Home / Cyber insurance questionnaire guide

The cyber insurance questionnaire, question by question

What carriers actually ask on an application, what the underwriter is assessing behind each question, what evidence answers it, and the traps that turn a routine form into a claim dispute.

Descriptive reference, not advice. Question wording below is paraphrased generically from common US carrier forms.

The document

What is a cyber insurance questionnaire?

A cyber insurance questionnaire is the carrier-issued set of security control questions your organization answers to obtain or renew a cyber policy. It arrives in three main forms: the application for a new policy, the renewal application each policy year, and the ransomware supplemental, an add-on form that drills into the controls most correlated with ransomware loss.

The answers are not a survey. They are representations the carrier relies on to price and bind the policy, and some policies attach the signed application as a condition precedent to coverage. When a claim is investigated and a material answer turns out to have been wrong, carriers have sought to rescind the policy or deny the claim, as in Columbia Casualty v. Cottage Health (2015) and Travelers v. International Control Services (2022). Whether that succeeds depends on materiality and state law, but the safe operating assumption is simple: every answer should be verifiably true on the day you sign.

Who fills it out, and why it goes wrong

The form is usually signed by an officer or risk owner, but the facts live with IT and security. In practice the questionnaire gets completed one of three ways, and each has a failure mode:

  • Answered from memory. The person filling it in believes MFA is on and backups run, so they check yes. Memory describes the intended state, not the deployed one.
  • Split across email threads. Fragments go to IT, risk, and the broker; answers come back without evidence and get transcribed. Nobody sees the whole picture, and nobody owns accuracy end to end.
  • Copied from last year. The renewal starts from the prior application. Every control that drifted in twelve months, such as a new admin account, a broadened MFA exclusion, or a lapsed restore test, is silently re-attested.

All three produce the same output: a signed document whose answers no one has checked against the live environment. That gap between what was attested and what is deployed is exactly what insurance posture measures.

Question by question

The six control areas, and what each question really asks

Nearly every US carrier form concentrates on the same six areas. Wording varies by carrier; the paraphrased versions below reflect the common pattern, not any single carrier's form.

1. Multifactor authentication

Typical question"Is multifactor authentication required for all email access, all remote network access, and all administrative or privileged accounts, including vendor and service accounts?"

What the underwriter is assessing: whether a stolen password alone can reach email, the VPN, or an admin console. MFA scope is among the most heavily weighted answers on the form because credential-based intrusion remains the leading path into ransomware and funds-transfer losses.

Evidence that answers it: Conditional Access or equivalent policy exports showing enforcement for all users and all admin roles, the list of excluded accounts with justification, and confirmation that legacy authentication protocols that bypass MFA are blocked.

Common trap: answering yes because MFA is "enabled" for the tenant. Enabled is not enforced. Excluded break-glass accounts, service accounts, legacy authentication protocols, and per-user exceptions all make a blanket "yes, all accounts" answer false while the dashboard still says MFA is on.

2. Backup and recovery

Typical question"Are backups of critical systems maintained offline, offsite, or in an immutable state, encrypted, and tested for restoration within the last 12 months?"

What the underwriter is assessing: whether a ransomware event becomes a restore project or a ransom negotiation. The question is really three: can the attacker reach and encrypt the backups, do the backups actually cover the systems that matter, and has anyone proven a restore works.

Evidence that answers it: backup configuration showing immutability or segregation from production credentials, the coverage list of protected systems, and a dated restore test record from the last 12 months.

Common trap: equating "backups run nightly" with what was asked. Backups reachable with the same domain admin credentials an attacker would hold are not segregated, and a restore that has never been tested is an assumption, not a control.

3. Endpoint detection and response

Typical question"What percentage of endpoints and servers are covered by an EDR solution, and is it monitored 24/7 by internal staff or a managed provider?"

What the underwriter is assessing: detection speed. EDR coverage is a proxy for whether an intrusion is caught in hours or discovered weeks later as encryption. The percentage matters because attackers pivot to the unmonitored machines.

Evidence that answers it: an onboarding or coverage report from the EDR console reconciled against the full device inventory, plus the monitoring arrangement (SOC, MDR contract, or internal on-call).

Common trap: reporting the percentage of known devices. Coverage measured against the EDR console's own inventory is circular; servers, legacy machines, and unmanaged endpoints that were never onboarded do not appear in the denominator.

4. Privileged access

Typical question"How many users hold domain, global, or equivalent administrative privileges, and are privileged accounts separated from daily-use accounts and reviewed periodically?"

What the underwriter is assessing: blast radius. Each standing admin account is a full-environment compromise waiting on one phish. The count, separation from daily-use identities, and review cadence together indicate whether privilege is managed or accreted.

Evidence that answers it: a current export of privileged role assignments, evidence of separate admin identities, just-in-time elevation if used, and the record of the last access review with removals actioned.

Common trap: counting only the admins you remember. Role assignments accumulate: former staff, vendor accounts, and "temporary" grants from past projects routinely push the real number well past the answer on the form.

5. Email security

Typical question"Do you use email filtering and authentication controls such as SPF, DKIM, and DMARC, and do you conduct phishing awareness training?"

What the underwriter is assessing: exposure to the two dominant loss drivers that start in the inbox: business email compromise and phishing-delivered malware. Authentication records also determine how easily your own domain can be spoofed against your customers and payment counterparties.

Evidence that answers it: the published SPF, DKIM, and DMARC DNS records with the DMARC policy value, anti-phishing and filtering policy configuration, and dated training or simulation records.

