Canonical question library
A canonical question library is a deduplicated set of cyber insurance application questions built from many carrier forms, so one set of evidenced answers can pre-fill most of what each carrier asks while preserving per-carrier wording. Insurance Posture's library is written in our own wording to reflect the control topics that recur across US cyber application and ransomware supplemental forms; no carrier's form is republished. See the cyber insurance questionnaire guide for a question-by-question walkthrough.
Coinsurance
Coinsurance is a policy provision under which the insured bears a stated percentage of a covered loss alongside the insurer. In cyber policies it most often appears on ransomware and extortion coverage, where a carrier may pay only a portion of an extortion loss and the insured bears the rest. Some carriers have applied coinsurance to risks with specific control gaps.
Compliance posture
Compliance posture is the state of an organization's controls measured against a compliance framework such as SOC 2, ISO 27001, or HIPAA. It differs from insurance posture in what the controls are measured against: an auditor's criteria rather than a carrier's application questions. An organization can hold a clean audit report and still be unable to evidence the specific controls a carrier underwrites.
Condition precedent
A condition precedent is a contractual requirement that must be satisfied before an insurer's obligations under the policy attach. Some cyber policies attach application answers, or the continued operation of named controls, as conditions precedent to coverage. How such provisions are interpreted and enforced varies by policy wording and jurisdiction.
Cyber insurance questionnaire
A cyber insurance questionnaire is the carrier-issued application, renewal application, or ransomware supplemental. Its answers are representations the carrier relies on, and some policies attach them as conditions precedent. Most questionnaires concentrate on six control areas: MFA, backups, EDR, privileged access, email security, and incident response. See the full questionnaire guide and the requirements breakdown.