surable

What a cyber insurance application actually asks

The short answer

Cyber insurance applications and supplemental questionnaires ask about 10 control areas: multi-factor authentication, endpoint protection, backups, patching, email security, training, incident response, access control, vendor risk, and funds-transfer verification. The 14security questions below are the ones that decide most applications, each with the answer that reads as ready and the fix when it isn't true yet.

Carriers word these differently, and a supplemental questionnaire for a law firm won't match one for a contractor. The substance barely moves. Every question below traces to a control framework clause and to the forms carriers actually send, which is why the same handful of topics decides most applications.

One thing worth saying plainly before you read on. Knowing the question doesn't change your answer. The application ends with an attestation you sign, and an answer that wasn't true gets re-read at claim time, when it's expensive. Use this page to find out what to fix, not what to say.

MFA & identity

Stolen credentials are the most common way attackers get in. Nearly every carrier now requires MFA on email, remote access, and admin accounts as a condition of coverage.

Is multi-factor authentication (MFA) required on all business email accounts?

MFA means a second step at sign-in (an app prompt, code, or security key), not just a password.

A ready answer: Yes, enforced for everyone, no exceptions

Why it matters: This is the #1 declination trigger. One phished password equals full mailbox access, wire fraud, and a likely 'no' from underwriters.

If the answer is no: Enable enforced MFA in Microsoft 365 / Google Workspace today. Built-in, free, typically an afternoon including user comms.

Typically hours · free

Evidence to have: Password & Multi-Factor Authentication Policy, Training One-Pager: Passwords & MFA

Terms: Multi-factor authentication (MFA), Credential stuffing

CIS v8.1 IG1 6.3 · CSF 2.0 PR.AA · asked on virtually every carrier application

Is MFA required for remote access (VPN, remote desktop) and administrator accounts?

A ready answer: Yes, both remote access and admin accounts

Why it matters: Carriers treat internet-reachable remote access without MFA as near-uninsurable. It's also how most ransomware starts.

If the answer is no: Inventory every remote entry point (VPN, RDP, remote-support tools) and privileged account; enforce MFA on each or shut it off.

Typically days · low cost

Evidence to have: Access Control & Account Management Policy, Password & Multi-Factor Authentication Policy, Patch & Vulnerability Management Policy, Remote Work Policy, Training One-Pager: Passwords & MFA

Terms: Multi-factor authentication (MFA), Phishing-resistant MFA, Privileged / administrator account, Attack surface, Remote Desktop Protocol (RDP), Virtual private network (VPN)

CIS v8.1 IG1 6.4–6.5 · standard supplemental-application question

Backup & recovery

Tested, offline-capable backups are the difference between an outage and paying a ransom. Claims data shows a record share of ransomware victims now refuse to pay. Working backups are what make refusal possible.

How is your critical business data backed up?

A ready answer: Automatic, off-site, with an offline or immutable copy

Why it matters: Without backups, a ransomware demand is your recovery plan. Uninsurable and unrecoverable is a bad combination.

If the answer is no: Stand up automatic off-site backup for critical systems this week, then schedule a restore test.

Typically days · budget needed

Evidence to have: Backup & Recovery Policy, Incident Response Plan (Fill-in-the-Blank)

Terms: Immutable / offline backup, 3-2-1 backup rule, Ransomware

CIS v8.1 IG1 11.1–11.4 · CSF 2.0 RC · every application asks; many ask 'offline/immutable?'

When did you last successfully test restoring from a backup?

A restore test means actually recovering files or a system and confirming they work, not just checking that the backup job ran.

A ready answer: Within the last 6 months

Why it matters: An untested backup is a hope, not a control. Discovering it's broken during a ransomware event is the most expensive way to find out.

If the answer is no: Run a restore test this month: restore a folder and one full system, time it, and document the result. That document answers the application question.

Typically hours · free

Evidence to have: Backup & Recovery Policy, Incident Response Plan (Fill-in-the-Blank)

Terms: Backup / restore testing, RTO / RPO, Business continuity / disaster recovery (BC/DR)

CIS v8.1 IG1 11.5 · carriers ask 'are backups tested?' and untested reads as unknown

Endpoint protection

EDR (endpoint detection and response) is what stops ransomware mid-attack. Many carriers price policies differently, or decline outright, based on this answer alone.

What protects your computers and servers from malware?

