Preparing for a Cyber Insurance Questionnaire

What insurers ask and how to prepare evidence before renewal.

Preparing for a Cyber Insurance Questionnaire: evidence, controls and timeline

Cyber insurance questionnaires ask about the same core controls every renewal: MFA coverage, endpoint detection, backups with tested restores, patching cadence, an incident response plan, privileged access management, and email filtering. Prepare by assembling an evidence file — policies, configuration screenshots, and test logs — at least 90 days before renewal, and answer only what you can prove.

The questionnaire is not paperwork; it is the underwriting decision. Your answers shape the premium, the coverage limits, the exclusions, and — if a claim ever happens — whether the policy pays at all. This guide walks through what insurers actually ask, how to build the evidence behind each answer, and how to avoid the traps that get claims denied.

What insurers actually ask

Questionnaires differ by carrier, but the control questions have converged over the past few renewal cycles. Expect detailed, yes-or-no questions — often with "on what percentage of systems" follow-ups — across these areas:

  • MFA coverage: email accounts, remote access (VPN, RDP, remote tools), privileged/admin accounts, and increasingly cloud consoles and backup systems
  • Endpoint detection: whether EDR is deployed, on what share of endpoints and servers, and whether anyone monitors it around the clock
  • Backups: frequency, immutability or offline copies, separation of backup credentials from production, and — critically — how often restores are tested
  • Patching cadence: how quickly critical vulnerabilities are remediated and how compliance is measured; see how to measure patch compliance for the metrics that answer this credibly
  • Incident response plan: whether a written plan exists, who the response contacts are, and when it was last exercised
  • Privileged access: separate admin accounts, least privilege, and whether admin credentials are vaulted or rotated
  • Email filtering: anti-phishing controls, attachment sandboxing, and user awareness training

Alongside the control questions, expect financial and exposure questions — revenue, record counts, reliance on specific vendors — and claims history. Answer the exposure questions from your actual books, not from memory.

7 areas

Core control categories most questionnaires probe: MFA, EDR, backups, patching, incident response, privileged access, and email filtering.

90 days

Minimum preparation runway before renewal. Gap closure, evidence gathering, and review cycles simply do not fit into a final-week scramble.

100%

The word that causes the most trouble. "All remote access" and "every endpoint" questions are where aspirational answers become claim-denial evidence.

How questionnaires have changed

If your last renewal was a few years ago, expect a longer and more specific form. The earlier generation of questionnaires asked broad questions — "do you use antivirus?" — and took the answers largely on trust. After several years of heavy ransomware losses, carriers tightened both the questions and the verification. Binary yes/no questions now come with percentage follow-ups, named-product follow-ups ("which EDR vendor?"), and in some cases requests for supporting evidence at binding time.

The practical consequence: the questionnaire can no longer be treated as a marketing document about your intentions. It functions more like an attestation, and the claims process treats it as one. Prepare for it the way you would prepare for an audit — with records, not recollections.

One more shift worth knowing: some carriers now re-validate controls mid-term, not just at renewal. External scanning data, breach telemetry, and claims-adjacent intelligence increasingly feed underwriting between policy periods. The posture you attest to needs to be the posture you maintain, not a snapshot you assemble once a year.

Control-to-evidence map

Questionnaire control What a strong answer looks like Evidence to keep on file
MFA on email, remote access, adminEnforced — not merely enabled — on 100% of in-scope accountsCoverage report from your identity provider showing enforcement per account
EDR deployed and monitoredFleet-wide deployment with 24/7 human monitoring (in-house or MDR)Console screenshot of deployment count plus monitoring agreement
Backups with tested restoresImmutable or isolated copies; restore tests on a documented scheduleTest-restore log with dates, systems, and outcomes
Critical patches within a defined windowA written SLA — for example seven days for critical — with measured compliancePatch compliance report and a signed patch management policy
Written incident response planCurrent plan with named contacts, exercised within the last yearThe plan document plus tabletop exercise notes
Privileged access controlsSeparate admin accounts, least privilege, offboarding within a defined windowAdmin account audit and a sample deprovisioning ticket
Email filtering and trainingAnti-phishing filtering on all mailboxes plus recurring awareness trainingFiltering policy screenshot and training completion report

