Carrier questionnaires now run to roughly fifty questions, and you are the one signing the form that says the answers are true. We go through it with you, tell you which answers hold up today, and fix what doesn't before you sign.
You are certifying that specific security controls are in place. Carriers verify the answers when a claim is made, which is the worst possible moment to find out a box was ticked optimistically.
An inaccurate answer can mean a higher premium, an exclusion written into your policy, or a claim denied outright after an incident you thought you were covered for.
They ask for counts, percentages and product names. That is why they so often land on a finance or operations lead with no way to verify them — and why guessing is so common.
Several cost nothing but a decision or a one-page policy. A few, like replacing end-of-life computers, need real lead time — which is the argument for looking early rather than the week the form is due.
We sit with you, work through the questionnaire, and give you a written list of which answers are defensible today and which are not. If you already have an IT provider, that list is yours to hand to them.
Below is every control area a current carrier application covers, question by question, plus the gaps that most often hold an application up. It's written for whoever administers your network.
Expand whichever sections you want. Nothing to fill in, nothing to download.
The largest single block of questions, and the one carriers weight most heavily.
Carriers ask what stops a malicious message before a person has to make a judgement call.
Not just whether backups exist — whether they would survive the event you are insuring against.
Carriers want to know you would notice an intrusion, and know what to do next.
The questions that most often expose the gap between what people believe they run and what they actually run.
The written-policy questions. Low cost to fix, and disproportionately effective on the application.
Process questions rather than technology ones, and usually the cheapest answers to change.
Machines past their support date cannot be patched, so there is no honest favourable answer available. This is a hardware replacement programme, not a configuration change, which is why it needs the longest lead time of anything on this list.
If everyday accounts hold local admin, the least-privilege question is a No and several related answers weaken with it. Removing standing rights is among the highest-impact changes available.
The application asks for a count. Most organisations cannot produce one without an audit, and an unverified number is exactly the kind of answer that fails scrutiny at claim time.
Heavily weighted by underwriters, inexpensive to put right, and one of the few controls that visibly improves over a policy year.
Having the document is not the question. Annual testing is. A single tabletop session satisfies this and the business continuity question together.
Answered as a percentage, so a gap is unmistakable. Zero is a hard flag and reliably attracts follow-up questions.
Two separate questions, both low effort, both currently No in most organisations we see. These are the quickest wins on the entire form.
Carriers now name specific hardening practices. Applied through Group Policy or Intune this is a configuration change rather than a purchase, and it removes a written explanation from your application.
If you're less worried about the paperwork and more about the underlying security, our cybersecurity page covers the layered protection we put in place — and NetworkShield™ is the fastest place to start.
Our free 2-minute IT Health Check is a short self-assessment you can take right now, with nothing to install and no call required.