Cyber insurance applications used to be short forms. Today, many carriers ask detailed questions about your security practices and may decline coverage or raise premiums if key controls are missing. For contractors, who face payment fraud, ransomware, and data theft, understanding the questions helps you buy better coverage and often improves your security in the process.
This article describes the types of questions commonly asked. Specific questions, terms, and prices vary by carrier and change over time, so rely on your broker for details.
Why insurers ask
An insurer is estimating the odds and cost of a claim. Controls that reduce the likelihood or size of an incident matter to them. Over time, carriers have learned that a few practices correlate strongly with fewer and smaller claims, and their applications reflect that.
Common topics
Multi-factor authentication
Expect questions about whether MFA is required for email, remote access, privileged and administrator accounts, and cloud applications. A "partial" answer may matter. If it is enabled for some users but not others, say so accurately.
Backups
You may be asked how often data is backed up, whether backups are kept offline or immutable, whether they are encrypted, and when you last tested a restore. These questions reflect the importance of recovery in ransomware events.
Endpoint protection and monitoring
Carriers often ask whether you use modern endpoint detection and response tools and whether someone monitors the alerts around the clock.
Email security
Questions may cover filtering of malicious attachments and links, protections against spoofing such as SPF, DKIM, and DMARC, and whether you flag external email.
Patching
They may ask how quickly critical patches are applied, and whether you run unsupported operating systems or software.
Remote access
Exposed remote desktop services are a known ransomware entry point. You may be asked whether any are open to the internet.
Payment controls
Because of the frequency of fraudulent funds transfers, many applications ask whether you verify banking changes by calling a known number, and whether payments require dual approval.
Training and incident response
Questions may include whether staff receive security awareness training and phishing simulations, and whether you have a written, tested incident response plan.
Privileged access
You may be asked how administrator accounts are managed and whether they are separate from daily-use accounts.
How to answer
Be accurate
Answer based on what is actually in place across the whole company, not what is planned or what is true for one office. Inaccurate answers on an application can give the carrier grounds to dispute a claim later. If you are unsure, ask your IT provider to verify before you sign.
Involve the right people
The person who signs the application is attesting to the answers. Have IT, finance, and operations review the draft together. The owner or CFO should understand what is being represented.
Keep evidence
Save screenshots, policies, and reports supporting your answers. They will help at renewal and during a claim.
Use the application as a roadmap
If you cannot answer yes to a question, that is useful information. The controls that insurers emphasize are also the ones that protect you directly. Closing the gap on MFA or backups may lower your risk and improve your coverage options.
Understand your coverage
Ask your broker about:
- What is covered: ransomware response, data restoration, business interruption, and funds transfer fraud.
- Sublimits and waiting periods for specific losses.
- Requirements for using approved vendors during an incident.
- Exclusions, such as unpatched known vulnerabilities or failure to maintain required controls.
- Coverage for social engineering and payment diversion, which sometimes sits in a separate policy or under a sublimit.
Plan ahead for renewal
Start the renewal conversation early, ideally 60 to 90 days ahead, so you have time to remediate any gaps rather than accepting a poor quote.
Ironfield Cyber's role
Ironfield Cyber helps contractors and energy firms prepare accurate applications, verify controls, and close the gaps carriers ask about. We do not sell insurance, but we can give your broker the technical answers and evidence they need.