Every year an office manager somewhere is handed a cyber insurance renewal questionnaire and asked to fill it in by Friday. It is four pages of technical questions, most of which sound like they have an obviously correct answer. Do you enforce multi-factor authentication? Yes, obviously. Do you maintain offline backups? Yes, there is a backup. Do you have endpoint protection? Yes, Windows has Defender.
Those answers are not survey responses. In most policies they are warranties — statements of fact that the insurer relies on when setting terms. If a claim is made and the insurer establishes that an answer was materially inaccurate, they have grounds to reduce or deny it. You will discover this during the worst week your business has had.
The questions that most often get answered wrong
Four come up repeatedly, and all four fail in the same way: the answer is technically true of something, but not true of everything the question covers.
- “Is MFA enforced on all email accounts?” — usually true for most staff and quietly false for a shared mailbox, a service account, or the owner who found it annoying and had it turned off.
- “Are backups stored offline or immutably?” — a backup replicating to a cloud folder that a compromised admin account can delete is neither. Ransomware operators target backups first, and they log in to do it.
- “Do you use endpoint detection and response?” — traditional antivirus and EDR are not the same product category. Answering yes because Defender is running is a stretch that an insurer will test.
- “Do you have a written incident response plan?” — meaning a document that exists today, names people, and has been read. Not an intention to write one.
Treat any question you cannot personally evidence as a “no” until someone produces the report that proves otherwise.
A better way to handle the form
Do not complete it from memory, and do not let a single person complete it alone. Take each technical question and ask what artifact would prove the answer — a coverage report, a successful test restore log, a policy export. If that artifact cannot be produced within a day, the honest answer is no.
Answering no is not a disaster. It usually means a higher premium or a remediation condition with a deadline attached. That is a considerably better outcome than a denied claim, and it also gives you something genuinely useful: a prioritized list of what to fix, written by someone with money at stake.
The gap between the form and reality
The useful thing about these questionnaires is that they are a reasonable proxy for a security baseline. Insurers ask about MFA, EDR, immutable backups, email filtering, and privileged access management because those are the controls that correlate with claims not being made. If you can answer the whole form truthfully in the affirmative, you are in better shape than most organizations of your size.
So use it that way. Fill it in honestly, note every no, and turn those into a remediation plan with dates. You have to complete the form anyway. You may as well get a roadmap out of it.
Written by the team at Summex Technologies.
Ask us about this