Cyber insurance

Your cyber insurance questionnaire: who checked the answers?

Start with the exact questions on your application. Identify who supplies technical evidence, who checks it and who is authorized to sign. Record exceptions and unresolved questions before the form is submitted.

In short

Review a cyber insurance questionnaire by matching each technical answer to relevant evidence, its scope and date. Ask the responsible team to explain exceptions and uncertainty. Follow the application's instructions and confirm unclear requirements with your insurer or broker. An independent technical review does not determine coverage or guarantee a claim outcome.

A provider can explain the systems it manages, and an internal team can contribute records of its own. The person coordinating the application needs to know which answer came from which source and what has actually been examined.

Start with the application and its instructions

Confirm the version, submission deadline and signature requirements. Keep the insurer's or broker's clarification with the application. Do not assume the form, signatory or requirements match a previous year or another organization's policy.

The Canadian BOXX application linked below illustrates control questions and an authorized-representative declaration. It is one example, not a universal checklist or an Ontario-specific rule. Questions about disclosure duties, contractual consequences or coverage belong with the insurer or broker and your appropriate advisers.

Separate reported answers from examined evidence

Examples to adapt to the actual questionnaire
Question areaEvidence to examineLimit to record
MFAApplicable policies, assignments, exceptions and relevant sign-in evidenceRegistration or capability alone does not establish enforcement.
RecoveryJob results, selected recovery tests and remaining dependenciesA tested file or system does not establish every recovery scenario.
Backup protectionStorage, permissions, retention and protection configurationOne setting alone does not establish protection against every deletion path.
Privileged accessRoles, purposes, responsible owners and review recordsDistinguish ordinary, service and emergency accounts.
Endpoint protectionDevice inventory reconciled with coverage and agent healthDefine the population before interpreting a percentage.
TrainingAssignment and completion records for the relevant periodCompletion is different from demonstrated behavior in an incident.

Microsoft's reporting documentation distinguishes MFA registration/capability from usage and describes limits to its reports. Ask a qualified administrator to explain which views and policy evidence address the application question.

An exception list is information to examine. Its length alone does not make the configuration acceptable or unacceptable. Ask how each exception affects the stated answer and how the insurer wants it disclosed.

A review sequence before submission

  • Identify the technical owner and authorized signatory under the application's instructions.
  • For each answer, record its source, scope, date and any exceptions.
  • Separate verified observations from reported claims and missing evidence.
  • Resolve unclear question wording with the insurer or broker rather than guessing yes or no.
  • Keep the submitted version and supporting records, and agree how relevant changes will be reviewed.

Plan backwards from the actual deadline and the work needed to resolve questions. There is no universal lead time that fits every application. If the deadline is close, discuss unresolved items promptly with the responsible parties.

When an independent examination can help

Provider and internal records can be useful evidence. An independent reviewer can examine selected records and configurations within an agreed scope, explain findings and identify what remains unverified. Independence alone does not make a report acceptable to an insurer.

Discuss cybersecurity verification if you need that external view. Confirm the intended use and any reader requirements before commissioning it. Implementation remains with your internal team or appointed provider.

For examples of evidence organization, read the insurance evidence guide. For a broader service question, use evaluating your IT provider and the ten-question checklist.

Common questions

Who is responsible for the application answers?
Follow the actual application's instructions and confirm who is authorized to sign. Record who supplied and checked the technical answers. Legal responsibility and any rights against a provider depend on the applicable arrangements and circumstances; ask your advisers.
Should I answer no when I am unsure?
Do not substitute a guess for an unresolved question. Ask the responsible team to examine it and confirm with the insurer or broker how uncertainty or partial implementation should be recorded.
Does an MFA registration report establish enforcement?
No. It describes registration or capability within its scope. Review relevant policies, assignments, exceptions and sign-in evidence with the responsible administrator. A percentage alone does not answer every application question.
When should we review the questionnaire?
As soon as the application and deadline are known. Allow time for evidence collection, clarification and any agreed follow-up. Base the schedule on the actual work and submission requirements.
Does independent verification guarantee coverage?
No. It can support a scoped technical assessment. It does not determine insurer acceptance, coverage, certification or a claim outcome.
Sources

Need an independent view of the technical evidence? Discuss the question, scope and intended use before commissioning a review.

Discuss Cybersecurity Verification

Free PDF  ·  5 pages

Get a free five page PDF checklist with ten questions to ask your IT provider.