Cyber insurance

What cyber insurers want to see before they’ll cover you.

Cyber-insurance applications have gone from a few yes-or-no questions to pages of specific security controls. Here are the ones that show up on almost every application, what each means, and how to show you actually have it.

The controls insurers ask about Answered honestly, in writing Veteran-owned, founder-led since 2020

The hard part

Why renewals got harder

A “yes” you can’t back up can cost you the claim you bought the policy for.

  1. What it costs you

    Higher premiums, lower limits, or a policy that isn’t renewed.

  2. What it feels like

    A questionnaire full of terms nobody in the office can answer with confidence.

  3. Why it shouldn’t be this way

    The controls are well known. Most small businesses can have all of them.

The controls

What insurers ask about

  1. MFA

    A second step at sign-in, on email, remote access and admin accounts.

    How you show it A report showing MFA on every account.

  2. Endpoint detection and response

    Protection on every computer that detects attacks and responds, not just antivirus.

    How you show it The product name and a count of protected devices.

  3. Separated, tested backups

    Backups an attacker on your network can’t reach, restored on a schedule.

    How you show it Where backups live, and the date of the last test restore.

  4. Patching on a schedule

    Updates applied regularly, with exceptions tracked.

    How you show it A patch report.

  5. Email filtering

    Phishing and malicious attachments blocked before they reach inboxes.

    How you show it The filtering service in use.

  6. Security awareness training

    Staff taught to spot phishing, usually with practice tests.

    How you show it Training records.

  7. A written incident response plan

    Who does what, and who you call, when something goes wrong.

    How you show it The plan itself, dated.

Every insurer’s list is a little different. Your insurer’s application is the real list; these are the ones that appear on almost all of them.

Before you sign

Two rules worth following

Answer the questionnaire truthfully. If an answer turns out not to be true, the insurer may deny the claim. “Not yet, and here’s our date” is a better answer than a yes you can’t support.

Know who to call first. Many policies require you to notify the insurer quickly and use their approved responders. Calling anyone else first can affect your coverage.

Who we are

How we help

We complete the technical side of the questionnaire with you, show where the gaps are, and close them before your renewal. On a monthly plan, the evidence insurers ask for is kept current all year.

Questionnaire help

The technical answers, accurate.

Gaps closed

In order of what insurers weigh most.

Evidence kept

Reports ready when renewal comes.

Year-round

Not a scramble every renewal.

Where to start

Where to start

The choice is yours.

What success looks like

Renewals without the scramble.

And answers you can stand behind.

  • Every control on the list is in place.
  • The evidence is ready before anyone asks.
  • You know who to call first.

Questions about cyber insurance

What do cyber insurers require?

Most ask about MFA, endpoint protection, separated and tested backups, patching, email filtering, training and an incident plan. Your insurer’s application is the definitive list.

What happens if we answer yes and it isn’t true?

The insurer may deny a claim. Answer truthfully, and fix gaps before renewal.

Is antivirus enough?

Usually not. Insurers increasingly ask for endpoint detection and response.

Who should we call first in an incident?

Your insurer. Many policies require prompt notice and name the responders you can use.

Can you fill out the questionnaire for us?

We complete the technical answers with you. You review and sign it.

Do brokers send clients to you?

We work with anyone who needs the technical side handled. Send them to our free IT risk review.

Renewal coming up?

Book a free IT risk review and we’ll check your setup against what insurers ask. Or start with a few questions about your tech.