4 minute read
Cyber Insurance Questions You Can’t Answer — And How to Fix It
Your cyber policy is up for renewal. The questions got harder.
Cyber insurance used to be a checkbox: pay the premium, get the policy, move on. Not anymore. After years of paying out on ransomware and wire fraud, insurers have tightened the screws, and renewal now comes with a questionnaire that reads like a security audit.
Do you enforce multi-factor authentication? Is every device running threat detection? Are your backups tested? Do your people get security training? Answer wrong, or answer “yes” when the reality is “sort of,” and you’re looking at a higher premium, a denied claim, or no coverage at all.
The short version
- “Do you enforce it?” doesn’t mean “is it available.” Insurers mean enforced, everywhere, no exceptions.
- A denied claim is worse than no policy. You pay for years, then find out the control you attested to wasn’t actually on.
- The five controls they check are the ones that stop most attacks anyway. Passing the form and being genuinely protected are the same work.
“Do you enforce MFA?” is a trick question
Not because the answer’s complicated. Because insurers don’t mean “is it available.” They mean enforced, everywhere, no exceptions. One shared admin account without MFA is enough to sink the answer.
The same reading applies down the whole form. “Threat detection on all endpoints” means every machine, not most of them. “Tested backups” means you’ve actually restored one, not that a backup job exists somewhere in a console. Underwriters learned the difference the expensive way, and now they check.
A denied claim is worse than no policy
With no policy, at least you know you’re on your own. The real trap is paying premiums for years, getting hit, filing the claim, and having it denied because the MFA you signed off on wasn’t turned on for the account that got breached. That’s happening now, and it’s a worse position than never having insured at all.
The controls insurers require aren’t arbitrary hoops. They’re the same handful of things that stop most attacks in the first place. Getting them genuinely in place doesn’t just pass the questionnaire, it means you’re far less likely to ever file the claim.
The five they always ask
MFA on email and key systems
Not available, not optional, not “most users.” Every account that can reach your data, with no exceptions carved out for convenience.
Threat detection on every device
Endpoint protection running on all machines. The one laptop someone brought in from home is the one that fails the audit.
Tested, recoverable backups
Backups that have actually been restored in a test, not just scheduled. A full year of retention is the standard insurers now look for.
Security awareness training for staff
Your team is the front line. Insurers want evidence they’ve been trained to spot the phishing email that starts most incidents.
A plan for when something goes wrong
A documented response, with someone named who picks up the phone at 2am. “We’d figure it out” is not an answer underwriters accept.
Don’t wait for the questionnaire
Pull up your policy and check the renewal date. If it’s inside the next 90 days, the form is coming, and the time to close gaps is before it lands. If you’re not sure how you’d answer any of the five, that’s worth a conversation now rather than a scramble later. We’ll walk your controls in plain terms and show you exactly where the gaps are.