Call Book a fit call
Free resource

Make your cyber-insurance answers true, not improvised.

Insurers stopped asking “do you take security seriously” and started asking for specifics. This page lists what they ask and how to make every answer true - because the questionnaire is the cheapest audit you will ever get.

What applications actually ask

Cyber-insurance applications have converged on the same core controls. Expect direct yes/no questions about each of these.

  • MFA - on email, on remote access, and increasingly on admin accounts and backups; many insurers treat this as a hard requirement
  • Backups - how often, whether a copy is offline or immutable, and whether restores are actually tested
  • Endpoint protection - current tooling on every device, not “antivirus came with the laptop”
  • Security training - whether staff get it, how often, and whether new hires are covered
  • An incident response plan - written, with named roles, not “we would call someone”
  • Patching - how quickly updates land, and whether anything unsupported is still running
  • Access control - named accounts, admin separation, and same-day offboarding

Answer truthfully - it is a legal document

The application becomes part of the policy. An answer that was optimistic on paper can surface at claim time, when it costs the most.

  • Never attest to a control you have not verified this quarter - “mostly” is a no until it is a yes
  • If the honest answer is no, fix the control first or disclose it - both beat a wrong yes
  • Match the question’s scope: “MFA on email” means every mailbox, including the owner’s and the bookkeeper’s
  • Keep the person who signs and the person who knows the systems in the same room when answering

Keep the answers true all year

Renewal comes annually; your systems change weekly. A small evidence habit keeps the two aligned.

  • Keep an evidence file per answer - a dated screenshot or export beats memory at renewal or claim time
  • Recheck the core controls on a schedule - quarterly is enough for a small office
  • Re-verify answers after any change that touches them: new remote access, a provider switch, an office move, staff turnover in admin roles
  • Put renewal eight weeks out on the calendar - enough time to close a gap honestly instead of attesting around it

Ready to see where you stand?

Start with a baseline security checkup. We review your environment, score the highest-risk gaps, and hand you a plain-English 30-day plan.

Book the baseline checkup - from $750+