Cyber insurance used to be straightforward. You filled in a short form, paid a modest premium, and hoped never to use it.
That market has changed considerably. After years of heavy claims, insurers now ask detailed technical questions and expect specific controls to be in place before they will quote at all. For a lot of businesses the renewal conversation is now the moment they discover their security position is thinner than they assumed.
Why it changed
Ransomware claims cost insurers a great deal of money. The response was predictable: raise premiums, tighten wording, and stop insuring organisations that have not done the basics.
The useful consequence is that insurer questionnaires have become a reasonable free checklist of what good practice looks like. Even if you never buy the policy, the questions are worth reading.
What they almost always ask about
Multi-factor authentication. Expect a specific question on whether MFA covers remote access, email and administrative accounts. This is frequently a condition rather than a preference — no MFA, no cover.
Backups, and whether they are separated. Not just “do you back up” but whether a backup exists that an attacker who compromises your network cannot also encrypt or delete. Expect to be asked when you last tested a restore, and to answer honestly.
Patching. How quickly you apply security updates, and whether anything unsupported is still running.
Endpoint protection. Whether you run something that detects suspicious behaviour rather than only matching known malware signatures.
Admin rights. Whether ordinary users run as administrators, and how privileged accounts are separated and controlled.
Email filtering and awareness training. Since most incidents still start with an email.
Your incident plan. Who gets called, in what order, and whether it has ever been rehearsed.
Answer accurately — it matters more than you think
There is a real temptation to give the answer that gets the better premium. Resist it.
Insurance is a contract based on the information you provide. If you state that MFA covers all remote access and a claim later shows it did not, you have handed the insurer a straightforward reason to reduce or decline the payout. The policy will have cost you money and delivered nothing at the moment you needed it.
If you cannot answer yes to something, say so. A slightly higher premium is considerably better than a policy that fails when tested.
Turn the questionnaire into a plan
The practical move is to treat the form as a gap analysis. Work through it and mark each item green, amber or red. The reds are your priority list, and they will usually be the same items that would have shown up in a proper security review anyway.
Most of what insurers ask for is neither exotic nor expensive. MFA, a separated backup, timely patching, restricted admin rights, decent email filtering. It is the same short list that prevents most incidents in the first place — which is rather the point.
Cyber Essentials certification is worth mentioning here too. It covers much of the same ground, it is recognised, and some insurers view it favourably. It also gives you a structured way to work through the basics rather than guessing at them.
The bottom line
Insurers now expect evidence rather than intent. Use their questionnaire as a checklist, answer it truthfully, and fix the gaps it exposes. You will end up with a better premium and — considerably more importantly — a business that is less likely to need the policy.
FAQ
Will Cyber Essentials get us cheaper cover? It varies by insurer, but it demonstrates the baseline controls many of them ask about and gives you a recognised way of evidencing them. It is worth having regardless of the premium effect.
What if we cannot meet a requirement? Say so on the form and ask what the insurer would accept as an alternative. Many will work with a documented plan and a timeline. What they will not accept is being told something was in place when it was not.
Do small businesses really need cyber insurance? Cover is a commercial decision, but the controls are worth having either way. If the questionnaire exposes gaps, those gaps are real whether or not you buy the policy.


