Accurate cyber underwriting answers need evidence, not assumptions. Before an application, renewal or post-incident review, record your controls, owners and verification dates.
Prepare evidence before you answer an insurer
Underwriters assess the chance and cost of a cyber loss. They need proof that controls work in day-to-day business.
Cyber underwriting looks at prevention, detection and recovery. Prevention includes multi-factor authentication (MFA), where users prove identity with more than one check.
Detection means spotting suspicious activity. Recovery means restoring systems and data after an attack.
Insurers often consider ransomware, phishing, business email compromise, data-breach costs and business interruption. The National Cyber Security Centre gives small-business guidance on its official website.
Proof must be current and specific
Useful proof includes MFA screenshots, device lists, patch reports and backup-success reports. It can also include access reviews and training logs.
Date every item. Name an owner for every answer.
A bought tool is not a working control unless it is enabled. It must cover relevant systems and have fault checks.
Keep a controlled set of policies for your cyber insurance application. Auditors, larger customers and suppliers may also ask for these documents.
This pack can include an information-security policy and acceptable-use rules. It can also include access, password, backup and retention rules.
Add supplier risk procedures, payment-check instructions and a data-breach procedure. Each document should show approval and review dates.
Each document should name its owner and version number.
A policy alone does not prove that it works. Pair it with training acknowledgements, access-review results and supplier assessments.
Keep approved exceptions and records of overdue actions too. These show that someone followed up on gaps.
The most common error is answering from memory. A dated record is safer than a confident guess.
Use different checks for each policy stage
New applications, renewals and post-incident reviews need different proof. The underlying controls may still be the same.
New application and renewal checks
For a new policy, confirm staff numbers and your revenue range. List data types, cloud services, remote access and past incidents.
Identify systems that would stop trading if unavailable. This helps show the likely business interruption risk.
At renewal, compare the declaration with the last one. Record changes such as new cloud tenants or managed service providers.
Also record changes involving mergers, remote workers, suppliers and bank-detail procedures. Every answer must be true on the signing date.
Post-incident reviews need facts
After an incident, save logs, screenshots, emails and supplier notices. Keep key decisions too.
Do not rebuild records from memory. Memory can change after a stressful event.
Reviews may ask when you found the event. They may ask which accounts or devices it affected.
They may also ask what data was involved and when you told the insurer. If personal data may be exposed, the Information Commissioner’s Office explains duties on its official website.
A post-incident answer needs facts from the time. It should not rely on a later reconstruction.
Build a question-by-question evidence matrix
A readiness matrix gives each likely insurer question an answer. It also records proof, owner, status, date and corrective action.
Copy this working matrix
| Insurer question | Acceptable evidence | Likely impact | Priority and editable fields |
|---|
| Is MFA active for email, admin, remote and finance access? | Settings screenshots, coverage report, access review | Eligibility, excess, ransomware terms | Blocker | Owner: ___ | Status: ___ | Action: ___ |
| Are devices patched and protected? | Asset list, patch report, endpoint coverage report | Premium, exclusions, claim scrutiny | Blocker | Owner: ___ | Status: ___ | Action: ___ |
| Can critical data be restored? | Backup logs, immutable settings, restore-test record | Business interruption and extortion terms | Blocker | Owner: ___ | Status: ___ | Action: ___ |
| How are suppliers and personal data managed? | Data map, supplier register, contracts, encryption settings | Privacy liability and data-breach scope | 30 days | Owner: ___ | Status: ___ | Action: ___ |
| How are payment-change requests checked? | Callback policy, training log, dual approval record | Fraud sub-limit or exclusion | High | Owner: ___ | Status: ___ | Action: ___ |
Treat missing MFA as a coverage blocker for email, administrator accounts and remote access. Do the same for unrecoverable critical backups and unsupported online devices.
An incident-response plan without an owner is also a blocker. Set 30-day targets for missing device lists and overdue access reviews.