Assemble the evidence file before you need it

The organizations that sail through renewals keep a standing evidence folder rather than scrambling each year. Build it once, then refresh it quarterly. It should contain:

  • Written policies: patch management, incident response, acceptable use, and access control — signed and dated, even if short
  • Configuration evidence: screenshots showing MFA enforcement, EDR deployment counts, email filtering policies, and backup job settings
  • Test logs: restore test records, tabletop exercise notes, phishing simulation results
  • Compliance reports: patch compliance rates, training completion percentages, and asset inventory exports with dates

Date everything. An undated screenshot is an assertion; a dated one is evidence. If you work with an MSP, ask them to produce this folder as a deliverable — it is a reasonable request, and many will already have most of it.

How answers map to premiums and coverage

Underwriting is not transparent, and outcomes vary by carrier, industry, and claims history — but the directional relationships are consistent. Strong, evidenced answers on the core controls generally correlate with better premiums and fewer exclusions. Weak or unverifiable answers tend to produce some combination of higher premiums, lower limits, higher retentions, ransomware sub-limits or co-insurance, and in some cases a decline to quote at all.

Two controls punch above their weight in most underwriting models: MFA on remote access and email, and backups with demonstrated restore capability. These map directly to the two most common claim types — business email compromise and ransomware — so carriers weight them heavily. If you can only afford to close a few gaps before renewal, start there.

Also note what a questionnaire answer cannot fix: a control deployed two weeks before renewal is real, but insurers and their forensic teams can see deployment dates. Early, sustained controls read better than last-minute ones.

"Answer the questionnaire for the environment you have, not the environment you intend to have. The gap between the two is where denied claims live."

The misrepresentation traps

The most dangerous questionnaire habit is answering aspirationally — yes, we have MFA, when it is really MFA on most accounts except the service accounts, the legacy app, and the CEO who opted out. After a claim, forensic investigators reconstruct exactly what was in place. Material mismatches between attested controls and reality give carriers grounds to deny the claim or seek rescission, and courts have sometimes sided with them.

Specific traps to watch for:

  • The 100% questions: "MFA on all remote access" includes the vendor's remote support tool and the firewall management interface, not just the VPN
  • The monitoring question: "EDR deployed and monitored" means someone reviews and responds to alerts — a console nobody opens does not qualify
  • The backups question: "tested regularly" implies a schedule and records; having once restored a file two years ago is not it
  • The inherited yes: answers copied from last year's form after the environment changed — a new acquisition, a cloud migration, an MSP switch

The safer posture: where a control is partial, answer honestly and attach a remediation plan with dates. Carriers regularly work with applicants mid-improvement. What they do not forgive is being told a control existed when it did not.

If you work with an MSP

Most of the technical answers belong to whoever operates the controls, which for many organizations is an MSP or co-managed provider. Send them the questionnaire early — it is part of the 90-day runway — and ask for answers with the supporting reports attached, not a verbal summary. A provider that runs these controls properly already generates the evidence: MFA coverage exports, patch compliance reports, restore test logs.

Be careful about one asymmetry: you sign the form, so the attestation risk is yours even when the operation is theirs. Review the answers against the evidence before submission, and keep both. If the provider's answers and your provider's evidence ever disagree, the signature is still yours.

It is also worth confirming what your agreement actually covers. Some providers operate monitoring and patching but treat backup restore testing, tabletop exercises, and insurance evidence as out-of-scope extras. Discovering that boundary during renewal week is how questionnaires end up answered from optimism. Ask early, in writing, and put the evidence deliverables in the service agreement if they are not already there.

