FAQ
How to Pass Your Cyber Insurance Questionnaire (Without Lying on It)
Somewhere on your desk is a cyber insurance questionnaire. It might be a new application, a renewal, or a client security review that reads like one. It asks whether you enforce multi-factor authentication, whether your backups are tested, and whether you have an incident response plan. You are discovering what every business owner discovers at this moment: you are not sure.
This article covers how to answer it well. That means two separate things. You want the coverage today, and you want a claim paid later. Most advice covers the first goal and ignores the second, and the second is where businesses actually get hurt.
Your Answers Become Part of the Contract
A cyber insurance questionnaire works differently than a survey. Your answers become representations that attach to your policy. When you check “yes” next to “MFA is enforced on all email accounts,” the insurer can audit that statement after an incident, right when they decide whether to pay.
A business answers yes to MFA because the owner remembers turning it on. Eighteen months later, an attacker gets in through one shared mailbox where it was never enforced. The insurer's forensics team finds that mailbox, compares it to the application, and denies the claim. The premium bought nothing, and the discovery arrives on the worst day of the business's life.
A “no” on the application costs you a higher premium or a required fix. A wrong “yes” can cost you the entire claim. Let that asymmetry drive how you fill in every box.
What the Questions Actually Mean
Insurers ask about the same handful of controls because their claims data points to the same handful of failures. Each question carries an implied “prove it”:
| The question | What they actually want |
|---|---|
| Is MFA enforced? | A policy that blocks sign-in without it, on every account including the owner’s |
| Are backups maintained? | Copies an attacker cannot reach, restore-tested on a schedule you can show |
| Is there endpoint protection? | Behavior-based detection on every machine, with someone responding to alerts |
| Is software supported and patched? | No end-of-life operating systems, plus a patching rhythm with evidence |
| Is there an incident response plan? | A written document naming who does what |
| Is staff trained? | A recurring program with records, ideally with phishing simulation results |
Two of these trip up businesses acting in good faith. “Enforced” MFA means the system rejects any sign-in without a second factor. If any account can skip it, the honest answer is no. “Tested” backups means someone recently restored real data and it worked. A green light on a dashboard is a status report, and status reports have fooled a lot of businesses.
Five Steps to a Questionnaire You Can Defend
- Answer nothing from memory. For every question, look at the actual setting yourself, or have whoever manages your systems show you the screen. Showing beats telling.
- Treat every “I think so” as a no. Uncertainty means the control is unverified. Each one becomes an item on your to-do list.
- Fix the cheap gaps before submitting. Enforcing MFA properly, retiring an end-of-life machine, and scheduling a restore test usually take days rather than months. All three improve your premium and your insurability.
- File the evidence with the application. Keep screenshots, policy exports, training records, and a restore-test log together, dated. If a claim ever comes, this folder stands between you and the denial scenario above.
- Document what you consciously declined. A written, accepted risk is a business decision. An undocumented one is a surprise waiting for the worst moment.
The questionnaire is a free, insurer-funded audit of the exact controls most likely to save your business. Every question you cannot answer confidently marks a gap that exists whether or not you buy the policy. The to-do list is the real value. The premium quote is secondary.
When to Bring In Help
Plenty of businesses handle the fixes themselves, and the list above is enough to get started. Outside help earns its keep on evidence: producing it, keeping it current, and giving your broker documented answers instead of hopeful ones. Evidence maintenance is a standing part of what Sentry Protect clients get from us. Businesses that need the one-time truth get it from a Sentry Inspect assessment, which documents where you stand across nine areas in a form written for insurers, boards, and auditors.
Still deciding whether you need cyber coverage at all? Our comparison of cyber insurance and general liability covers the difference. The short version: the incidents on this questionnaire are exactly the ones your general liability policy will not touch.
Want to know how you would score before the insurer asks? The self-assessment covers the same ground in three minutes, privately, with no email address required.