Common trap: a DMARC record set to p=none. A monitoring-only policy exists but enforces nothing; answering "DMARC implemented" while spoofed mail still delivers overstates the control the underwriter thinks it is pricing.

6. Incident response

Typical question"Do you have a written incident response plan, has it been tested in the last 12 months, and how long are security logs retained?"

What the underwriter is assessing: claim severity. Two otherwise identical intrusions produce very different losses depending on whether the response is rehearsed and whether logs exist to scope the breach. Thin logging inflates forensic cost and can force worst-case breach notification.

Evidence that answers it: the plan document with an owner and revision date, a record of the last tabletop or live exercise, and the configured log retention periods for identity, email, and endpoint telemetry.

Common trap: attesting to a plan that exists as a document and nothing else. A plan no one has exercised, with contacts that have left and retention defaults never raised, satisfies the letter of "written" and fails everything the question is for.

Summary: what each questionnaire section assesses and the trap that most often makes the answer wrong. Wording paraphrased from common US carrier forms.
Control areaUnderwriter is really askingMost common trap
MFACan a stolen password alone get in?"Enabled" reported as enforced; exclusions and legacy auth ignored
Backup and recoveryIs ransomware a restore or a ransom?Backups reachable with production credentials; restore never tested
EDRHours to detect, or weeks?Coverage measured against the console's own inventory
Privileged accessHow big is one phish's blast radius?Admin count answered from memory, not a role export
Email securityHow exposed to BEC and spoofing?DMARC at p=none reported as implemented
Incident responseHow bad does a claim get?Written plan attested, never exercised, logs at defaults
Method

How to answer a questionnaire accurately

The pattern that avoids every trap above is the same for all six sections: verify against the live environment, attach evidence to each answer, and label anything you cannot verify.

  • Verify, do not recall. For each question, check the actual configuration: the policy export, the role assignment list, the DNS record, the backup job. If the check contradicts the intended answer, you have found a gap while it is still cheap.
  • Keep evidence per answer. A dated artifact behind every answer means the signer attests to verified facts, and if a claim is ever investigated, you can show what was true when you signed.
  • Flag attested-only answers. Some questions cannot be verified from configuration (a tabletop exercise, a vendor's practice). Mark those as attestations, name the person who stands behind each one, and keep whatever supporting record exists.
  • Disclose rather than round up. A precise answer with a known exception, such as MFA enforced with two documented break-glass exclusions, is a better representation than a clean "yes" the environment contradicts.

Done manually, this is the days-to-weeks part of the process, which is why our renewal readiness checklist starts the clock 90 days before renewal. The control-by-control detail of what carriers expect lives in the cyber insurance requirements guide.

Automation

How Insurance Posture Analyzer automates the questionnaire

The verify-evidence-flag loop above is exactly what Insurance Posture Analyzer runs as a product.

  1. 1

    Upload any form

    Bring the carrier's application, renewal application, or ransomware supplemental in any format. Questions are extracted and matched to a canonical library written in our own wording to reflect the control topics that recur across US cyber application and ransomware supplemental forms; no carrier's form is republished, so one set of verified answers maps across carrier wordings.

  2. 2

    Answer with attestations

    Answer each question from extracted documents and attestations. Answers that only a human can make stay clearly labeled as attested, with the evidence file stored alongside.

  3. 3

    Scans cross-check mapped answers

    Read-only scans of Microsoft 365, Entra ID, and Azure cross-check each mapped answer and flag drift when the environment contradicts what was attested. Gaps are graded by coverage consequence, and a broker-ready drift brief collects the evidence in one place. Scheduled rescans catch drift between renewals.

FAQ

Cyber insurance questionnaires, answered

Are questionnaire answers legally binding?

They are representations the carrier relies on when it prices and binds the policy, and some policies attach the application as a condition precedent to coverage. A material misstatement can become a ground for rescission or claim denial, as carriers argued in Columbia Casualty v. Cottage Health (2015) and Travelers v. International Control Services (2022). Whether that succeeds depends on materiality and state law, so treat every answer as one you may need to stand behind during a claim.

Can I reuse last year's answers?

Use last year's application as a checklist, not a source. Copying answers forward is one of the most common ways wrong answers reach a renewal, because environments drift: MFA exclusions accumulate, admin accounts get added, backup jobs change. Re-verify every answer against the live environment before signing, and treat anything you cannot verify as a gap to close or disclose.

What is a ransomware supplemental?

An additional questionnaire many carriers attach to the main application that drills into the controls most correlated with ransomware loss: MFA scope, backup immutability and restore testing, EDR coverage, remote access exposure, and end-of-life systems. Its answers often drive ransomware-specific terms such as sublimits and coinsurance, so it carries as much weight as the main application.

How long does a questionnaire take?

Filling in the form takes hours; answering it accurately usually takes days to weeks, because most questions require checking the live environment and collecting evidence across IT, security, and risk owners. Starting roughly 90 days before renewal leaves time to remediate what verification uncovers. Our renewal readiness checklist lays out that timeline.

Who should fill it out?

An officer or risk owner usually signs, but the facts live with whoever administers identity, backups, endpoints, and email. The pattern that works: one coordinating owner, named contributors per control area, and evidence attached to each answer, so the signature attests to verified facts rather than a compiled email thread.

Check your questionnaire against your environment

Upload your carrier's application, connect a read-only account, and see which answers your live Microsoft 365, Entra ID, and Azure configuration actually supports, before your signature says they all do.

Start your assessment