← Back to Insights
Cyber InsuranceMarch 23, 20265 min read

What Cyber Insurers Review Before Offering Coverage

Reviewing a cyber insurance application questionnaire
In this article

Understand the security controls commonly addressed in SMB cyber-insurance applications and how to prepare accurate, evidence-based responses.

What Cyber Insurers Review Before Offering Coverage

Key Takeaways

  • Cyber-insurance applications have become more detailed as insurers have refined their underwriting.
  • Common topics include MFA, backups, endpoint protection, patching, employee awareness, privileged access, and incident response.
  • Requirements differ by insurer, policy, industry, organization, and requested coverage.
  • Inaccurate or unsupported answers can create serious coverage issues.
  • An audit or vulnerability assessment can help verify selected statements, but it cannot guarantee coverage, policy terms, claim payment, or a lower premium.

Some SMBs receive higher quotes, restrictive terms, or a refusal to quote because the insurer's underwriting criteria are not met.

The practical issue is not to guess what "insurers usually want." It is to answer the actual application accurately and understand the policy being offered.

Why Underwriting Has Become More Detailed

Loss Experience and Ransomware

Ransomware, business interruption, data recovery, legal services, and emergency response have influenced cyber-insurance loss experience. Insurers have responded by refining pricing, coverage, exclusions, and the evidence requested during underwriting.

More Specific Applications

Applications may now ask detailed questions such as:

  • Is MFA applied to remote, email, cloud, and administrative access?
  • Are backups protected from production compromise?
  • Have restoration procedures been tested?
  • Is endpoint detection deployed and monitored?
  • How are critical vulnerabilities and security updates managed?
  • Does the organization maintain and exercise an incident response plan?

The exact questions and definitions matter. "MFA enabled" may mean different things depending on which users, services, and access paths are included.

Controls Commonly Addressed

The topics below appear frequently, but they are not universal requirements. Always use the insurer's current application and definitions.

MFA for Critical Access

An insurer may ask about remote access, email, cloud applications, administrator accounts, and suppliers. Confirm which identities and access paths are actually protected, which MFA methods are used, and whether exceptions exist.

Protected and Tested Backups

The insurer may ask whether backups are separated from production, restricted, immutable, monitored, and tested. A completed backup job is not the same as a successful recovery test.

Endpoint Protection and EDR

Applications may ask about endpoint protection, EDR, deployment coverage, alert monitoring, and response capability. The required technology and operating model vary.

Update and Vulnerability Management

Questions may address asset inventory, vulnerability identification, security updates, internet-facing systems, end-of-life software, exceptions, and remediation targets.

Employee Awareness

An insurer may ask about phishing awareness, training cadence, testing, reporting, and whether training covers every employee or only selected roles.

Incident Response

The application may ask whether the organization has a documented plan, verified contacts, defined responsibilities, external response providers, legal counsel, and exercises.

Other Possible Topics

Depending on the risk, the insurer may also examine:

  • privileged-access management;
  • network segmentation;
  • email security;
  • logging and monitoring;
  • supplier access;
  • payment controls;
  • data types and volumes;
  • previous incidents;
  • business continuity; and
  • contractual dependencies.

What Can Happen When Requirements Are Not Met?

No Quote or Restricted Terms

An insurer may decline to quote, require specific improvements, offer lower limits, apply a higher deductible, or introduce exclusions. The outcome depends on its underwriting rules and the risk presented.

Coverage That Does Not Match the Main Exposure

A policy may contain exclusions, sublimits, waiting periods, conditions, or definitions that materially limit protection. Review the wording with a qualified insurance broker and legal counsel where appropriate.

Problems During a Claim

If an application contains a material inaccuracy, or a policy condition was not met, coverage may be disputed. The legal outcome depends on the facts, policy wording, and applicable law.

The safe practice is simple: do not answer from assumption. Verify the implementation and preserve evidence supporting the response.

How an Audit or Assessment Can Help

A cybersecurity audit may examine governance, access, backups, incident response, suppliers, policies, and evidence. A vulnerability assessment may identify known technical weaknesses in an approved scope.

These engagements can help:

  • identify gaps before an application is submitted;
  • clarify which statements are supported by evidence;
  • separate technical exposure from process gaps;
  • create a prioritized improvement plan; and
  • prepare questions for the broker or insurer.

They do not certify that the organization meets an insurer's proprietary underwriting rules unless the insurer expressly accepts the deliverable for that purpose.

They also do not guarantee lower premiums, broader coverage, or payment of a future claim.

Common Mistakes

Requesting Quotes Without Verifying the Current Environment

Completing the application from memory can lead to inaccurate answers. Gather evidence from the internal team, IT provider, security tools, contracts, and recovery tests first.

Describing a Partial Control as Universal

MFA on one administrator account is not MFA on every access path. A backup job is not proof of restoration. Endpoint software on most devices is not full deployment.

State the exact scope, exceptions, and date of verification.

Ignoring Definitions and Exclusions

Read how the policy defines computer systems, dependent business interruption, ransomware, social engineering, funds transfer, prior acts, and security failures. Obtain professional insurance advice before relying on the coverage.

What to Do Now

  1. Obtain the insurer's current application and policy wording.
  2. Assign every technical question to a person who can verify the answer.
  3. Inventory critical identities and confirm actual MFA coverage.
  4. Review the latest documented recovery test.
  5. Confirm endpoint, update, vulnerability, and incident-response evidence.
  6. Identify exceptions rather than hiding them.
  7. Ask the broker or insurer to clarify ambiguous terms in writing.

Frequently Asked Questions

Is cyber insurance mandatory?

There is no general Quebec law requiring every SMB to purchase cyber insurance. It may, however, be required by a customer, lender, landlord, partner, prime contractor, or other contract.

How much does cyber insurance cost for an SMB?

There is no reliable universal price. The premium depends on factors such as revenue, industry, data, coverage, limits, deductibles, claims history, controls, and insurer appetite. Obtain current quotes from licensed insurance professionals.

Can an audit reduce our premium?

Possibly, but it cannot be promised. An audit may provide useful evidence and identify improvements, but only the insurer determines its underwriting decision, coverage, conditions, and premium.

Topics
cyber insuranceinsurance requirementsSMBMFAbackups
RD
About the Author
Rémi Douville
President · RDCybersécurité Inc.

More than 12 years of cybersecurity experience.

PMP · Master’s degree in Computer Engineering, specializing in cybersecurity management

Want to know where you stand?

Schedule a 20-minute introductory call. We will review your situation and clarify the most useful next step.

Schedule a Call →