Cyber insurance
Answering your cyber insurer's questionnaire, without bluffing
What insurers now verify, why an approximate answer turns against you at claim time, and how to build an evidence file that holds up.
Key points
- Insurers no longer take declarations at face value: they verify, sometimes at claim time.
- An inaccurate answer can compromise indemnification, even when made in good faith.
- The required controls overlap heavily between insurers: treating them serves far beyond the policy.
- The evidence file built for the insurer also answers your enterprise customers' questionnaires.
Why insurers tightened their requirements
Because cyber loss experience made the original model untenable. Policies were long underwritten on simple declaration; insurers have since tightened access conditions, verification and exclusions alike. The questionnaire is no longer an administrative formality: it is a selection instrument.
That has a direct consequence for smaller businesses: controls that used to be asked of large organizations are now asked of everyone. A thirty-person company is questioned on its logging, its privileged account management and its restore testing.
It also has a less visible consequence. Many organizations discover their own gaps while filling in the form, and fill it in anyway, ticking what they believe to be true. That is precisely where the most expensive risk is created.
Which controls come up every time?
Six, with wording that varies between insurers: multi-factor authentication on remote access, isolated and restored backups, endpoint and server protection, retained logging, patch and privileged account management, and a written incident response procedure.
None of these is specific to insurance. They are the measures public authorities also recommend, which is why questionnaires overlap so heavily. Treating them once therefore serves several purposes.
- Multi-factor authentication. On all remote access and administrative accounts, with no tolerated exemption for executives: the most frequently requested exemption, and the most dangerous.
- Isolated and restored backups. Insurers increasingly ask for the date of the last restore test, not merely whether a backup exists.
- Endpoint and server protection. Detection deployed across the whole estate, including the forgotten machines: production workstations, legacy servers, contractor equipment.
- Retained logging. Records that exist and are kept long enough to be useful after an incident, often the weakest point in smaller organizations.
- Patching and privileged accounts. An update process, and an inventory of the accounts holding elevated rights.
- A written incident response procedure. Who decides, who is notified, in what order. A plan improvised on the day is not a procedure written in calm conditions.
What is the risk of an approximate answer?
An insurance contract rests on the accuracy of declarations. An inaccurate answer on a material point can support a reduced settlement or a denial of cover, including where the inaccuracy was made in good faith. The moment this surfaces is the worst possible one: after the loss, during adjustment.
The typical case is not fraud, it is imprecision. An organization ticks "multi-factor authentication enabled" because it is enabled on email, without realizing that remote access to the accounting server has none. The declaration is simultaneously sincere and inaccurate.
The remedy is simple but requires method: verify each statement before ticking it, and keep proof of that verification. That is what we call the evidence file.
We also recommend having the clauses reviewed by your broker or legal counsel. Our work concerns the technical reality being declared, not the interpretation of the contract.
What goes into the evidence file?
For each statement in the questionnaire, the item that demonstrates it: a configuration capture, a coverage report, a dated restore test record, the written procedure. The file is built once, updated periodically, and serves the insurer and your enterprise customers equally.
Its value lies in its dating. A file assembled at underwriting and never revisited loses meaning within months, because the estate moves: new machines, departures, a change of provider.
It serves a second purpose beyond insurance. The supplier questionnaires circulated by large customers cover the same ground in a different order. An organization keeping this file answers in hours what usually ties up a week.
Frequently asked questions
It depends entirely on your starting point, and we do not announce it in advance. Some organizations find that most controls are already in place and only the evidence is missing; others must first deploy what is absent. The initial inventory, however, is short: it is what tells you where you actually stand.
No, and the two do not cover the same risk. Insurance transfers part of the financial consequences of an incident; it prevents neither downtime, nor data loss, nor reputational harm. Insurers themselves now condition cover on the existence of security controls, which settles the question of substitution.
Yes, and it is often the most efficient route. The broker knows the insurer's expectations and the exact wording of the clauses; we know the real state of your systems. Direct dialogue avoids round trips and misunderstandings about what a question actually covers. We stay in our technical role and do not advise on the contract itself.
Raise it with your broker or insurer without waiting for a loss. A declaration corrected before any incident is handled as a file update; discovered during adjustment, it is handled very differently. We help you establish the exact gap between what was declared and what is in place, so the correction is precise.
Not necessarily. We start by checking what your current licences already cover: several of the required controls correspond to capabilities that are present but not enabled. Where purchases are needed, you make them directly with the vendor or your reseller: we resell no licences.
Sources
- Canadian Centre for Cyber Security: Baseline cyber security controls for small and medium organizations · the recommendations questionnaires largely draw on
- Autorité des marchés financiers (Quebec) · oversight of insurers and brokers
- Commission d'accès à l'information du Québec · notification obligations, frequently referenced in policies
Is your infrastructure ready for the next threat?
An initial assessment, free and without commitment, to evaluate your security posture.