4 min read
Cyber Insurance Requirements: What Insurers Ask Practices and Firms Before They Cover You
The short answer
Many cyber insurance applications ask whether the basics are in place: MFA on email and remote access, backups kept apart from your network and tested, computers kept up to date and watched, staff trained to spot phishing, and a written plan for an incident. Answer every question accurately, since your answers are what the insurer relies on if you ever make a claim.
The security section of a cyber insurance application often lands on the office manager’s desk a few weeks before renewal. Many of the questions are yes or no, and whoever fills it in may have to guess what “endpoint detection” or “privileged access” means for their office.
Guessing is the part to avoid. Your answers become the insurer’s picture of how your office protects itself, and they’re worth getting right.
Why the questions keep getting more specific
Insurers pay for the clean-up after ransomware and hacked email accounts, so they want to know how likely you are to need it. The National Association of Insurance Commissioners notes that insurers increasingly require specific security controls and may limit what they’ll pay for ransomware.
Much of what they ask about is the same set of basics that CISA, the federal cybersecurity agency, recommends to small businesses in its Cyber Essentials guide. None of it is exotic.
The questions you’ll see, and what they mean
Wording varies by insurer, but these topics come up often.
Multi-factor authentication
What they’re asking: whether signing in takes a second step, such as a code or an app prompt, as well as a password. There may be separate questions for email, remote access to the office, and administrator accounts.
A true yes: multi-factor authentication (MFA) is required for every person on email, for every remote connection, and for every admin login, with no exceptions left over from setup. As CISA’s MFA guidance explains, a stolen password then isn’t enough on its own to get in.
Backups and restore tests
What they’re asking: whether you could recover if your computers and server were encrypted by ransomware, and how quickly.
A true yes: important data is backed up automatically, at least one copy is kept apart from your network where an attacker can’t change or delete it, and someone has restored from it recently to prove it works.
Protection and monitoring on every computer
What they’re asking: whether every computer and server runs security software that’s watched for alerts, not only installed.
A true yes: every device has it, including the old one in the back office, and someone looks at the alerts and acts on them, around the clock if possible.
Updates and unsupported systems
What they’re asking: how quickly security updates are applied, and whether anything is running software the maker no longer supports.
A true yes: updates go on automatically or on a schedule you can describe, and any old computer that can’t be updated is replaced or kept off the network.
Email filtering
What they’re asking: whether email is checked for phishing, malicious attachments and links before it reaches inboxes.
A true yes: your email service’s filtering is switched on and set up, not left at defaults nobody has looked at.
Staff training
What they’re asking: whether staff are taught to spot phishing and requests to change payment details, and how often.
A true yes: everyone, including new starters, gets regular short training, and you can say when it last happened.
A written plan for an incident
What they’re asking: whether you know what you’d do in the first hours of an attack, and who you’d call.
A true yes: a short written plan exists, staff know where it is, and it starts with calling your insurer. Our guide to the first hour after ransomware or a hacked email account is a good starting point.
Vendor and remote access
What they’re asking: which outside companies can reach your systems, and how that access is controlled.
A true yes: you have a list of vendors with access, each uses its own account with MFA, and access is removed when it’s no longer needed.
First-party and third-party cover
The FTC’s cyber insurance page explains the two halves. First-party cover protects your own data and pays your own costs, such as recovering data, notifying clients and lost income while you’re down. Third-party cover protects you when others bring claims against you after an incident. Ask your agent which your policy includes, and whether you need both.
Answering accurately, even when the answer is no
Fill in the application with whoever runs your IT in the room, or at least on the phone. Go question by question, and only answer yes when it’s true for every person and every device. Keep a copy of what you submitted.
If an answer is no, say so, and tell your agent or broker what you’re doing about it and by when. If something you described changes during the year, such as dropping a backup service, ask your agent whether you need to tell the insurer.
What to do before your renewal
- Find last year’s application and check each answer is still true.
- Close the quick gaps first: MFA on email and remote access, and a test restore from backup.
- Write a one-page incident plan if you don’t have one.
- Book short phishing training for the whole office.
Accounting and tax firms will find most of these on our list of 7 signs your firm’s IT needs attention. Medical and dental practices can work from our HIPAA checklist, which covers the same ground.
Getting your application right with us
We help practices and firms across Orange County answer the IT questions on their applications accurately, and fix what needs fixing before renewal. We look after the controls insurers ask about every day: MFA, tested backups, monitored and updated computers, email filtering and staff training.
If renewal is coming up, book a free IT check-in and we’ll go through the security questions with you. You can also read about our IT support for medical practices, accounting and CPA firms or any Orange County office.
This guide is general information, not legal or insurance advice. For questions about your own policy, talk to your insurance agent or broker.

