“We failed a cyber insurance questionnaire.”
The questionnaire is a contract, not a formality.
Cyber insurance applications changed. They used to be a page. Now they read like an audit, and that is deliberate, carriers were paying out more than they collected, so they tightened both what they ask and what they enforce.
The part people miss: your answers are representations. If you answer yes to multi-factor authentication and a claim reveals it was only enabled for some people, the carrier may decline the claim. You will have paid premiums for years for coverage that evaporates at the moment you need it.
Right now
What is probably true today.
Based on what we find in businesses that arrive this way. Not all of it will apply. Enough of it usually does.
-
Somebody answered the questionnaire with their best understanding, not with evidence.
-
Multi-factor authentication is on for most people, which the form treats as identical to "no."
-
You cannot currently produce documentation proving any of the controls you claimed.
-
The gap between the answers and the reality has never been examined by anyone.
Regardless of who you hire
What to do this week.
None of this requires us. Do it yourself, or hand it to whoever helps you with technology.
-
1
Find last year's completed application and read it
Go line by line and mark every answer you could not currently prove with a screenshot or a report. That list is your exposure, not to attackers, to your own carrier.
-
2
Treat every uncertain answer as a no
That is how it will be treated at claim time. It is a more useful assumption to work from than optimism.
-
3
Get the gaps documented before you renew
An assessment produces exactly the evidence these applications ask for. Several clients have found the premium reduction covers a meaningful share of the cost.
Worth reading next
Cyber Insurance: What's the difference from General Liability and why does it matter?
General liability will not pay for ransomware, and a cyber policy will not pay if you cannot prove the controls you claimed. How the two differ.
How to Create a Cybersecurity Budget For Small Business
A repeatable framework for deciding what to spend on cybersecurity: impact first, then capabilities, then a 12-18 month roadmap your CFO can defend.
If you would rather not work through it alone
Fifteen minutes, and we will tell you what we would do.
No pitch on the first call. Tell us what happened and we will tell you honestly how serious it is, what we would tackle first, and whether you need an assessment at all.
No pitch on the first call. If we are not a fit, we will say so and point you somewhere better.