What your cyber insurer actually wants to see

By S. Sridhar Thewar · 7 min read · Published August 2026
Short version: Insurers are underwriting the controls that actually reduce claims: multi-factor authentication on remote access and email, backups that have been restore-tested, a patching process, and evidence of testing. Answer the proposal form from what is configured, not from what you intend, because a wrong answer can be treated as misrepresentation when you claim.

Cyber cover has moved from a box-ticking add-on to something underwriters price on the controls you can actually evidence. The renewal form is longer than it was, the questions are more specific, and the answers now change both your premium and whether a claim gets paid.

Why the questions got harder

Insurers have paid enough ransomware claims to know which controls correlate with not paying out again. So the proposal form stopped asking whether you take security seriously and started asking whether multi-factor authentication is enforced on remote access, specifically.

The practical effect is that the form now maps closely to the same handful of controls that appear in customer security questionnaires. If you have answered one of those recently, you have done most of the work already. If you have not, see how to answer a client security questionnaire, because the overlap is substantial.

The five areas that carry the most weight

The part that should worry you

An insurance proposal form is a contractual document. Answering it inaccurately, even carelessly rather than dishonestly, gives an insurer grounds to reduce or decline a claim on the basis of misrepresentation. That is a materially worse position than paying a higher premium for an honest answer.

So the person filling in the form should not be guessing on behalf of the business. If nobody can confirm from the firewall configuration whether remote access enforces multi-factor authentication, that uncertainty is itself the finding, and it is cheaper to resolve before signing than during a claim.

What we would do first, if the renewal is close

Check three things, in this order, because they are the ones most likely to be answered wrongly from memory.

First, log into the firewall and confirm exactly how remote access authenticates. Second, ask whoever manages backups when a restore was last performed as a test, and get a date rather than an assurance. Third, list what is reachable from the internet, because that is the surface the insurer is pricing and it is frequently larger than the business believes.

If those three come back clean, the rest of the form is usually straightforward. If they do not, you have found the work that needed doing anyway, and you have found it on your own timetable rather than during an incident.

What underwriters do with the answers

It helps to know the form is not simply a pass or fail. Underwriters use the answers to price the risk and to set the terms, which means a weak answer in one area is often survivable if the rest is sound. What causes trouble is inconsistency: claiming mature patching while also saying nobody owns the process, or asserting multi-factor authentication everywhere while listing a remote-access method that does not support it.

That is worth knowing because it changes how you should approach a gap. Presenting a control as absent, with a date for when it will be in place, is a normal and acceptable answer. Presenting a control as present when a loss adjuster could later establish otherwise is the expensive option.

It is also worth checking whether your policy carries conditions rather than just questions. Some cover is written with warranties attached, where a specific control must remain in place for the duration. If your policy says multi-factor authentication is a condition, then disabling it for a contractor six months later has consequences nobody will remember to warn you about.

An honest note on testing

We sell penetration testing, so weigh this accordingly: not every insurer requires one, and buying a test purely to satisfy a form is a poor reason to spend the money. Read what your policy actually asks. Where a test is required, what the underwriter wants is evidence of findings and remediation, not a scan output. A report showing issues found and subsequently closed is worth more to them than a clean scan that tested nothing meaningful.

Guidance frameworks like the CIS Critical Security Controls and the NIST Cybersecurity Framework cover the same ground the proposal form does, if you want a structure to work through before the renewal lands.

Frequently asked questions

Does cyber insurance require a penetration test?

Some policies do, many do not. Where testing is required the underwriter usually wants evidence of findings and their remediation rather than a raw scan output. Read the specific policy wording rather than assuming.

What happens if we answer the proposal form incorrectly?

A proposal form is a contractual document. An inaccurate answer, even a careless one rather than a dishonest one, can give the insurer grounds to reduce or decline a claim for misrepresentation. Verify answers against the actual configuration.

Which control matters most to insurers?

Multi-factor authentication on remote access, email and administrative accounts is the most consistently asked-about control, followed closely by whether backups have been restore-tested.

Can NexusSec help us complete an insurance proposal form?

For the network, firewall, remote access and testing sections, yes. We check the actual configuration so the answers are evidenced rather than assumed. We do not advise on policy wording or cover levels; that is your broker's role.

Renewal form on your desk?

We will verify the technical answers against your actual configuration, so what you sign is accurate.

Book a free consultation