Cyber insurance readiness for US businesses: Answer the insurance questionnaire with yes, and have the evidence behind every yes.
Cyber insurance applications have become technical. They ask whether multifactor sign-in is enforced, whether devices are managed and protected, whether backups would survive ransomware, and whether anyone would notice an attack. Answering no can cost you coverage or price. Answering yes when it is not quite true can cost you a claim, because a misstated application can give the insurer grounds to dispute one. We get the controls in place before renewal and document each answer.

- Before renewalControls in place, not promised
- EvidenceA document behind each answer
- AccurateAnswers that match reality
- 5 minP1 response, delivered remotely
Eight areas that come up on almost every questionnaire.
Multifactor sign-in, enforced everywhere it is asked
Applications typically ask about multifactor for email, remote access, and administrator accounts separately. Enforced means every account, with exceptions documented, not available to anyone who turns it on. Legacy authentication protocols that bypass multifactor need closing too.
Endpoint detection and response
Questions about EDR are now standard: whether it is deployed on every device and server, and whether someone watches the alerts. We deploy and tune it on the devices you have, and make sure the coverage claim matches the device inventory.
Backups that survive ransomware
Insurers ask whether backups are separated from the main network, protected against deletion, and tested. Backups that ransomware can reach and encrypt are not the backups the question is about. We set them up, and we test a restore so the answer is proven rather than assumed.
Email security and mail authentication
Filtering, protection against impersonation, and the SPF, DKIM, and DMARC records that stop others sending mail as you. Email remains the most common way attacks start, and the questions reflect that.
Privileged access and patching
Who holds administrator rights, whether they use separate accounts for it, and how quickly security updates reach devices and servers. Both are common questions, and both are easy to overstate if nobody has checked recently.
Logging and detection
Whether you would notice an attack in progress, and whether you keep enough logs to investigate one afterwards. We switch on and retain the logging in Microsoft 365, Entra ID, and your endpoints, and make sure alerts reach a person.
An incident response plan
A written plan that says who does what in the first hours, reachable when your network is not, and rehearsed at least once. Many applications ask whether you have one; a claim goes far better when you have actually used it.
Security awareness training
Training and phishing simulation for staff, with records of who completed it. A common question, and one where the evidence is easy to produce once the program is running.
An application is a set of statements you are relying on later.
The questionnaire is easy to treat as a form to get through. It is better treated as a description of your security that you may need to stand behind after an incident.
- Answer what is true today, not what is planned. If a control is in progress, say so; your broker can tell you how to present it.
- Watch the scope of each question. "Multifactor for remote access" and "multifactor for all users" are different questions with different answers.
- Keep the evidence. A configuration export, a policy, or a screenshot dated near the application date settles questions quickly if they come up later.
- Read the policy terms with your broker. How your specific policy treats misstatements and exclusions is a question for them and your counsel, not for us.
Four positions we take.
We start well before the renewal date
Controls take time to deploy properly, and some, like enforced multifactor, need user communication first. Starting a few months ahead turns the renewal into paperwork rather than a rush.
Every answer gets a document
For each control the application asks about, we record what is in place, how it is configured, and when it was checked, so you can answer the insurer, and any follow-up from their assessor, with substance.
We do the security, not the insurance
We are not brokers or attorneys and do not advise on policies or coverage. We make the controls real and the evidence available; your broker handles the policy and your counsel any legal questions.
The controls keep running after renewal
A control that lapses after renewal is a problem waiting for the next claim. Managed clients keep monitoring and the standard response commitments: five minutes on critical, ten on high, thirty on the rest.
Four situations we see before renewals.
A small business renewing for the first time with new questions
Last year the application was a page. This year it asks about EDR, backups, and multifactor in detail. We work through it with you and close the gaps before the date.
A company told its premium will rise or coverage will change
Often the reason is a specific missing control. Putting it in place and documenting it gives your broker something concrete to take back to the insurer; the outcome is theirs to decide.
A regulated business with overlapping requirements
Healthcare and financial services firms answer similar questions for HIPAA, GLBA, auditors, and insurers. Much of the evidence serves all of them, so we build it once.
A company that needs coverage to win contracts
Customers and lenders increasingly require proof of cyber coverage. Getting insurable, and staying that way, becomes part of doing business.
Four steps from questionnaire to renewal.
- 1
Read the questionnaire against reality
We go through your application, or last year's, and check each answer against how your environment is actually configured.
- 2
Close the gaps, in order
Multifactor, endpoint protection, backups, email security, logging, and the rest, prioritized by what the application asks and what reduces the most risk.
- 3
Document each control
A dated record of what is in place for every question, ready for the application and any follow-up from the insurer.
- 4
Keep it in place
Monitoring and periodic checks so the answers stay true between renewals, and next year's application takes an afternoon.
What US businesses ask about cyber insurance readiness.
The pages around this one.
Make every answer on the application true before you give it.
Send us your questionnaire, or last year's. We check each answer against your environment, close the gaps in order, and document every control before renewal.
Related Services
Explore more solutions that work great with this service
Tenant Security Baseline
Documented controls mapped to CIS
Learn moreMFA Solutions
Multi-factor authentication implementation for US businesses on
Learn moreEndpoint Security
Endpoint security for US businesses using Microsoft Defender for
Learn moreIncident Response Plan Development
Incident response plan development for US organizations: decision
Learn moreSecurity Awareness Training Programs
Security awareness training programs for US businesses: role-based
Learn moreCybersecurity Audit
Security assessment and compliance audit
Learn moreIT Compliance
HIPAA, SOC 2, NIST, CMMC, CCPA readiness
Learn more