnaire incorrectly?

Your application forms part of the policy. If a claim investigation finds that a control you said was in place was missing, the insurer may dispute or reduce the claim. Answer based on what is actually configured, and ask your broker how to describe controls that are only partly in place.

Does antivirus count as endpoint detection and response (EDR)?

Usually not. Traditional antivirus blocks known malware. EDR records endpoint activity, detects suspicious behaviour and lets a responder isolate a machine. Many insurers now ask specifically for EDR, and some ask whether it is monitored 24/7.

How often should we test backups for insurance purposes?

Test a restore at least quarterly, and keep a dated record of what was restored, how long it took and whether it worked. That record answers the backup question with evidence rather than a checkbox.

How we can help

Let's talk about your IT and security.

Book a free 30-minute assessment. We will look at where you stand, what your insurer and clients expect, and the few things worth fixing first. No obligation.