Cyber insurance
What cyber insurers want to see before they’ll cover you.
Cyber-insurance applications have gone from a few yes-or-no questions to pages of specific security controls. Here are the ones that show up on almost every application, what each means, and how to show you actually have it.
The hard part
Why renewals got harder
A “yes” you can’t back up can cost you the claim you bought the policy for.
-
What it costs you
Higher premiums, lower limits, or a policy that isn’t renewed.
-
What it feels like
A questionnaire full of terms nobody in the office can answer with confidence.
-
Why it shouldn’t be this way
The controls are well known. Most small businesses can have all of them.
The controls
What insurers ask about
-
MFA
A second step at sign-in, on email, remote access and admin accounts.
How you show it A report showing MFA on every account.
-
Endpoint detection and response
Protection on every computer that detects attacks and responds, not just antivirus.
How you show it The product name and a count of protected devices.
-
Separated, tested backups
Backups an attacker on your network can’t reach, restored on a schedule.
How you show it Where backups live, and the date of the last test restore.
-
Patching on a schedule
Updates applied regularly, with exceptions tracked.
How you show it A patch report.
-
Email filtering
Phishing and malicious attachments blocked before they reach inboxes.
How you show it The filtering service in use.
-
Security awareness training
Staff taught to spot phishing, usually with practice tests.
How you show it Training records.
-
A written incident response plan
Who does what, and who you call, when something goes wrong.
How you show it The plan itself, dated.
Every insurer’s list is a little different. Your insurer’s application is the real list; these are the ones that appear on almost all of them.
Before you sign
Two rules worth following
Answer the questionnaire truthfully. If an answer turns out not to be true, the insurer may deny the claim. “Not yet, and here’s our date” is a better answer than a yes you can’t support.
Know who to call first. Many policies require you to notify the insurer quickly and use their approved responders. Calling anyone else first can affect your coverage.
Who we are
How we help
We complete the technical side of the questionnaire with you, show where the gaps are, and close them before your renewal. On a monthly plan, the evidence insurers ask for is kept current all year.
Questionnaire help
The technical answers, accurate.
Gaps closed
In order of what insurers weigh most.
Evidence kept
Reports ready when renewal comes.
Year-round
Not a scramble every renewal.
Where to start
Where to start
The choice is yours.
- Want your answers checked before you sign? Book my free IT risk review →
- A team of 15 to 70 who want IT fully handled. Our Fully Managed IT Support Program →
- A small team, mostly in the cloud. IT Essentials →
What success looks like
Renewals without the scramble.
And answers you can stand behind.
- Every control on the list is in place.
- The evidence is ready before anyone asks.
- You know who to call first.
Questions about cyber insurance
What do cyber insurers require?
Most ask about MFA, endpoint protection, separated and tested backups, patching, email filtering, training and an incident plan. Your insurer’s application is the definitive list.
What happens if we answer yes and it isn’t true?
The insurer may deny a claim. Answer truthfully, and fix gaps before renewal.
Is antivirus enough?
Usually not. Insurers increasingly ask for endpoint detection and response.
Who should we call first in an incident?
Your insurer. Many policies require prompt notice and name the responders you can use.
Can you fill out the questionnaire for us?
We complete the technical answers with you. You review and sign it.
Do brokers send clients to you?
We work with anyone who needs the technical side handled. Send them to our free IT risk review.
Renewal coming up?
Book a free IT risk review and we’ll check your setup against what insurers ask. Or start with a few questions about your tech.