What a Cyber Insurance Application Actually Asks You (and Why You’ll Fail It)

What a Cyber Insurance Application Actually Asks You (and Why You’ll Fail It)

If you’ve renewed a cyber liability policy in the last year, you’ve noticed the application isn’t a checkbox form anymore. Insurers got burned paying out ransomware claims to businesses with no actual security in place, so the applications now read like a security audit — and most Owatonna and Twin Cities small businesses fail it on the first pass without knowing why.

Here’s what’s actually on that form, and what it means if you can’t answer yes.

1. “Do you require multi-factor authentication on email and remote access?”

This is usually question one, and it’s often the one that sinks an application. MFA isn’t optional anymore for underwriters — it’s the single control most correlated with stopping account-takeover, which is how most ransomware starts. If your team logs into Microsoft 365 or your VPN with just a password, you don’t pass this line.

2. “Do you have endpoint detection and response (EDR), not just antivirus?”

Insurers now distinguish between traditional antivirus (which matches known threats) and EDR (which watches for suspicious behavior and can isolate a machine automatically). “We have antivirus” used to be an acceptable answer. It isn’t anymore — and on the application, it reads as a gap.

3. “Do you have tested, offline or immutable backups?”

Not “do you have backups” — “have you tested a restore, and can ransomware reach and encrypt them too?” A backup that lives on the same network as everything else, that nobody has ever restored from, is treated by underwriters as functionally not a backup. This is the same gap that shows up in our post on backups you haven’t tested — it shows up again here because it’s the same failure with an insurance policy attached to it.

4. “Do you have a documented incident response plan?”

Not “would you know who to call” — a written plan, with named roles, that your team has actually seen. “We’d figure it out” is not a plan, and it’s a hard no on the form.

5. “Do you provide security awareness training to employees?”

Most breaches at businesses your size start with someone clicking a phishing email, not a sophisticated exploit. Insurers ask this because it’s cheap to fix and prevents the most common way in. If the answer is “we tell people to be careful,” that’s a no.

6. “Do you have a patch management process for servers, workstations, and network devices?”

Unpatched software is the second most common way in after phishing. The question isn’t whether updates ever happen — it’s whether there’s a process that guarantees they happen on a schedule, across every device, not just the ones someone remembers.

What failing the application actually costs you

It’s not just a higher premium. Insurers are increasingly denying claims outright when a business answered “yes” on the application to a control that turns out not to exist — MFA that was never actually enforced, backups that were never tested. A gap on the form becomes a denied claim after the breach, which is worse than paying more for the policy.

Where Owatonna and Twin Cities businesses actually stand

Most 10-75 seat businesses we talk to have some of these controls, informally, without documentation, and without anyone checking that they’re actually enforced everywhere. That’s the gap: not “no security,” but security that can’t be proven on a form an underwriter is going to hold you to after an incident.

What the application asks What most small businesses have
MFA enforced everywhere MFA available, not required
EDR with monitoring Antivirus, unmonitored
Tested, isolated backups Backups that run, never restored
Written incident response plan An informal “call IT” habit
Ongoing security awareness training A one-time hire-day mention
Documented patch management Updates happen “eventually”

This is exactly the gap Hacker’s Vault closes: managed MFA enforcement, monitored endpoint protection, tested backup verification, and the documentation to back all of it up – the controls the application is actually asking about, in place and provable, not just assumed. See what’s included in Hacker’s Vault, or book a time to walk through your last application line by line and see where you’d actually stand.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *