Field notes

What your cyber insurance questionnaire actually asks for

It arrives with the renewal paperwork: a security questionnaire that used to be one page of checkboxes and is now several pages of specifics. Do you enforce multi-factor authentication? Do you run EDR? Are your backups tested, encrypted, and kept off-site? Your broker needs it back by Friday.

Here's a plain-English translation of what each question means, why insurers now care, and what a truthful "yes" looks like for a business your size. The usual disclaimer applies: we're an IT company, not your attorney or your broker.

Why the form got strict

Ransomware payouts spent years eating insurers' margins, so the industry changed posture: better security gets you coverage and better pricing, weak security gets you exclusions, higher premiums, or a declination. More important for you: the questionnaire is part of the application. Answers that turn out to be wrong give the insurer an argument to reduce or deny a claim, precisely when you need it most. The goal isn't to answer impressively. It's to answer truthfully, and to close the gaps before you sign.

The questions, translated

"Is multi-factor authentication enforced?"

They mean everywhere that matters: email accounts, remote access into your network, and any administrator account. One phished password should never be enough to get into your business. A real yes: MFA is enforced by policy, not left to each employee's diligence, and you could produce a screenshot of that policy setting today.

"Do you use EDR or next-generation antivirus?"

Traditional antivirus checks files against a list of known bad ones. EDR (endpoint detection and response) watches how machines behave and flags the pattern of an attack in progress, which is how modern intrusions actually get caught. A real yes: a business-grade EDR agent on every workstation and server, with alerts that reach a human who will act on them.

"Are backups encrypted, kept off-site, and tested?"

Attackers delete the backups they can reach before they encrypt anything; insurers know this. So the form asks for a copy an intruder inside your network can't touch, and proof the restore actually works. A real yes: the 3-2-1 pattern (three copies, two media, one off-site), plus a scheduled test restore with a date on it. "The backup job shows green" has convinced many owners who later discovered green meant nothing.

"Do you filter email and train staff on phishing?"

Nearly every small-business incident starts in an inbox, usually with an invoice swap or a payroll-change request. A real yes: modern filtering in front of your mail, sender authentication configured on your domain, and a short, recurring staff briefing on the scams that actually land. Fifteen minutes twice a year beats a poster in the break room.

"Are systems patched, and are any past end-of-life?"

They're asking whether updates happen on a schedule and whether anything in the building no longer receives security fixes at all. The old PC running the label printer counts. A real yes: a patching cadence you could state out loud, plus an inventory that would surface the forgotten machine in the corner. Specialty equipment that can't be patched freely (a POS station, a clinical workstation) gets isolated on the network and documented as an exception, which insurers respect far more than silence.

"How is access controlled?"

Individual accounts instead of shared logins, permissions matched to the job, same-day removal when someone leaves, and a password manager so "the password" isn't a sticky note or a group text. A real yes: you could name who has admin rights, and offboarding is a checklist, not a memory.

How small businesses actually get there

Read the list again and notice what it isn't: it isn't a big-company technology stack. It's hygiene, and most of it gets done once and then maintained. We bundle exactly this as a fixed-scope security hardening project (MFA rollout, password manager, email security, staff training), typically measured in days, not months, and then the monthly plan keeps the evidence current: patch records, backup test dates, access reviews. Come renewal time, the questionnaire becomes an afternoon instead of a scramble.

If you handle patient or client records, the same work does double duty toward your privacy obligations; we cover that side in our guide for medical and dental practices.

And answer honestly. A "no" on the form might raise your premium. A false "yes" can surface after an incident, during the forensic review, with your claim on the line. If the truthful answer today is no, the move is to make it a yes before the renewal, not on paper first.

Common questions

We're a small shop. Are we really a target?

The attacks that hit small businesses are automated; nobody checked your headcount first. Phishing kits and ransomware crews work in volume, and small companies are attractive precisely because the defenses above are so often missing.

What if we're not sure whether our answer is true?

That uncertainty is the finding. An afternoon of verification (is MFA actually enforced, or just available? when did a restore last succeed?) is cheap compared to discovering the real answer during a claim.

Will doing all this lower our premium?

Often it helps, and some carriers require it just to quote. But the honest pitch is different: the controls above are what make the incident survivable at all. The premium discount is a bonus on top of not losing your data.

How long does it take to get from "mostly no" to "yes"?

For a typical small business: days of focused work for the core items, then light ongoing upkeep. The longest pole is usually scheduling the staff training and the backup test, not the technology.

Renewal questionnaire sitting on your desk?

We'll walk it with you, close the gaps, and hand you the evidence file. Call (415) 555-0134 or send us a note. →