The cyber insurance questionnaire is one of the most quietly dangerous documents a small business signs. It looks like paperwork. It reads like a checklist. And the temptation, when you hit a question you’re not sure about, is to tick “yes” and move on so the application keeps flowing. That single instinct is how businesses end up paying premiums for years and then watching a claim get denied at the worst possible moment. Let’s walk through how to fill these out accurately, so the coverage you’re paying for is actually there when you need it.
Why honesty is the whole point
A cyber insurance application is part of the contract. The answers you give are representations the insurer relies on to decide whether to cover you and at what price. If you state that you have a control in place and you do not, and a loss happens that the control would have addressed, the insurer can argue the policy was based on a material misrepresentation. Depending on the policy and state law, that can mean reduced payment or a denied claim, after you have paid every premium.
This is not a rare edge case. As insurers have tightened underwriting, they have gotten far more willing to investigate after a breach and to push back when the application does not match what they find. The honest answer that earns you a slightly higher premium or a coverage condition is almost always cheaper than the optimistic answer that voids your claim. We cover the broader picture of what carriers now demand in what cyber insurers require and why renewals get denied.
So the goal is not to look as secure as possible. It is to describe your environment exactly as it is.
The questions that trip businesses up, and what they really mean
A few questions cause more accidental misstatements than the rest. Here is what they are actually asking.
“Do you require multi-factor authentication?” This is rarely a single yes-or-no. Carriers usually want to know specifically whether MFA protects email, remote access (VPN and remote desktop), and administrative or privileged accounts. “We have MFA” can be technically true while the exact systems they care about are unprotected. Answer per system, and if you’re not certain MFA is enforced everywhere they ask about, the truthful answer is “not on all of them.”
“Do you have endpoint detection and response (EDR)?” Traditional antivirus is not EDR. If you’re running basic built-in antivirus and the question asks about EDR or managed detection and response, the honest answer is no, even if you feel protected. Don’t let the word “antivirus” in your head become a “yes” to “EDR” on the page.
“Are backups tested and kept offline or immutable?” Having backups is not the same as testing them, and a backup an attacker can reach and delete is not really protecting you. If you have never done a test restore, or you cannot confirm your backups are immutable or separated from the production network, do not claim that you have. This is a question where the truthful answer often reveals a real gap worth closing.
“Do you provide regular security awareness training?” A single onboarding video three years ago is not “regular.” If training is not ongoing, say so.
“Do you have a written incident response plan?” A plan that lives only in someone’s head does not count. If it is not written down and your team has not seen it, the answer is no.
Across all of these, the pattern is the same: the question is more specific than it first appears, and the honest answer is often “partially” or “no.” That is fine. It is far better than a “yes” you cannot back up.
How to answer accurately when you’re not sure
When you genuinely don’t know whether a control is in place, don’t guess in either direction. Find out before you sign.
Pull the people who actually know. If you have an IT provider, send them the questionnaire and ask them to confirm each technical item against your real configuration, in writing. Internal IT can do the same. The phrase you want back is not “yeah, we’re good,” it is “here is exactly what is enabled and where.” That written confirmation also protects you, because it shows you took reasonable care to answer truthfully.
Where a control is partial, describe the partial state plainly. “MFA is enforced on email and VPN; we are deploying it to administrative accounts this quarter” is an honest, defensible answer that many underwriters will accept, sometimes with a short timeline condition. An accurate “in progress” beats a false “complete” every time.
If a question is ambiguous, ask your broker what it means before answering. Brokers field these all day, and a quick clarification prevents an unintentional misstatement. Keep a copy of how the question was explained to you.
The controls these questionnaires probe are the same layered protections we build and document under our People+ Framework, MFA, EDR, tested backups, training, and an incident response plan. When those are genuinely in place and documented, the questionnaire stops being a minefield and becomes a list of true statements.
Close the gaps the questionnaire exposes
Here is the useful side effect of answering honestly: the questionnaire becomes a free gap assessment. Every question you could not truthfully answer “yes” is a control worth a real conversation. Some you will close quickly and cheaply. Others you will document as “in progress” with a date. Either way, you now know where you stand, which is the same posture regulators and the rest of your compliance obligations reward.
Where to start
If a cyber insurance application or renewal is in front of you, don’t fill it out alone and don’t fill it out optimistically. Sit down with whoever manages your IT and confirm each control against reality, in writing, before anyone signs. If you’d like a second set of eyes, we’re happy to review a questionnaire with you and tell you plainly which answers your environment actually supports and which gaps are worth closing first. No pressure, just an honest read so your coverage holds when it counts.