Cyber insurance has changed. A few years ago you could get cover by signing a form. Now insurers ask detailed questions about your security controls, premiums move based on your answers, and a wrong answer can void a claim when you need it most.
The questions, at least, are remarkably consistent. Whether it’s a proposal form from a major insurer or a pre-renewal questionnaire from your broker, the same handful of controls come up every time. This is the checklist.
1. Multi-factor authentication
The first question on nearly every proposal form, and increasingly a condition of cover rather than a discount. Insurers typically want MFA on:
- Email and cloud applications (Microsoft 365, Google Workspace)
- Remote access (VPN, remote desktop)
- Administrator and privileged accounts
“Mostly” is not an answer they like. Expect to be asked whether MFA is enforced for all users, and to evidence it. See our MFA control for what good looks like.
2. Backups - and proof they work
Ransomware drives most cyber claims, so insurers care a lot about your ability to recover without paying. They’ll ask:
- Are critical systems and data backed up regularly?
- Are backups kept offline, offsite, or otherwise separated from your network?
- Have you actually tested a restore?
That last one trips people up. A backup you’ve never restored is a hope, not a control. Foundation covers this in backing up critical data and validating backups.
3. Patching and supported software
Insurers ask how quickly you apply security patches and whether you’re running end-of-life software. Unsupported operating systems and unpatched internet-facing systems are among the most common reasons for declined cover or loaded premiums.
4. Staff security training
Most incidents start with a person, not a firewall. Expect questions about whether staff receive regular cybersecurity awareness training, whether new starters are trained at induction, and whether you run phishing simulations.
5. An incident response plan
Insurers want to know that if something happens, you won’t be improvising. They ask whether you have a documented incident response plan, who’s responsible for invoking it, and whether it’s been tested or rehearsed. Some also ask about business continuity and disaster recovery plans.
6. Access control and administrative privileges
Who has admin rights, and why? Insurers ask whether administrative access is restricted, whether privileged accounts are reviewed, and how leavers are removed from systems.
The real problem: evidencing it
Most IT managers can answer these questions verbally. The hard part is evidence. Brokers and insurers increasingly want something on paper - and “trust me” doesn’t move a premium.
This is where a structured assessment earns its keep. A Foundation Cyber Security assessment covers every control above - they map directly to controls in the framework - and produces the evidence pack the insurance conversation needs:
- A maturity assessment across all 47 controls, including the ones insurers ask about
- A prioritised task list showing gaps are known and being managed
- A risk report written for a non-technical audience
- Alignment to recognised frameworks (Essential Eight, CIS, NIST 800-53, ISO 27001)
Handing your broker a current assessment does two things. It makes the proposal form fast and accurate, and it shows the insurer an organisation that manages security deliberately - which is exactly what underwriters price for. It also protects you at claim time: your answers are backed by a documented assessment, not a best guess from renewal day.
Run the checklist on yourself
Before your insurer does it for you. Take the free 5-question Quick Security Check - it covers training, backups, patching, endpoint protection, and logging in about 2 minutes. Then create a free account and run the full 47-control assessment in the Foundation platform to build the evidence pack your next renewal will ask for.