What your cyber insurance questionnaire is really asking

Your cyber insurance application is not a survey. It is part of the insurance contract, and the answers on it are what the carrier relies on when it decides whether to pay a claim. The practical advice that follows from that is simple: answer it the way you would answer a question under oath. Literally, narrowly, and only about things you can show evidence for.
We are writing this because the questionnaires have gotten much more specific over the last few years, and the process for filling them out usually has not. The form still arrives as a PDF full of yes and no boxes, and it still tends to land on whoever has room on their calendar that week.
What happens when an answer is too optimistic
In April 2022, an Illinois electronics manufacturer called International Control Services bought a cyber policy from Travelers. Its application stated that the company used multi-factor authentication to protect administrative and privileged access.
In May, the company was hit with ransomware. Travelers investigated and, according to its complaint, found that MFA was in place on the firewall but not on the company's other digital assets. On July 6, 2022, Travelers filed suit in federal court in Illinois asking to have the policy declared void from the beginning.
The case never reached a trial. On August 26, 2022, both sides filed a stipulation agreeing that the policy should be rescinded, null and void from inception, with no coverage available for past, present, or future claims.
We have no idea what was in anyone's head when that application was completed, and we are not going to guess. The useful lesson does not require bad intent. Someone was handed a yes-or-no question about a complicated environment, and yes was mostly true. Mostly true is not the standard these forms are measured against.
Reporting on that case: Insurance Journal, July 12, 2022 and August 30, 2022.
What the common questions are actually asking
The wording varies by carrier. The intent behind the questions does not. Here is the translation.
"Do you require multi-factor authentication for remote access, for administrative accounts, and for email?" That is three questions wearing one coat. It is very common to have MFA on Microsoft 365 email but not on the VPN. Or on every account except the two domain administrator accounts. Or everywhere except one service account that would break something if it were enforced. Those are all different answers.
"Are your backups segregated, offline, or immutable?" The carrier is asking one thing: if ransomware gets into your network holding a set of your credentials, can it also destroy your backups? A backup sitting on a network share that a domain administrator can reach is usually a no.
"Do you test your restores?" This is a request for a date. If the backup software reports success every night and nobody has actually restored anything in the last year, that is a no. It is one of the most common honest no answers we see.
"Is endpoint detection and response deployed on all endpoints?" All means all. Servers, the machine in the corner running the old line-of-business application, the laptop that only gets turned on at month end. Carriers ask for device counts because the space between "deployed" and "deployed everywhere" is exactly where claims come from.
"Do you have a written incident response plan?" Written, and findable by a human being at 11pm when the network is down and the file server it was stored on is encrypted.
"Do you have end-of-life or unsupported software in your environment?" For most organizations the truthful answer is yes, somewhere. Saying so up front is far better than being asked about it after a loss.
Why an inaccurate answer is so easy to give
In our experience this is almost never dishonesty. It is structural, and there are four usual causes.
The form goes to the person with room on their calendar, not the person with visibility into the systems. That is often an office manager, a controller, or an executive assistant, and none of them can reasonably be expected to know whether conditional access covers legacy authentication.
It gets forwarded to the IT provider with a note saying "can you take a look at this," and comes back with the boxes ticked and no explanation of how any of it was decided.
The vocabulary is genuinely technical. "Privileged access management" and "immutable" are not everyday business words, and a question you cannot parse is a question you tend to answer optimistically.
And the format punishes nuance. There is a yes box and a no box, and no box for "yes on 94 of our 97 machines, and here are the three."
How to answer one well
Make it a joint task. The person who owns the policy and the person who owns the systems should both be in the conversation, and both should be able to explain every answer out loud.
Answer narrowly and put the exceptions in writing. Carriers can price an exception. They cannot price a surprise, and an exception that surfaces after a claim is the expensive kind.
Ask for evidence rather than opinions. The screenshot of the conditional access policy. The date of the last successful test restore and what was actually restored. The endpoint agent count sitting next to your asset list.
Keep the completed form and that evidence in the same folder. If you have a claim two renewals from now, that folder is the thing that will matter.
Where the answer is genuinely no, you have two good options and one bad one. Fix it before you bind, or disclose it and accept how it prices. The bad one is typing yes and hoping the year goes quietly.
The questionnaire is also a decent free assessment
Set the insurance aside for a moment. That list of controls exists because carriers have claims data, and those are the controls that keep showing up on the paying side of it. If you work through the form honestly and end up with six no answers, you now have a prioritized security roadmap that somebody else built and paid for.
That is a real benefit, and it is available to you whether or not you ever file a claim. Some of the most productive projects we have run with clients started as a list of no answers on a renewal application.
If you want a second set of eyes
We have been doing this work from Ann Arbor for more than 25 years, we are vendor agnostic, and a good part of what we do is sitting with a client going through one of these line by line before it goes back to the broker. Some of our client relationships are measured in decades, and that kind of work is a large part of why.
We are happy to have that conversation whether or not we manage your systems. If you are staring at a questionnaire and want a second opinion on it, call us at (734) 929-1400 or reach out through the site. If we look at your environment and think you are in decent shape already, we will tell you that too.




Comments