PS ProTech(305) 699-5652
← All posts

All professional firms

What cyber insurers ask, and how to be ready

· PS ProTech · 5 min read

A cyber insurance application used to be a page long. Today it reads like an audit. Insurers know which missing controls cause claims, and they ask about each one.

That makes the form useful: it's a list, written by people with money at stake, of what protects a firm like yours. Here are the questions you're most likely to meet and what a good answer looks like.

Why your answers matter

The application is part of your contract. If you say a control is in place and it isn't, the insurer may be able to reduce or refuse a claim when you need it most.

Two rules follow:

  • Answer what is true today, not what you plan to do.
  • Keep the evidence. A screenshot, a report or a dated policy for each yes.

The questions

Do you require multi-factor authentication?

Usually asked three ways: for email, for remote access to your network, and for administrator accounts. This is the question insurers care about most, and a no on any part of it can mean a declined application or a much higher premium.

A good answer: yes on all three, enforced for everyone, with a report from your email system showing it. See why MFA comes first.

Do you use endpoint detection and response?

Insurers distinguish between traditional antivirus and tools that watch for malicious behavior. They want the second kind on every computer and server.

A good answer: yes, on every device, with an inventory that matches your headcount. See endpoint security.

How are your backups protected?

Expect several parts: how often you back up, whether backups are kept separate from your network, and whether you've tested a restore. A firm with good backups doesn't need to pay a ransom.

A good answer: daily, stored separately, tested within the last quarter, with a note of the last restore. Many firms discover here that their cloud files aren't really backed up, which we explain in does Microsoft 365 back up your data?

Do you train staff and test them with simulated phishing?

Most claims start with a person being fooled. Insurers want regular training and proof it happened.

A good answer: training at least once a year, simulated phishing several times a year, and completion records. See security awareness training.

Do you filter email?

They're asking whether malicious links and attachments are screened before they reach staff, and whether others can easily send email pretending to be you.

A good answer: yes to both. See email security.

How quickly do you install security updates?

Insurers ask about critical updates specifically, often with a timeframe such as within thirty days. They also ask whether you run software the maker no longer supports.

A good answer: critical updates within days, applied automatically, with a report. No unsupported systems. See why software updates matter.

Do you verify changes to payment instructions?

This one covers funds transfer fraud, which is often a separate part of the policy with its own conditions. Some policies only pay if you followed a call-back procedure.

A good answer: a written rule that every payment change is confirmed by phone on a known number, signed by the staff who handle payments. See the call-back rule.

Do you have an incident response plan?

They want to know you won't lose days deciding what to do.

A good answer: a written plan with named contacts, reviewed in the last year. Our first hour of a ransomware attack is a starting point.

Who has administrator access?

Insurers ask whether everyday accounts have administrator rights. An attacker who lands on an administrator's machine gets everything.

A good answer: staff work with standard accounts, and administrator access is separate and limited to the people who need it.

What sensitive data do you hold, and how much?

The number of records drives the price, and firms often underestimate it. A small tax practice can hold Social Security numbers for thousands of people once you count spouses, dependents and prior years.

A good answer: a realistic count, and a policy for deleting what you no longer need.

Which outside companies can reach your systems or data?

Insurers increasingly ask about your vendors: your IT provider, your payroll service, your document storage, anyone with a login. Verizon's 2026 breach report found a third party involved in 48% of breaches (Verizon 2026 summary), and insurers have noticed.

A good answer: a short list of vendors with access, what each can reach, and confirmation that each uses multi-factor authentication. If you're choosing a provider, our ten questions to ask covers what to check.

Do staff use AI tools with client data?

A newer question, and one many firms can't answer. Insurers want to know whether confidential information is going into tools you don't control.

A good answer: a written policy naming the approved tools and what must never be entered. See a policy for staff using AI tools.

The answers that cause trouble

  • "Yes" meaning "mostly." MFA on email but not for the two partners who objected is a no.
  • "Our IT person handles that." Ask them, in writing, and keep the reply.
  • Guessing. If you don't know, find out. An honest "no, in progress" is far safer than a wrong yes.

Getting ready

Start two months before renewal.

  1. Get last year's application and the new one if it has changed.
  2. Mark each question yes with evidence, partly, or no.
  3. Fix the cheap, important gaps first: MFA, a restore test, the call-back rule.
  4. Build an evidence folder, with one document or screenshot for each yes. It also answers most client security questionnaires.
  5. Tell your broker what you've improved. Better controls can mean better terms.

Our 15-point security checklist covers most of what's on these forms and takes about an hour.

After the policy starts

Getting covered isn't the end of it. Three things keep the cover worth having.

Keep the controls in place. What you declared has to stay true all year. If you turn off multi-factor authentication for someone because it annoyed them, your application is no longer accurate.

Tell your broker about changes. A merger, a new office, a move to different software or a big jump in the records you hold can all affect your cover.

Know what to do on day one of an incident. Most policies require you to notify the insurer promptly and to use their approved lawyers and responders. Calling your own contacts first can cost you coverage. Keep the insurer's incident number in your one-page plan, next to your IT provider's.

Where we fit

Insurance and questionnaire support is part of our compliance support, included in the Secure plan. If a renewal is coming up, a free IT and cybersecurity review will show you where you stand first.

This is general information. Your policy and your broker are the authority on what your insurer requires.

See what it costs for your firm.

Build a plan in two minutes. No call required.