Set the same target for supplier checks and outdated training. These are often easier to fix than core control gaps.
Evidence dates matter: Check key MFA, endpoint and backup proof within the last 30 to 90 days. A restore test may happen less often. It should cover systems you would actually need to recover.
From question to reliable declaration
1. Read the exact question
→
2. Check all relevant systems
→
3. Save dated proof
→
4. Name owner and action
An insurer may ask if an incident plan can work under pressure. Keep records showing the current plan owner and contact lists.
Record escalation routes, decision authority and the ransomware playbook. Keep records from recent exercises too.
A useful test record names the scenario used. It might cover a compromised Microsoft 365 account or encrypted file server.
It should list the people involved and decisions made. Record recovery times and follow-up actions.
These records support answers about readiness. They can also show improvement after a near miss or past incident.
For endpoint protection, separate deployment from effective coverage. Underwriters may ask if endpoint detection and response (EDR) covers laptops, servers and remote devices.
They may ask whether alerts are watched. They may also ask how you handle unmanaged or unsupported devices.
Keep an endpoint coverage report. Compare the security-console count with the asset list.
Investigate any gaps. A control cannot protect a device it cannot see.
A patch report should show the age of critical patches. It should show devices where installation failed too.
It should also show the recorded route for fixing failures. This matters for ransomware insurance requirements.
Unpatched online systems can affect eligibility, exclusions or claim checks. Inactive endpoint controls can have the same effect.
Compare cyber questions with other insurance
Cyber forms have more detail than property or public liability forms. Digital controls can change quickly.
Cyber, property and liability compared
| Insurance type | Typical evidence | Review timing | Common loss concern |
|---|
| Cyber insurance | MFA, backups, patching, incident plan | Every 30 to 90 days for key controls | Ransomware, breach, email fraud |
| Property insurance | Asset values, alarms, surveys | At renewal or after major changes | Fire, flood, theft |
| Public liability | Turnover, activities, contracts | At renewal or service changes | Injury or property damage |
GDPR and cyber cover are different
UK GDPR and the Data Protection Act 2018 set duties for personal data. Cyber insurance may help with some breach-response costs where the wording allows.
It does not remove legal duties. It does not guarantee cover for regulatory fines.
Keep proof of data lists, retention rules and encryption. Keep access reviews and breach procedures too.
Do not make broad claims about your controls. Answer only what your evidence supports.
This checklist is not legal advice or insurance-broking placement advice. It is not a policy wording review or incident-response support. It is less relevant for firms without meaningful digital systems or sensitive data. Even very small firms can face email fraud and ransomware risks.
Questions & answers
What questions are asked in cyber insurance
Insurers often ask about MFA, endpoint security, patching, backups and phishing controls. They also ask about suppliers, data handling and incident response.
They may ask about turnover, past incidents and remote access. Payment fraud controls may also be checked.
Does cyber insurance require MFA?
Many insurers expect MFA for email, remote access and privileged accounts. They may also expect it for cloud administration and finance systems.
MFA that covers only some users may not meet the insurer’s stated requirement. The same applies where key systems remain outside MFA.
What documents do I need for cyber insurance?
Useful documents include device lists, MFA reports and patching reports. Keep backup logs, restore-test records, training logs and an incident plan.
Proof dated within 30 to 90 days is often more credible. This applies to active controls rather than old documents.
Can a wrong answer affect a cyber insurance claim?
Yes, an inaccurate or incomplete declaration can lead to closer checks. It may affect how a claim is handled.
The outcome depends on the policy wording and question asked. It also depends on what the business knew and the relevance to the loss.
Submit answers that match your real controls
The strongest application matches your real setup. It has dated proof and names sensible actions for gaps.
Check email, payments, administrator access and backups first. Then update the matrix before renewal and after major system changes.
Update it after incidents too. Honest records give your broker and insurer a clearer starting point.
Related sources
These articles can help you explore the topic in more depth: