The questionnaire your cyber insurance company is sending you is becoming increasingly important. I’ve been filling out these forms for almost a decade, and I’ve seen almost every iteration of their complexity. A lot of them are getting tougher, and unfortunately, I see a lot of business owners not taking them seriously. Often they check a bunch of boxes that make them feel good, send it back, and call it a day. And they’re getting insured, of course. But the problem isn’t getting insurance. Getting your claim through is.
Why the forms got harder
Why, over the last five to ten years, have these forms become a lot harder? Because insurers have gotten burned. A lot of businesses are getting breached and filing claims that the insurers had to honor. And of course, the game of insurance is to get the clients and not pay out if they can help it. That’s exactly what they’re starting to do.
I was looking over one of the first forms I filled out. I actually got a kick out of how simple it was. They’d ask you questions like, “Have you ever been breached before? Do you have backups?” A little bit about your business to understand your risk. Are you using multi-factor authentication? What antivirus are you using? Do you have a firewall? Some of the basic stuff you’d ask a client if it was 2016. Cyber breaches weren’t as prevalent as they are today.
I compared a form from the same insurance company from 2020 to now, and the pages have gotten much bigger. The form used to be only one to two pages, and the questions were pretty simple. Now, in some cases, it’s over ten pages.
Here’s the problem with filling out that form and sending it in without really knowing the answer. If you check yes to a box (let’s say multi-factor authentication because I see that one a lot) and you get breached, the cyber insurance company will step in to help you with the legal, the forensics, and the IT side. But part of the forensic work is also determining how the breach happened. If it happened because multi-factor authentication was off, or the user who got breached had it off, they can deny the claim. And now that claim, which I’ve seen be upwards of half a million, is denied and is completely out of pocket to you. You have a choice: do I pay it and keep my business running, or do I shut down?
Not to get too deep into the cybersecurity side, but the bad actors know how much money you can pay. Before they come up with the ransom, they look through your documents. They look for bank statements and other documents to see how much you actually have.
I don’t have one specific story, because I’ve seen many claims over the years. Still, filling out the forms honestly doesn’t automatically deny you from having cyber insurance. In fact, it often doesn’t. It just puts you in a different risk category, and it does cost a little more per year because the insurance company has to take on more risk with you.
What they’re asking for now
Here are some things they’re asking for today. Some are the basics, things you’ve been asked before, and some are a little more advanced.
They’re asking whether you have a managed IT provider, and if so, they want information about what they manage for your business and what you’re paying them for.
Some are asking how many unique records you have that contain sensitive personally identifiable information, and how many are non-sensitive. Things like email addresses, phone numbers, names, which are technically personally identifiable information, but not sensitive.
They’re asking what kind of endpoint protection you use on your computers, so antivirus, as an example. They’re asking if you use endpoint detection and response, and if so, what it is. They want to know if it’s deployed to all endpoints on your network. That word “all” is really crucial. If not, they want a percentage and why it isn’t deployed everywhere.
They want to know about your perimeter security. Your firewalls (if you have them), whether you’re paying for the services, whether multi-factor is turned on to access them, whether you scan through the firewall, and whether you conduct penetration testing on your network. If you don’t know what penetration testing is, that’s okay. Take a second to search it online. It’s intensive and can get expensive, and they want to know.
Multi-factor authentication enforced on any remote access and on all company email accounts, which in many cases is just your 365 or your other email provider. Whether you simulate phishing attacks to test employees at least once a year. Whether you use a separate email filter, and what it is.
In some cases, they even ask for your Microsoft Secure Score if you use Microsoft 365. That matters because many people don’t make the necessary security changes in 365, and their score is around 25 out of 100.
If you have Active Directory, they want to know whether non-IT users have local administrator accounts and whether they have local administrator rights on their computers. They want to know whether any network monitoring detects suspicious or malicious behavior, separate from the firewall. They want to know if you have any end-of-life software, meaning software the vendor no longer updates, that could cause security vulnerabilities.
Patch management. In the past they’d ask if you did it. Now they want to know how you ensure that all critical patches are applied. They want a timeline of how quickly you’d handle things like zero-day vulnerabilities. They want to know any major changes you have planned in the next 12 months. Not ones you’ve done, the ones you’re planning.
They want to know how you protect confidential information. Things like encryption, network segmentation, access controls. They want to know how often you purge records that are no longer required. Data retention is another way to say that.
Backups. They want to know how you store your backups of critical data. Specifically, how they’re stored, not just whether you back up. They want details on the frequency, including how often you take a full backup and how often you take incremental backups. Meaning how often you take a full copy of your system, versus how often you’re just updating that copy with the newest data. They want details on how you secure those backups, and how you test them. How do you make sure that if you have to recover them, they actually work? They also want to know how many backup copies you keep and how you prevent separate copies from being impacted by an incident.
They want to know if you provide training on social engineering. And although this doesn’t sound like cybersecurity, they want to know that before you transfer funds to an account you haven’t paid before, you get authorization from the recipient through a different method than the original request. Meaning, if they send an email saying, “Hey, please update our bank account,” you call them on a number you already know and ask them to verify the bank account information verbally.
Then they’ll have a bunch of control boxes you can check to say you have these things in place. Web content filtering, for example, or an intrusion detection system. Those have been there before, but now they carry more weight because they want the name of the software for each thing you check. If you check “Yes, I’m using a DNS filter,” they want to know what product you are using to do that.
They’re not asking to be nosy, per se. What you fill out here are the things they have seen cause security breaches. They want to protect you against the things you didn’t know to do, the things you shouldn’t have been expected to know how to fix, or the things that aren’t industry standard today.
A free security audit
Look at it differently. These forms are free security audits.
Often, even if you have a provider and send it to them, they might not fill it out truthfully. But if they fill it out truthfully, it’s a good indicator of whether or not they’re providing what you need for security, or whether they can provide it and you’re not paying for it.
And if you can’t answer a question on one of these forms, it doesn’t really mean there’s a problem with the insurance company or the form. In many cases, it’s a gap in your company’s security.
What to do with it
Don’t guess. Don’t check yes because you want it to sound better to the insurance company. And certainly don’t check yes if you don’t know. Find out. If the answer is no, put no. That’s very important.
If you have someone in a technical role, take the questionnaire to them and go line by line, and have them answer those questions for you. Anything you can’t check yes to becomes something you need to work on in your business to make it more secure. And by the way, once you do that, your premium will lower.
Being honest now saves you from paying out hundreds of thousands of dollars later on a claim.
The other side
Insurance companies do have tiers, and it’s also based on the type of business you have. They may ask if you have certain things, like custom threat intelligence. Most businesses I’ve worked with don’t need custom threat intelligence, because they don’t hold classified government secrets.
So don’t feel like you have to have everything on the form. Use your judgment, and rely on technical resources to tell you what you should and shouldn’t have. Often, the forms let you explain your reasoning for checking no, and if you have a good enough reason, you’ll still be put in the lower-risk category.
This isn’t about buying everything on the list. It’s about mitigating risk, which is ultimately your job as a business owner or business leader. So when you get these forms, fill them out honestly. If there’s a gap, research it and fix it to prevent a breach in the first place.
In two weeks, I’ll get into the truth about your data and AI. Most businesses will blindly upload data to an AI model, but have no idea if they’re protected. If that sounds interesting, subscribe so we can send it to you.
If you’d rather talk about risk management and how to protect your business, that’s the kind of thing I like doing. You can grab some time with me here.