The 90-day preparation timeline

  1. 1 Day 90 — get last year's questionnaire. Request the renewal application from your broker early and diff it against last year's answers. New questions flag where carrier attention has moved.
  2. 2 Days 90–60 — gap assessment. Walk every control question and grade your real posture: in place, partial, or missing. Prioritize MFA coverage and backup restore testing. A security score assessment is a fast way to baseline this.
  3. 3 Days 60–30 — close gaps and write documents. Enforce the missing MFA, schedule a restore test, and finalize the incident response plan — our guide to building an incident response plan covers the structure insurers expect.
  4. 4 Days 30–14 — assemble the evidence file. Pull the reports, screenshots, and logs that back every yes answer. Date each item.
  5. 5 Days 14–0 — answer with evidence in hand. Complete the questionnaire from the evidence file, have whoever operates the controls review the technical answers, and keep a copy of the final submission with the evidence attached.

Who should answer what

Questionnaires fail when one person guesses at everything. Split the work: finance answers revenue and record-count questions, IT or your MSP answers the control questions with evidence in hand, and leadership signs off on the risk-acceptance items — the controls you know are missing and have chosen to remediate later. The person signing the form should have seen the evidence file, not just the answers.

Treat the renewal as a forcing function rather than a chore. The same controls that satisfy the underwriter are the controls that stop the incidents — and an environment that is managed well enough to answer honestly is an environment that is cheaper to insure. If your preparation reveals that patching, monitoring, or backups are more aspiration than fact, the five signs your IT environment is not fully managed will help you find the gaps before your insurer does.

Working with your broker

A good broker is leverage in this process, not just a conduit for the form. Ask them three things well before renewal: which carriers are currently writing your industry and size band, which controls those carriers are weighting hardest this cycle, and whether any markets will pre-underwrite — give an indication of terms based on a draft questionnaire — before you formally apply.

Brokers also see claim outcomes across their book, which means they know which questionnaire answers have actually been litigated. If your broker tells you carriers are denying claims over partial MFA coverage or untested backups, believe them and prioritize accordingly. If your broker cannot tell you that, that too is useful information about your broker.

After you submit

Keep the final submitted questionnaire together with the evidence file that backed it, in the same folder, permanently. If a claim arrives two years from now, the first thing the forensic team compares against reality is that document. The comparison should be boring.

Then treat the gap list you built during preparation as a roadmap rather than a confession: work through it across the policy year, quarter by quarter. When the next renewal comes, the honest yeses you earned are the cheapest premium reduction available — and the evidence file mostly updates itself if you built the refresh habit in.

Frequently asked questions

When should you start preparing for a cyber insurance renewal?

At least 90 days before the renewal date. That window gives you time to close obvious gaps — MFA coverage, backup testing, a written incident response plan — and to assemble the evidence file insurers increasingly request. Starting the week before renewal forces you into aspirational answers you cannot defend later.

What happens if you answer a cyber insurance questionnaire inaccurately?

The worst case is a denied claim when you need the coverage most. Insurers investigate after an incident, and if they find that a control you attested to — say, MFA on all remote access — was not actually in place, they may deny the claim or seek to rescind the policy for misrepresentation. Overstating your posture is far more dangerous than disclosing a gap and accepting a higher premium.

Do insurers actually verify questionnaire answers?

Increasingly, yes. Many carriers run external scans of your attack surface before binding, some request screenshots or reports as evidence at renewal, and virtually all of them verify controls during the forensic investigation that follows a claim. Treat every answer as something you may one day have to prove with logs.

Is MFA required on every account to get cyber insurance?

Requirements vary by carrier, but the common minimum is MFA on email, on all remote access such as VPN and remote desktop, and on privileged or administrator accounts. Some carriers now ask about MFA for cloud backups and for everyone with access to sensitive data. Answering yes when coverage is partial is one of the most common misrepresentation traps.

What if we cannot close a control gap before renewal?

Answer honestly and attach a remediation plan with dates. Carriers regularly work with applicants who are mid-improvement — a disclosed gap with a credible plan is a pricing conversation, while a concealed gap is a potential denial. Ask your broker whether the carrier will re-underwrite mid-term once the control is in place; some will adjust terms after evidence of remediation.

Renewal coming up and not sure your answers would survive a claim review?

SmashByte Security helps organizations close the control gaps insurers ask about and assemble the evidence file that makes renewal a formality instead of a gamble.

Request Security Assessment