Skip to main content

4 min read

Cyber Insurance Requirements: What Insurers Ask Practices and Firms Before They Cover You

The short answer

Many cyber insurance applications ask whether the basics are in place: MFA on email and remote access, backups kept apart from your network and tested, computers kept up to date and watched, staff trained to spot phishing, and a written plan for an incident. Answer every question accurately, since your answers are what the insurer relies on if you ever make a claim.

The security section of a cyber insurance application often lands on the office manager’s desk a few weeks before renewal. Many of the questions are yes or no, and whoever fills it in may have to guess what “endpoint detection” or “privileged access” means for their office.

Guessing is the part to avoid. Your answers become the insurer’s picture of how your office protects itself, and they’re worth getting right.

Why the questions keep getting more specific

Insurers pay for the clean-up after ransomware and hacked email accounts, so they want to know how likely you are to need it. The National Association of Insurance Commissioners notes that insurers increasingly require specific security controls and may limit what they’ll pay for ransomware.

Much of what they ask about is the same set of basics that CISA, the federal cybersecurity agency, recommends to small businesses in its Cyber Essentials guide. None of it is exotic.

The questions you’ll see, and what they mean

Wording varies by insurer, but these topics come up often.

Multi-factor authentication

What they’re asking: whether signing in takes a second step, such as a code or an app prompt, as well as a password. There may be separate questions for email, remote access to the office, and administrator accounts.

A true yes: multi-factor authentication (MFA) is required for every person on email, for every remote connection, and for every admin login, with no exceptions left over from setup. As CISA’s MFA guidance explains, a stolen password then isn’t enough on its own to get in.

Backups and restore tests

What they’re asking: whether you could recover if your computers and server were encrypted by ransomware, and how quickly.

A true yes: important data is backed up automatically, at least one copy is kept apart from your network where an attacker can’t change or delete it, and someone has restored from it recently to prove it works.

Protection and monitoring on every computer

What they’re asking: whether every computer and server runs security software that’s watched for alerts, not only installed.

A true yes: every device has it, including the old one in the back office, and someone looks at the alerts and acts on them, around the clock if possible.

Updates and unsupported systems

What they’re asking: how quickly security updates are applied, and whether anything is running software the maker no longer supports.

A true yes: updates go on automatically or on a schedule you can describe, and any old computer that can’t be updated is replaced or kept off the network.

Email filtering

What they’re asking: whether email is checked for phishing, malicious attachments and links before it reaches inboxes.

A true yes: your email service’s filtering is switched on and set up, not left at defaults nobody has looked at.

Staff training

What they’re asking: whether staff are taught to spot phishing and requests to change payment details, and how often.

A true yes: everyone, including new starters, gets regular short training, and you can say when it last happened.

A written plan for an incident

What they’re asking: whether you know what you’d do in the first hours of an attack, and who you’d call.

A true yes: a short written plan exists, staff know where it is, and it starts with calling your insurer. Our guide to the first hour after ransomware or a hacked email account is a good starting point.

Vendor and remote access

What they’re asking: which outside companies can reach your systems, and how that access is controlled.

A true yes: you have a list of vendors with access, each uses its own account with MFA, and access is removed when it’s no longer needed.

First-party and third-party cover

The FTC’s cyber insurance page explains the two halves. First-party cover protects your own data and pays your own costs, such as recovering data, notifying clients and lost income while you’re down. Third-party cover protects you when others bring claims against you after an incident. Ask your agent which your policy includes, and whether you need both.

Answering accurately, even when the answer is no

Fill in the application with whoever runs your IT in the room, or at least on the phone. Go question by question, and only answer yes when it’s true for every person and every device. Keep a copy of what you submitted.

If an answer is no, say so, and tell your agent or broker what you’re doing about it and by when. If something you described changes during the year, such as dropping a backup service, ask your agent whether you need to tell the insurer.

What to do before your renewal

  1. Find last year’s application and check each answer is still true.
  2. Close the quick gaps first: MFA on email and remote access, and a test restore from backup.
  3. Write a one-page incident plan if you don’t have one.
  4. Book short phishing training for the whole office.

Accounting and tax firms will find most of these on our list of 7 signs your firm’s IT needs attention. Medical and dental practices can work from our HIPAA checklist, which covers the same ground.

Getting your application right with us

We help practices and firms across Orange County answer the IT questions on their applications accurately, and fix what needs fixing before renewal. We look after the controls insurers ask about every day: MFA, tested backups, monitored and updated computers, email filtering and staff training.

If renewal is coming up, book a free IT check-in and we’ll go through the security questions with you. You can also read about our IT support for medical practices, accounting and CPA firms or any Orange County office.

This guide is general information, not legal or insurance advice. For questions about your own policy, talk to your insurance agent or broker.

Sources

  1. FTC: Cyber Insurance
  2. FTC: Cybersecurity for Small Business
  3. NAIC: Ransomware
  4. CISA: Cyber Essentials
  5. CISA: Turn On MFA

Frequently asked questions

Do insurers require MFA?
Many applications ask about it, sometimes account by account: email, remote access and administrator logins. Whatever your application says, it's worth having. CISA points out that with MFA on, a stolen password on its own isn't enough to get into the account.
What if we can't answer yes to everything?
Answer honestly anyway. Tell your agent or broker what's missing and when it will be in place, and get the quick fixes done before the application goes in. An accurate no with a date beside it puts you in a better position than a yes that isn't true.
Does cyber insurance pay ransoms?
It depends on the policy. The National Association of Insurance Commissioners notes that insurers typically require you to notify them before any payment, and that not doing so can lead to coverage being denied. If you're ever hit, call your insurer before contacting the attackers or paying anything.
Is cyber cover already part of our business policy?
It might be. Look for a cyber section or endorsement in your business owner's policy and your professional liability policy, then ask your agent what it covers, whether that's your own costs, claims against you or both, and what the limits are.
Can our IT provider fill in the application?
Your IT provider can answer the technical questions and show you how each one is set up. The application is signed by your practice or firm, though, so someone there should read every answer before it goes in and keep a copy.