A ready answer: EDR (e.g., Defender for Business, CrowdStrike, SentinelOne) on all devices

Why it matters: Automatic declination territory, and the most likely reason you'd suffer the loss the policy exists for.

If the answer is no: Deploy EDR to every computer and server this week. This is the single fastest insurability improvement after MFA.

Typically days · budget needed

Evidence to have: Acceptable Use Policy, Patch & Vulnerability Management Policy, Backup & Recovery Policy, Incident Response Plan (Fill-in-the-Blank)

Terms: Endpoint detection and response (EDR), Endpoint, Managed detection and response (MDR), Ransomware

CIS v8.1 IG1 10.1 · EDR is a named requirement on most 2026 applications

Incident response

A written, tested incident response plan is a hard requirement on most applications. Untested plans are treated as no plan.

Do you have a written incident response plan?

Who to call, who decides, how to isolate systems, carrier and legal contacts, communication steps.

A ready answer: Yes, written, with named roles and current contacts

Why it matters: This single missing document fails one of the most common application requirements, and it's the cheapest one to fix.

If the answer is no: Write the one-page version today (who to call, how to isolate, where backups are), then grow it into a full plan with the template.

Typically hours · low cost

Evidence to have: Incident Response Plan (Fill-in-the-Blank)

Terms: Incident response plan (IRP)

CIS v8.1 IG1 17.1–17.3 · CSF 2.0 RS · a written IR plan is a hard requirement on most applications

Have you tested your incident response plan in the last 12 months?

A tabletop counts: 60–90 minutes walking through a ransomware scenario and noting what broke.

A ready answer: Yes, tabletop or real exercise, notes kept

Why it matters: Carriers ask 'written AND tested', and tabletops always surface a dead phone number or a missing decision-maker before a real incident does.

If the answer is no: Run a 60-minute tabletop this quarter: one ransomware scenario, the leadership team, someone taking notes. Date-stamp the notes; that's your evidence.

Typically hours · free

Evidence to have: Incident Response Plan (Fill-in-the-Blank)

Terms: Tabletop exercise

CIS v8.1 IG1 17.x · applications increasingly ask 'tested?' and untested plans read as shelfware

Patching & vulnerabilities

Unpatched, internet-facing software is now a leading initial-access vector. Applications ask about patch cadence and end-of-life systems specifically.

How are security updates applied to your systems and software?

A ready answer: Automatic where possible, tracked, critical patches within days

Why it matters: Unknown patch status means unknown exposure, and an application answer you can't honestly support.

If the answer is no: Have whoever manages IT produce a list of what's patched automatically vs. manually. That list becomes your patch-management policy's appendix.

Typically hours · free

Evidence to have: Patch & Vulnerability Management Policy, Remote Work Policy

Terms: Patch management, Vulnerability, Vulnerability scanning, Attack surface, Zero-day

CIS v8.1 IG1 7.3–7.4 · vulnerability exploitation is a leading initial-access vector (Verizon DBIR 2026)

Do you run any systems that no longer receive security updates (end-of-life)?

Examples: Windows Server 2012, Windows 7/8 machines, old firewalls or NAS devices, unsupported line-of-business software.

A ready answer: No, everything is supported

Why it matters: Unsupported systems can't be patched, and carriers know it. This answer triggers surcharges, exclusions, or declination.

If the answer is no: Replace what you can; isolate what you can't (separate VLAN, no internet). Either path turns a 'no' answer into a defensible one.

Typically a week or more · budget needed

Evidence to have: Patch & Vulnerability Management Policy, Pre-Signature Attestation Checklist

Terms: End-of-life (EOL) system, Asset inventory, Compensating control

CIS v8.1 IG1 2.2 · a named question on many supplemental applications

Email security

Business email compromise drives more claims than ransomware. Carriers ask what filtering and anti-spoofing protections sit in front of your inbox.

What protections sit in front of your business email?

A ready answer: Advanced filtering + anti-phishing + DMARC enforced

Why it matters: Email is the front door for the most common claim types. Minimal protection here undermines every other control.

If the answer is no: Move email to Microsoft 365 or Google Workspace if self-hosted; enable their anti-phishing protections and SPF/DKIM/DMARC.

