Your Cyber Insurance Questionnaire Asks for Things You May Not Have

The form came from your broker with a deadline on it. It runs several pages, and somewhere around the second one it stops asking about your business and starts asking about your network.

Multi-factor authentication — on remote email, on remote network access, on every administrator account. Endpoint detection and response, by product name. Backups that are offline, encrypted, MFA-protected, and tested. A written incident response plan that is in effect and has been exercised. Verification procedures on wire transfers over twenty-five thousand dollars.

You are a law firm, an RIA, a CPA firm, a tax preparation practice. Nobody at your firm knows the answers, and the person who might — your IT company — is not the one signing the form. You are.

What the questionnaire is actually asking for

Carriers stopped asking whether you have security. They now ask what you can produce.

The questions have a shape. Every one of them is really asking: is there a written record of this, and could you hand it to someone?

Multi-factor authentication. Not “do you use MFA.” Current forms break it out by surface — remote email, remote network access, administrator and privileged accounts. Several forms offer a checkbox for administrator accounts “where allowed,” which is where most small firms quietly land. An underwriter reads that box as a gap.

Endpoint detection and response. Listed separately from antivirus, because carriers no longer treat them as the same thing. Some forms require you to name the product.

Backups, described by characteristic. Offline or air-gapped. Encrypted. MFA-protected. Tested. Recoverable inside a defined window. “We have backups” is not an answer to this question.

A written incident response plan. Tested and in effect, with named responsibilities. Not a plan you intend to write.

Payment and transfer controls. Dual verification above a dollar threshold, and confirmation through a second channel — a phone call, not a reply to the email.

Patching, training, and vendor oversight. How fast critical updates go on. Whether security training is mandatory. Whether your vendors are held to your standard in writing.

Why a hopeful “yes” is the expensive answer

The signature block on a cyber application is not a formality. It states that the answers are true, that no material facts have been omitted, and that the insurer is relying on them in issuing the policy. The application becomes part of the contract.

One carrier’s form puts the consequence plainly: if the application contains misrepresentations or fails to state facts materially affecting the risk, the policy may be deemed null and void. Another carries a notice written specifically for Texas applicants, warning that an intentional misstatement material to the risk can be found by a court to be insurance fraud.

Read that in order. You answer yes to a control you believe you have. Two years later you have a breach — the one event where the policy is the entire point. The carrier’s forensics team examines what was actually in place. If it does not match the form, the conversation stops being about your claim and starts being about your application.

Nobody sets out to misrepresent anything. They tick a box that sounds close enough, because the alternative is admitting they do not know. That is the risk this page exists to name.

What the honest answer requires

An answer you can defend has three parts: the control is in place, it is written down, and you could produce the evidence if asked.

Most firms have some of the first, little of the second, and none of the third. That is not negligence. Nobody told them the standard had moved.

Here is the part worth understanding. The questionnaire is not a separate standard your carrier invented. Nearly everything on it — a written security program, an incident response plan, vendor oversight, staff training, access control — is already required of your firm by something else. The FTC Safeguards Rule. IRS Publication 4557. SEC Regulation S-P. The Texas rules that reach your practice.

And the form is the smallest of those demands. An underwriter asks about the controls that drive claims. Your regulator asks about everything that reaches your firm, and does not stop at the edge of the form.

So the questionnaire is a useful alarm and a poor checklist. If you build only what the carrier asked, you will pass underwriting and still be exposed everywhere the form never looked. Build to what actually applies to your firm, and the questionnaire answers itself along the way. See the eleven obligations that reach Texas legal and financial firms.

If the renewal is weeks away

You will not close every gap before the deadline, and you should not pretend otherwise on the form.

What you can do:

Answer accurately, including “no.” An honest no is underwritable. Carriers price risk; they do not expect perfection.

Where a control is partial, say so and describe what compensates for it. A documented exception with a compensating control reads very differently from a bare no — and completely differently from a yes you cannot support.

Gather what evidence you do have. Screenshots of MFA settings, your endpoint console, a backup restore test with a date on it.

Then fix what the form exposed, on a real timeline, so next year’s renewal is a different conversation.

How Briggs IT Services helps

We start with a Compliance Readiness Review. We gather what your firm actually has, then review it against what the questionnaire, your regulator, and Texas law each require you to be able to produce.

You get a written report: what you can answer truthfully today, where the gaps are, and what closing each one takes.

From there, we create the plan. If you have IT — internal or outside — we guide them through the changes and they do the hands-on work. If you have no IT, we do it ourselves, inside a scoped remediation phase with a defined end.

Then we build the documentation, so the next questionnaire is a matter of retrieving what exists rather than guessing.

Common questions about the cyber insurance questionnaire

Do I have to answer a cyber insurance questionnaire truthfully?

Yes. The signature block states that your answers are true and that the insurer is relying on them. The completed application becomes part of the insurance contract, not a preliminary form.

What happens if I answer yes to a control my firm does not actually have?

A misrepresentation that is material to the risk can give the carrier grounds to deny a claim or rescind the policy. One carrier’s form states the policy may be deemed null and void. It is usually discovered after a breach, when the policy is the whole point.

What does “MFA on privileged accounts” mean on a cyber insurance form?

Multi-factor authentication on every administrator account, not only on staff logins. Current forms break MFA out by surface — remote email, remote network access, and admin accounts separately. Many forms offer a checkbox for admin accounts “where allowed,” and an underwriter reads that as a gap.

Is a cloud backup enough to answer the backup question?

Usually not. Carriers ask for backup characteristics: offline or air-gapped, encrypted, MFA-protected, tested, and recoverable inside a defined window. A cloud backup reachable with the same credentials as your live systems does not satisfy most of those.

Does a Texas firm need a written incident response plan for cyber insurance?

Yes, and carriers increasingly ask whether it is tested and in effect rather than merely written. The same plan is expected by the FTC Safeguards Rule and by the Texas rules that reach legal and financial firms, so it is not work done only for the insurer.

Find out what you can actually answer