Skip to content

Strategy6 min read

What cyber insurers now expect from you

Insurers have stopped taking your word for it. The controls on the questionnaire, explained, and how to prove you have them.

By Ventiq ·

A blue glass umbrella sheltering three small glass blocks

A few years ago, cyber insurance was easy to buy. You ticked a box saying you had antivirus, and a policy arrived. After several years of expensive ransomware and payment-fraud claims, insurers changed their approach. The proposal form now asks detailed questions about specific controls, premiums depend on the answers, and a claim can be denied if the answers turn out to be wrong.

That makes the questionnaire worth taking seriously, and worth understanding before it lands.

The questions you should expect

The exact wording varies by insurer, but almost every proposal form now asks about the same handful of controls. They line up closely with the Australian Signals Directorate’s Essential Eight, which is no accident.

Multi-factor authentication. Is it enforced for all users on email? On remote access? On administrator accounts? “Available but not enforced” is usually treated as “no”.

Backups. Are they taken regularly, kept separate from your network (so ransomware cannot encrypt them too), and tested by actually restoring from them? Many insurers now ask when you last tested a restore.

Endpoint protection. Do your computers have modern endpoint detection and response (EDR) rather than old-style antivirus, and is someone monitoring the alerts?

Patching. How quickly are security updates applied to operating systems and applications? Is anything running unsupported software?

Email security. Do you have protection against phishing and impersonation, and are SPF, DKIM and DMARC configured for your domain?

Administrative access. How many people have admin rights, and do they use separate accounts for admin tasks?

Staff training. Do staff receive security awareness training, and how often?

Incident response. Do you have a written plan for what happens when something goes wrong, and who to call?

Why “I think so” is dangerous

The proposal form is a legal document. If you declare that multi-factor authentication is enforced for all users and a claim later reveals that the finance team was excluded “because it was annoying”, the insurer may decline the claim, and the business wears the loss. The person signing the form, usually a director, needs to know the answers are true, not assume they are.

How to turn the questionnaire into an advantage

Treat it as a checklist, not a test. The controls insurers ask about are the controls that actually stop attacks. Implementing them properly reduces the chance you ever claim, as well as the premium.

Keep evidence, not just intentions. A screenshot of the policy enforcing multi-factor authentication. The log from the last test restore. The patching compliance report from last month. When the evidence exists, the questionnaire takes an hour instead of a week, and renewal becomes routine.

Make someone accountable. Directors are expected to oversee cyber risk, but they cannot personally verify every setting. Someone, inside or outside the business, should own the controls, keep the evidence current and report on it in plain language. That is the job we do under Technology Strategy & Governance, with the technical work delivered through our Cyber Security & Compliance service.

A practical sequence

  1. Get the questionnaire from your broker early, before renewal.
  2. Answer it honestly, including the gaps.
  3. Close the gaps in order of impact: multi-factor authentication, backups, admin rights, patching, email security.
  4. Collect the evidence as you go.
  5. Submit with confidence, and keep the evidence folder for next year.

If you would like a quick read on where you stand before the form arrives, the free Essential Eight readiness check covers most of what insurers ask, in two minutes.

Next step

Let us make your technology secure, simple and accountable.

Tell us what is working, what is not and where the business is heading. We will give you a clear, practical path forward.