Typically a week or more · budget needed

Evidence to have: Email Security Policy, Funds-Transfer & Payment Verification Procedure, Training One-Pager: Phishing & Social Engineering

Terms: Business email compromise (BEC), Phishing, SPF / DKIM / DMARC

CIS v8.1 IG1 9.x · BEC + funds-transfer fraud drive 58% of claims (Coalition 2026)

Security awareness training

Documented, recurring training is a standard application question and an attestation item. 'We tell people to be careful' does not count as documented.

How often do employees receive security awareness training?

A ready answer: Recurring training plus phishing simulations, attendance documented

Why it matters: A 'no' here is a red flag to underwriters, and untrained staff are the entry point for the most common claims.

If the answer is no: Start simple: a 30-minute session this month using ready-made materials, an attendance sheet, and a calendar reminder for next quarter.

Typically hours · free

Evidence to have: Email Security Policy, Security Awareness Training Policy, Training One-Pager: Phishing & Social Engineering

Terms: Phishing, Security awareness training

CIS v8.1 IG1 14.1–14.6 · 'documented training' is an application checkbox and attestation item

Funds-transfer controls

Funds-transfer fraud is the single most common small-business loss type. A documented call-back verification procedure is cheap and prevents it, and some carriers require it for full FTF coverage.

Before changing bank details or sending an unusual payment, do you verify by phone using a known number?

The scenario: an email 'from your vendor' says their bank account changed. What happens next in your company?

A ready answer: Yes, documented call-back procedure, known numbers, no exceptions

Why it matters: This is the single most common way small businesses lose money to attackers, and the loss is instant and rarely recoverable.

If the answer is no: Institute the call-back rule today and tell every person who can move money. It's free and it prevents the most frequent claim type outright.

Typically hours · free

Evidence to have: Email Security Policy, Funds-Transfer & Payment Verification Procedure, Training One-Pager: Payment & Wire Fraud

Terms: Business email compromise (BEC), Funds-transfer / wire fraud, Funds-transfer verification (call-back rule)

The control that prevents the most common claim type, BEC/funds-transfer fraud, 58% of incidents (Coalition 2026). Some carriers require it for full FTF coverage.

Access control & offboarding

Orphaned accounts from departed employees are a classic breach entry point. Carriers ask whether access removal is immediate and documented.

When someone leaves the company, how quickly is their access removed?

A ready answer: Same day, using a documented checklist

Why it matters: Orphaned accounts are a classic breach source and an application question you currently can't answer well.

If the answer is no: List every system a departing employee touches; turn it into a checklist; assign an owner. Two hours, permanent fix.

Typically hours · free

Evidence to have: Access Control & Account Management Policy

Terms: Least privilege, Access control, Offboarding

CIS v8.1 IG1 5.3–5.4 · 6.1–6.2 · account-lifecycle questions appear on most applications

Vendor & third-party risk

Third-party breaches account for a large share of incidents. Applications increasingly ask how you vet vendors with access to your data.

Do you review the security of vendors who access your systems or data?

A ready answer: Yes, inventory kept, security terms in contracts

Why it matters: You're extending your attack surface to companies you've never asked a single security question.

If the answer is no: Start with the inventory: every vendor with system or data access, what they touch, and whether they have MFA. Ten vendors, one page, one hour.

Typically hours · free

Evidence to have: Vendor & Third-Party Risk Policy

Terms: Supply-chain / third-party attack, Vendor / third-party risk management

CIS v8.1 IG1 15.1 · third-party involvement in breaches roughly doubled (DBIR 2026)

Naming the document is the easy half

Each answer above names the document that evidences it. Filling the form in takes one level more: the section of that document an underwriter will read, the appendix you attach (the restore-test log, the end-of-life register, the offboarding checklist), and the wording to use when a carrier phrases the question differently or when you have to disclose a gap. That's the Application-Mapping Guide and the Evidence Index, both in the pack. See every document section by section, or run the free Check and it will name the section for your own gaps.

What if I can't fix something before the form is due?

Disclose it and say what you do instead. Underwriters price around a known gap every day, and a compensating control (a documented call-back rule, network segmentation, a shorter backup window) often keeps the quote alive. What they can't price is an answer that turns out to be wrong after a loss. That's the one that gets a claim denied.

Get your answers scored in five minutes

The free Readiness Check walks these same questions, scores you by control area, and hands back your three biggest gaps with the fix for each. No email needed for the score.

Working from a real form? The Readiness Pack includes a guide mapping each document to the question it answers, and agents can send clients the one-page version.