Cyber Insurance

We'll fill out the cyber insurance application with you.

Carrier questionnaires now run to roughly fifty questions, and you are the one signing the form that says the answers are true. We go through it with you, tell you which answers hold up today, and fix what doesn't before you sign.

Book a 30-Minute Call No network access required
The One-Minute Version

What you need to know, and nothing more

The application is a legal attestation

You are certifying that specific security controls are in place. Carriers verify the answers when a claim is made, which is the worst possible moment to find out a box was ticked optimistically.

Getting it wrong is expensive

An inaccurate answer can mean a higher premium, an exclusion written into your policy, or a claim denied outright after an incident you thought you were covered for.

The questions are written for your IT department

They ask for counts, percentages and product names. That is why they so often land on a finance or operations lead with no way to verify them — and why guessing is so common.

Most gaps are fixable before renewal

Several cost nothing but a decision or a one-page policy. A few, like replacing end-of-life computers, need real lead time — which is the argument for looking early rather than the week the form is due.

What we do about it

We sit with you, work through the questionnaire, and give you a written list of which answers are defensible today and which are not. If you already have an IT provider, that list is yours to hand to them.

At a glance

~50questions on a current application
7control areas assessed
30minutes for the first call
Nonenetwork access needed

Not sure where you stand yet? The free 2-minute IT Health Check is a quick self-assessment — nothing to install and no call needed.

The Detail

The full technical breakdown

Below is every control area a current carrier application covers, question by question, plus the gaps that most often hold an application up. It's written for whoever administers your network.

Expand whichever sections you want. Nothing to fill in, nothing to download.

What carriers ask, by control area

Identity and access control

The largest single block of questions, and the one carriers weight most heavily.

  • Multi-factor authentication enforced on the email platform — asked separately from everything else, because email compromise drives most claims.
  • MFA on remote access into the corporate network, and on cloud applications.
  • MFA protecting all local and remote access to privileged accounts. Partial coverage is a No.
  • Whether staff operate under least privilege at all times, rather than holding standing local administrator rights.
  • Whether password management software is issued to employees.
  • Whether a Privileged Access Management (PAM) tool is deployed. Not yet universal, but increasingly required at higher limits.
Email and endpoint controls

Carriers ask what stops a malicious message before a person has to make a judgement call.

  • Which controls are applied to inbound email, chosen from a list — you are expected to name them.
  • Whether a secure email gateway is in place.
  • Whether Office macros are disabled by default. A common quiet No.
  • Web filtering that blocks access to known malicious sites.
  • Endpoint detection and response coverage, and which product.
  • Whether staff are trained to apply extra scrutiny to attachments and links from outside the organisation.
Backups and business continuity

Not just whether backups exist — whether they would survive the event you are insuring against.

  • Whether backups are local, offline, offsite, or cloud. Local-only is a weak answer, because ransomware reaches it.
  • The specific controls protecting the backups themselves, from a checklist.
  • Whether a business continuity plan exists, and whether it has actually been walked through rather than simply written.
Detection and incident response

Carriers want to know you would notice an intrusion, and know what to do next.

  • Whether a SIEM is collecting and monitoring logs.
  • Whether a Security Operations Centre covers you, including what hours and whether there is on-call cover outside business hours.
  • Whether host-based and network firewalls disallow inbound connections by default.
  • Whether an incident response plan exists and is tested annually — the testing is the part most organisations miss.
  • Whether a cybersecurity tabletop exercise has been run within the last two years.
Asset and vulnerability management

The questions that most often expose the gap between what people believe they run and what they actually run.

  • Whether an asset discovery tool continuously maps devices on the network.
  • Whether the asset database is up to date.
  • End-of-life operating systems still in service. Usually the single biggest exposure on the whole application, and the slowest to fix.
  • Whether there is a process for decommissioning unused systems.
  • What percentage of the network is covered by scheduled vulnerability scanning — answered as a number, so there is nowhere to hide.
  • Whether patching extends to third-party applications, not only the operating system.
  • How frequently penetration testing is conducted.
Configuration and governance

The written-policy questions. Low cost to fix, and disproportionately effective on the application.

  • Whether a hardened baseline configuration is applied across all or most devices.
  • Whether the network is segmented according to data classification level.
  • Whether a written data classification policy exists. This can genuinely be one page.
  • Whether PowerShell is hardened in line with the practices the carrier names.
  • How many machine service accounts hold Domain Administrator privileges — a count, not a yes or no, and one that needs a real audit to answer defensibly.
  • Whether a formal vendor management process performs due diligence on third parties.
Funds transfer and eCrime controls

Process questions rather than technology ones, and usually the cheapest answers to change.

  • Whether a request to transfer funds is verified out-of-band before it is actioned.
  • Whether a known contact is called back on a known number before a vendor’s bank details are changed.
  • These two answers cost nothing but a written procedure and the discipline to follow it.

The answers that most often come back No

End-of-life computers still in service

Machines past their support date cannot be patched, so there is no honest favourable answer available. This is a hardware replacement programme, not a configuration change, which is why it needs the longest lead time of anything on this list.

Standing local administrator rights

If everyday accounts hold local admin, the least-privilege question is a No and several related answers weaken with it. Removing standing rights is among the highest-impact changes available.

Service accounts running as Domain Admin

The application asks for a count. Most organisations cannot produce one without an audit, and an unverified number is exactly the kind of answer that fails scrutiny at claim time.

No security awareness training or phishing simulation

Heavily weighted by underwriters, inexpensive to put right, and one of the few controls that visibly improves over a policy year.

An incident response plan that has never been tested

Having the document is not the question. Annual testing is. A single tabletop session satisfies this and the business continuity question together.

Vulnerability scanning at zero percent

Answered as a percentage, so a gap is unmistakable. Zero is a hard flag and reliably attracts follow-up questions.

No password manager, no data classification policy

Two separate questions, both low effort, both currently No in most organisations we see. These are the quickest wins on the entire form.

PowerShell left unrestricted

Carriers now name specific hardening practices. Applied through Group Policy or Intune this is a configuration change rather than a purchase, and it removes a written explanation from your application.

Related

Already know where you're exposed?

If you're less worried about the paperwork and more about the underlying security, our cybersecurity page covers the layered protection we put in place — and NetworkShield™ is the fastest place to start.

See Cybersecurity See NetworkShield™

Not sure where you stand?

Our free 2-minute IT Health Check is a short self-assessment you can take right now, with nothing to install and no call required.

Take the IT Health Check →