surable

For agents: this page is the handout.

Print it (Ctrl+P, or Cmd+P on a Mac) and choose “Save as PDF” to attach it to the email you send with the questionnaire, or just send the link. Add ?agency=Your+Agency&phone=555-0100 to the URL and your name prints at the bottom. More for agencies.

Before you fill out the cyber insurance supplemental

The eight things carriers ask about, and the evidence they expect

Applications end with a signature saying your answers are true. Every answer below is one an underwriter can check after a claim, so answer each one the way it actually is today. If something isn't in place, most of these take an afternoon to fix.

ControlWhat the application asksEvidence to have
Multi-factor authenticationIs MFA enforced on email, on remote access (VPN and remote desktop), and on administrator accounts?A screenshot of the enforcement policy in Microsoft 365 or Google Workspace, plus a written password and MFA policy.
Endpoint detection & responseDo you run EDR, and is it deployed on every endpoint and server?The product name, the console's coverage count, and who watches the alerts.
BackupsAre backups automated, kept offline or immutable, and tested by restore?The last restore test date and what was restored. Untested backups read as no backups.
Patching & end-of-life systemsHow fast are critical patches applied, and is anything running an unsupported operating system?A patch cadence in writing, plus an inventory showing nothing unsupported. Windows 10 went end of support in October 2025.
Email securityDo you filter inbound mail, and do you use SPF, DKIM, and DMARC on your domain?The filtering product, and a DMARC record that isn't set to p=none.
Funds-transfer verificationDo you verify payment and banking-detail changes by a call to a known number before sending money?A written call-back procedure, and the dollar threshold that triggers a second approver.
Security awareness trainingIs staff training documented, and how often does it run?The training dates, who attended, and the phishing simulation results if you run them.
Incident response planDo you have a written incident response plan, and has it been tested?The plan itself, plus dated notes from a tabletop exercise in the last twelve months.

If an honest answer is no

You have two good options and one bad one. Fix the control before you submit, which for MFA, a call-back rule, and a written plan is a single afternoon. Or disclose the gap accurately and note what you do instead. The bad option is answering yes and hoping, because that answer gets re-read when you file a claim.

Find out where you stand first

The free Readiness Check at surable.ai/readiness-checkasks the same kind of questions an application does and scores you across ten control domains. It takes about five minutes, gives you your three biggest gaps with the fix for each, and doesn't need an email address to show you the score.

General readiness information, not legal or insurance advice. Coverage decisions are the carrier's. Prepared by Surable (surable.ai), which sells readiness assessments and documents and does not sell, quote, or place insurance.