The application is not a form. It is a set of declarations about controls you are stating you have — and an answer that was aspirational when it was ticked is the most expensive kind of mistake, because you find out at claim time.
Cyber insurance applications have changed. Five years ago they asked your revenue and industry. Now they ask specific technical questions, and the answers form part of the contract.
That matters more than it sounds. If you declare that multi-factor authentication is enforced on all remote access and a claim later shows it was not, the insurer has grounds to reduce or refuse the payout. The policy was priced on an assumption you supplied.
What they ask, and what it commits you to
| The question | What it actually means |
|---|---|
| Is MFA enforced on email and remote access? | On every account, including administrators and service accounts — not enabled for most people |
| Do you have endpoint detection and response? | EDR, not just the antivirus that shipped with the machine |
| Are backups offline or immutable? | A backup a compromised admin account cannot delete |
| Do you have a written incident response plan? | Written. Not a shared understanding of who to call |
| Do you apply security updates within a defined window? | And can evidence it, if asked |
| Do you provide security awareness training? | Delivered and recorded, not intended |
| Do you have email filtering and anti-phishing controls? | Configured beyond the defaults |
Answer them accurately, even when the answer is no
A 'no' costs you a higher premium or a condition to fix it within a period. An inaccurate 'yes' costs you the claim, at the exact moment you need it most.
The right sequence is to find out what is genuinely true, fix what is cheap to fix, then answer honestly about what remains. That is a fortnight of work, not a project.
The gaps we find most often at this stage
- MFA enabled but not enforced — legacy authentication still permitted, so some protocols never see the prompt.
- Backups that exist but are reachable with the same administrator credentials as everything else, so ransomware takes them too.
- No incident response plan in writing, only an assumption about who gets called.
- Local administrator rights on everyday user accounts, which almost every application now asks about.
- An old server still on the network that nobody wants to be responsible for.
Do this before you fill anything in
- Get the application form first and read the questions before answering any of them.
- Establish what is actually true — for MFA, that means checking enforcement rather than trusting the setting.
- Fix the cheap gaps. MFA enforcement and admin rights are usually days, not months.
- Write the incident response plan. One page naming who decides, who calls the insurer, and who talks to customers is worth more than a document nobody reads.
- Keep the evidence. If you are asked at claim time, the records are the answer.
A cybersecurity assessment before the application is not about passing it. It is about making sure every 'yes' on the form is one you could defend a year later, in a bad week, to somebody looking for a reason not to pay.
Frequently asked
Can we be refused a payout for an inaccurate answer?
Yes. Applications form part of the contract, and insurers have declined claims where a declared control was not in place. This is not a hypothetical risk — it is the specific reason to answer carefully rather than optimistically.
We are small. Do we really need cyber insurance?
That is a business decision, not a technical one. What we would say is that the controls the application asks about are worth having regardless of whether you buy the policy — the questions are a reasonable checklist of what actually reduces risk.
Our broker says we just need MFA. Is that right?
MFA is the single most common requirement and the most common gap. It is rarely the only one, and 'MFA is on' and 'MFA is enforced everywhere including administrators and legacy protocols' are very different statements.
How long does it take to be ready?
For a typical small business with Microsoft 365, usually a couple of weeks of focused work. The long pole is normally an old server or an application that breaks when you tighten something.