Renewing a cyber insurance policy used to mean a short form and a signature. For many contractors and energy companies, it now involves a multi-page questionnaire about multi-factor authentication, backups, endpoint protection, and incident response. Underwriters have learned that certain controls are strongly associated with fewer and smaller claims, and they ask about them directly.
Understanding what the questions mean and why they are asked helps you answer accurately, improve your position, and avoid problems when you need to make a claim.
Why the questions have gotten tougher
Ransomware and payment fraud have produced large losses across many industries, and insurers responded by tightening underwriting. The questions are essentially a checklist of the defenses that make an attack less likely to succeed or less costly if it does. Your answers affect eligibility, coverage limits, premiums, and in some cases the exclusions that apply.
Common questions and what they mean
Multi-factor authentication
Typical questions: Is MFA required for email? For remote access? For administrator accounts? For backups?
Underwriters care because stolen passwords are a leading way in. Answers must be precise. "We use MFA" is not the same as "MFA is required for every user on every email account and remote connection." Partial coverage should be described honestly.
Backups
Typical questions: How often do you back up? Are backups offline or immutable? Are they tested? How long would restoration take?
A backup that ransomware can encrypt or delete is not much protection. Underwriters want separation and testing.
Endpoint detection and response
Typical questions: Do you use monitored endpoint protection on all computers and servers? Who watches the alerts?
Traditional antivirus alone may not satisfy these questions. Monitoring matters.
Email security and training
Typical questions: Do you filter email for malicious content? Do you provide phishing training? Do you run simulations?
Payment controls
Typical questions: Do you verify banking changes by phone? Do two people approve wires over a certain amount?
Social engineering and funds transfer coverage often depends on whether you follow a verification procedure. Read your policy to see whether coverage is conditioned on callback verification.
Patching and remote access
Typical questions: Do you patch critical vulnerabilities within a defined time? Is remote desktop exposed to the internet?
Incident response and governance
Typical questions: Do you have a written incident response plan? Have you tested it? Who is your contact?
OT and operational systems
Energy and industrial operators may be asked whether control systems are segmented from business networks, and how remote access to them is controlled.
Answer honestly
It is tempting to answer optimistically, especially if you plan to fix a gap soon. Do not. An inaccurate answer can give an insurer grounds to contest a claim, and the application is typically signed by an officer. If something is in progress, say so and give the date. Have IT verify technical answers before the owner signs.
Practical steps to improve your position
- Close the big gaps first: MFA everywhere, tested offline backups, monitored endpoint protection, and verification procedures for payments.
- Document your controls. Keep screenshots, policies, and training records ready.
- Write and rehearse an incident response plan, including whom you call first and your insurer's hotline.
- Plan the renewal early. Start sixty to ninety days before, so there is time to remediate.
- Talk to your broker. A broker who understands cyber can explain coverage terms and compare options.
Read the policy, not just the application
Know what is covered: ransomware response costs, business interruption, data restoration, legal costs, notification, and funds transfer fraud. Understand sublimits, waiting periods, exclusions, and requirements such as using the insurer's approved response vendors. Know the notification procedure before an incident.
Insurance is not a security program
Coverage helps pay for recovery, but it does not restore your reputation, repair your relationships, or guarantee that a claim will be paid in full. Controls first, insurance as a backstop.
How Ironfield Cyber can help
Ironfield Cyber helps contractors and energy companies verify the answers on cyber insurance applications and close the gaps underwriters care about most. If your renewal is coming up, we can review your questionnaire with you and your broker.