The renewal questionnaire is open. Directors need answers on MFA, backups, patching and incident response before they can bind the policy.
Choosing the strongest-sounding option can raise insurer concern. So can using old facts or leaving hard questions blank.
Common errors include vague answers, overstated controls and undisclosed changes or incidents. Accurate answers backed by evidence help underwriters price the business fairly.
They also reduce the chance of challenged terms, cover or claims.
Why weak answers can raise premiums or affect cover
A cyber insurer prices controls it can check. Unclear or inaccurate answers can lead to more questions, a higher excess, or required fixes before cover starts.
A “yes” for multi-factor authentication, or MFA, helps only when it explains what MFA protects. MFA requires more than a password, such as an app code.
Insurers may ask if MFA protects Microsoft 365 or Google Workspace email. They may also ask about VPNs, remote desktop protocol, cloud accounting, privileged accounts and supplier remote access.
“MFA is enabled for staff” can mislead an insurer if administrator accounts or old remote servers sit outside MFA.
Which errors can affect a future claim?
A blank answer may lead to an underwriter question. An incorrect answer about a key control, ransomware event or claims history can have wider effects.
This matters if the error changed the insurer’s decision. Under the Insurance Act 2015, commercial buyers must make a reasonable search for relevant facts.
They must present those facts clearly. The director who signs the declaration remains responsible for its accuracy.
The questionnaire must describe the business on its submission date. It must not describe 2025’s IT setup.
This advice does not replace the proposal, renewal declaration, endorsements or conditions in a specific policy. If an incident has happened, or you find a possible incorrect statement, follow the policy notification process. Seek suitable professional advice if the insurer requests a formal clarification. Do not quietly amend historic answers after the event.
A cyber insurance questionnaire does more than set SME cyber insurance premiums. It can also affect the cover an insurer offers.
An insurer may not verify MFA, secure backups or a tested response process. It may then apply a higher excess, a ransomware sublimit, or a control condition.
It may also apply an exclusion linked to a known weakness. Read MFA coverage exclusions with special care.
Do not assume “MFA is enabled” protects every loss. Email administrators, remote access and privileged cloud accounts may sit outside the stated control.
Compare the completed proposal with the policy schedule, endorsements and definitions before binding cover. Ask the broker about any security condition you cannot today meet.
The answers most likely to increase an SME premium
Weak MFA, untested backups, slow patching and incomplete endpoint protection often prompt higher pricing. Poor payment checks and no incident plan can also trigger tighter terms or follow-up questions.
| Insurer question | Common answer error | Likely underwriting view | Evidence to check |
|---|
| Is MFA in place? | “Yes” without exclusions | Email or admin takeover risk remains | Identity-provider report and exception list |
| Are backups secure? | Backups exist, but no restore test | Longer ransomware interruption risk | Dated restore-test record |
| Are devices protected? | Antivirus called EDR | Limited detection and response capability | EDR console coverage report |
| Any incidents or claims? | Only formal claims disclosed | History may be incomplete | Incident and claim register |
Does MFA cover every critical login?
MFA often matters more than a basic antivirus answer for ransomware and email fraud. Stolen passwords are a common way into a business.
A precise response should name protected services and any exceptions. For example: “MFA covers all Microsoft 365 users, VPN access and privileged accounts.”
“Two legacy service accounts cannot use MFA. They are restricted to named devices, and replacement work is due by 30 September.”
That is safer than hiding the gap.
Are backups tested and separate?
A useful ransomware backup sits apart from everyday systems. It must resist alteration and be tested through a real restoration.
Keep a dated record of what was restored. Record recovery time, data completeness and anything that failed.
Policies may ask about restore tests every 3 to 12 months. The proposal’s own definition always takes priority.
Can you prove patching and EDR coverage?
Patch management means applying supplier fixes for known software flaws. Think of it like repairing a broken lock before someone tests the door.
Endpoint detection and response, or EDR, watches devices for attack signs. It also helps contain an attack.
A policy statement does not prove that laptops, servers and remote devices are current. Keep asset records, patch status, EDR reports and unsupported-software records.
The National Cyber Security Centre gives practical UK guidance for small organisations.
Build evidence before sending the questionnaire
The safest answer is specific, dated and checkable by another person. Evidence should show coverage, ownership and known gaps.
What proof supports an MFA answer?
Use an export from the identity system, such as Microsoft Entra ID. It should show enrolled users and authentication methods.
Add a list of privileged accounts, excluded services and shared accounts. Give a target date for each exception.
Do not assume MFA covers cloud apps because staff use it for email. Check accounting, payroll, customer relationship and remote-support systems separately.
What proves backups can be restored?
A dated restoration test is stronger than a green backup screenshot. Record the restored system, backup date, recovery time, tester and missing data.
Ask IT to confirm technical controls. Ask finance to confirm payment and fraud checks.
Ask HR to confirm training records. A director should confirm revenue, claims and final declarations.
A practical evidence pack can include:
- An asset inventory showing laptops, servers, mobiles and key cloud services.
- MFA reports covering email, remote access and administrator accounts.
- EDR coverage reports, patch status and unsupported-software records.
- Backup configuration and restoration test results from the last 3 to 12 months.
- Phishing training records and an incident response exercise record.
Questionnaire evidence flow
IT
Checks MFA, EDR, patches and backups
Finance
Checks turnover, payments and fraud controls
HR
Checks training, joiners and leavers
Director
Checks claims, exceptions and declaration
Submit only answers supported by current, dated evidence.
Can a policy prove a control exists?
A written policy says what staff should do. A log, report or test shows what actually happened.
Insurers often need both for access reviews, patching, supplier controls and incident response. UK GDPR and the Data Protection Act 2018 require suitable personal-data security.
They do not create a standard cyber insurance answer. The most frequent error here is treating a written policy as proof.
For UK SMEs, Cyber Essentials can give a useful baseline for underwriting evidence. Certification does not guarantee cover or a lower price.
Its focus includes boundary firewalls, secure setup, access control and malware protection. It also covers security update management.
These areas closely match cyber insurance underwriting questions.
The National Cyber Security Centre publishes supporting guidance. It can help turn broad policy statements into working records.
Examples include an asset list, named system owners and timely patch reports. Keep proof that unused accounts are removed.
If you hold Cyber Essentials certification, state its current status and expiry date. Do not imply certification because similar controls are in place.
Avoid vague claims, old data and blank fields
Vague descriptions, old turnover figures and incomplete incident history can concern an underwriter. They may assume gaps or ask for more proof.
When does “N/A” create a problem?
“N/A” is suitable only where the risk truly does not exist. It is unsafe for remote access when directors work from home.
It is also unsafe for cloud suppliers when customer data sits in Microsoft 365. It is unsafe for payment controls when invoices are paid online.
A firm may not sell online but still hold personal data. Payroll files, staff email and customer contacts can all contain it.
Describe the data held, not just the sales channel.
Does UK GDPR training reduce premiums?
Training alone rarely gives a fixed discount. Missing training can weaken an answer about phishing and data-breach readiness.
Records should show who completed training and when. They should also show how you chase overdue staff.
An incident response plan is most credible after a tabletop exercise. The exercise should show who calls the insurer and contains the attack.
It should show how staff contact customers. It should also consider Information Commissioner’s Office notification.
Your questions answered
Yes. Incorrect turnover can distort pricing and limit assessment. Use the proposal’s revenue definition, and state whether the figure is actual or forecast.
Will overstating past incidents hurt my cyber insurance?
Yes. Overstating or understating incidents causes problems. State the date, event type, loss, data affected and remedial action.
MFA vs antivirus answers: which cuts premiums?
MFA often carries more weight for account takeover and email fraud. Antivirus matters, but insurers increasingly expect EDR across managed endpoints.
Are vague security control descriptions costing me?
They can be, because vague wording suggests gaps. Replace “regular backups” with backup scope, separation method and the latest restore-test date.
Does omitting UK GDPR training escalate my cyber premium?
It may increase concern about phishing, breach response and personal-data handling. Training records from the past 12 months are more credible than “ongoing” training.
Claims history errors: when do they spike premiums?
They matter most for ransomware, funds transfer fraud, sensitive-data loss or long interruption. Repeat events without documented fixes are especially concerning.
Submit a precise, evidence-backed declaration
Treat the completed form as a snapshot of the business on the signing date. Match each answer to a named owner, dated evidence and open exceptions.
A lower premium is never guaranteed. Insurers also assess sector, turnover, limits, claims and market conditions.
Clear evidence can prevent avoidable loadings and restrictions caused by uncertainty. Before signing, compare the questionnaire with IT reality and policy wording line by line.
Also compare it with the renewal declaration.
Not all weak answers carry the same risk. An incomplete response leaves out requested facts, such as excluded administrator accounts.
An ambiguous response says “regularly patched” without a timeframe or coverage figure. An out-of-date response reflects 2025’s systems or turnover.
A materially inaccurate response says a control exists when it does not. Before renewal, reconcile the questionnaire with identity-system reports and asset inventories.
Also check supplier arrangements and the cyber claims history or incident register.
The same facts should support a later claim notification. Record exceptions, incidents and pending fixes plainly, with dates and ownership.
Do not rely on a broad claim that security is “in place”.
Related sources
These articles can help you explore the topic in more depth: