Cyber cover has moved from a box-ticking add-on to something underwriters price on the controls you can actually evidence. The renewal form is longer than it was, the questions are more specific, and the answers now change both your premium and whether a claim gets paid.
Why the questions got harder
Insurers have paid enough ransomware claims to know which controls correlate with not paying out again. So the proposal form stopped asking whether you take security seriously and started asking whether multi-factor authentication is enforced on remote access, specifically.
The practical effect is that the form now maps closely to the same handful of controls that appear in customer security questionnaires. If you have answered one of those recently, you have done most of the work already. If you have not, see how to answer a client security questionnaire, because the overlap is substantial.
The five areas that carry the most weight
- Multi-factor authentication. On remote access, on email, and on administrative accounts. This is the single most-asked control, and "we have it on some things" is not the answer the form wants. Know exactly where it is enforced.
- Backups, and whether they have been restored. Not whether backups run. Whether anyone has performed a test restore, how long it took, and whether the backups are reachable from the same network as everything else. A backup a ransomware operator can encrypt is not a backup.
- Patching. Whether there is a defined process and cadence, particularly for internet-facing systems. "When we notice something" is a real answer many businesses would have to give honestly.
- Access control and leavers. How accounts are created and, more importantly, removed. Dormant accounts belonging to former staff are a recurring finding in our assessments.
- Evidence of testing. Whether a penetration test has been carried out, when, and whether the findings were remediated. Some insurers ask for the report; more ask for a summary and the remediation status.
The part that should worry you
An insurance proposal form is a contractual document. Answering it inaccurately, even carelessly rather than dishonestly, gives an insurer grounds to reduce or decline a claim on the basis of misrepresentation. That is a materially worse position than paying a higher premium for an honest answer.
So the person filling in the form should not be guessing on behalf of the business. If nobody can confirm from the firewall configuration whether remote access enforces multi-factor authentication, that uncertainty is itself the finding, and it is cheaper to resolve before signing than during a claim.
What we would do first, if the renewal is close
Check three things, in this order, because they are the ones most likely to be answered wrongly from memory.
First, log into the firewall and confirm exactly how remote access authenticates. Second, ask whoever manages backups when a restore was last performed as a test, and get a date rather than an assurance. Third, list what is reachable from the internet, because that is the surface the insurer is pricing and it is frequently larger than the business believes.
If those three come back clean, the rest of the form is usually straightforward. If they do not, you have found the work that needed doing anyway, and you have found it on your own timetable rather than during an incident.
What underwriters do with the answers
It helps to know the form is not simply a pass or fail. Underwriters use the answers to price the risk and to set the terms, which means a weak answer in one area is often survivable if the rest is sound. What causes trouble is inconsistency: claiming mature patching while also saying nobody owns the process, or asserting multi-factor authentication everywhere while listing a remote-access method that does not support it.
That is worth knowing because it changes how you should approach a gap. Presenting a control as absent, with a date for when it will be in place, is a normal and acceptable answer. Presenting a control as present when a loss adjuster could later establish otherwise is the expensive option.
It is also worth checking whether your policy carries conditions rather than just questions. Some cover is written with warranties attached, where a specific control must remain in place for the duration. If your policy says multi-factor authentication is a condition, then disabling it for a contractor six months later has consequences nobody will remember to warn you about.
An honest note on testing
We sell penetration testing, so weigh this accordingly: not every insurer requires one, and buying a test purely to satisfy a form is a poor reason to spend the money. Read what your policy actually asks. Where a test is required, what the underwriter wants is evidence of findings and remediation, not a scan output. A report showing issues found and subsequently closed is worth more to them than a clean scan that tested nothing meaningful.
Guidance frameworks like the CIS Critical Security Controls and the NIST Cybersecurity Framework cover the same ground the proposal form does, if you want a structure to work through before the renewal lands.