Skip to content
All insights
ProtectMicrosoft SecurityComplianceJune 9, 2026

Passing the cyber insurance questionnaire: the controls underwriters make you attest to

The Short Version
  • A cyber insurance application is a controls questionnaire, and the insurer decides coverage based on the security you can truthfully say you have in place.
  • Carriers consistently ask about MFA, endpoint protection on every device, managed patching, backups, email filtering, and security awareness training for staff.
  • A single exception like an owner's self-built machine without antivirus turns a truthful 'yes' on 'every device' into a 'no' and can get a later claim denied as an inaccurate application.
  • The right order is to close the gaps first and apply second, standing up the controls and verifying no exceptions before signing the application.
Bottom line: Cyber insurance is underwritten against a controls checklist, so implement and verify every control before you sign, because a policy built on a truthful questionnaire is the one that pays out.

In that same conversation, the attorney admitted the firm carried no cyber insurance and didn't know where to start. "I'm the weak link," he said. "The antivirus is on everybody's computer except mine, because I set up my own." That one sentence is exactly the kind of thing that gets a claim denied.

A policy is underwritten, not just bought

Many small firms only think about cyber insurance after a scare. Then they discover it doesn't work like buying a tool off a shelf. You apply, and the application is a controls questionnaire. The insurer is deciding whether to cover you based on what security you can truthfully say you have in place.

The questions are fairly consistent across carriers. They want to know whether you have:

  • Multi-factor authentication (MFA) on your accounts.
  • Endpoint protection on every device.
  • Managed patching that keeps systems up to date.
  • Backups.
  • Email filtering.
  • Security awareness training for staff.

Why one exception is a real problem

Notice the phrase "every device." The owner's self-built machine, the one without antivirus, is exactly the gap that turns a truthful "yes" into a "no." And the stakes aren't just a rejected application. If you attest to controls you don't have and later file a claim, the insurer can deny it on the grounds that the application was inaccurate. You pay premiums for years and get nothing at the worst possible moment.

An Attestation Is a Legal Statement

An attestation is a legal statement, not a wish list. Checking "yes, MFA everywhere" when one account is exempt is exactly the kind of discrepancy a carrier looks for when a claim lands.

The right order of operations

The fix is unglamorous and effective: close the gaps first, then apply. An IT partner can do both halves, stand up the controls (MFA across the board, endpoint protection on every machine, patching, backups, filtering, training), and then help complete the questionnaire so your answers are accurate and your coverage holds.

Implement, Verify, Then Sign

The sequence is the point. Implement the controls, verify there are no exceptions hiding in the corner, and only then sign the application. A policy built on a truthful questionnaire is one that pays out.

If you're shopping for cyber insurance, or you have a policy and aren't certain your environment matches what you attested to, that's worth checking before you ever need to file. We're happy to take a look. Let's talk it through.

See where you stand. Then move forward.

Book a free intro call. We'll talk through where you are today and map a plan for growth, protection, automation, and alignment.

30 minutesNo obligationGet an initial estimate within one week