Cyber Insurance Field Guide

Answer the questionnaire without guessing.

A practical guide to validating controls, organizing evidence, and submitting cyber insurance answers your organization can defend.

Clear Path Tech AssuranceExecutive + technical guide11-minute read
Is MFA enforced for all remote access?
YesNo
Configuration export attached
Are backups protected from modification?
YesVerify
Recovery architecture under review
Was incident response tested this year?
YesNo
Tabletop record available
InterpretUnderstand what the carrier is asking
ValidateConfirm technical and governance claims
DocumentOrganize evidence before follow-up
ReviewSubmit collaboratively

Executive summary

A cyber insurance questionnaire is not a routine form. It is a set of representations about how your organization manages security risk.

Interpret each question carefully, verify the answer against actual configurations and practices, document supporting evidence, and have the right stakeholders review the final submission. The goal is not the most favorable answer. It is the most accurate and defensible answer.

Three rules for every answer

Do not assume

Using Microsoft 365 does not prove MFA, backups, retention, monitoring, or secure administration.

Define the scope

A control may cover email but not VPN, administrators, servers, cloud applications, or acquired units.

Preserve evidence

Keep exports, reports, plans, tests, inventories, and approval dates with the working file.

The question categories you should expect

Identity and MFA

Workforce users, administrators, remote access, email, VPN, privileged systems, and critical cloud services.

Endpoint security

EDR or MDR deployment, monitoring responsibility, server coverage, isolation, and response.

Backup and recovery

Frequency, immutability, offline copies, separation, retention, and restoration testing.

Patching and vulnerabilities

Scanning frequency, remediation targets, internet-facing systems, exceptions, and unsupported technology.

Email and fraud controls

Filtering, awareness training, payment verification, phishing simulations, SPF, DKIM, and DMARC.

Incident response

Written plans, executive authority, legal and forensic contacts, exercises, and escalation paths.

Vendor risk

Critical vendor inventories, reviews, contracts, privileged access, and concentration risk.

Governance

Executive ownership, policies, board oversight, risk tracking, prior incidents, and exceptions.

What the underwriter is really asking

Many weak answers are technically true but materially incomplete. Strong answers define scope, explain exceptions, and point to evidence.

Example: “Do you use multi-factor authentication?”

Weak answer

“Yes. We use MFA.”

There is no scope, enforcement detail, exception, or evidence.
Defensible answer

“MFA is enforced for workforce users, separate administrative accounts, remote access, and critical cloud applications. Two documented service-account exceptions are restricted and monitored.”

Support: policy, Conditional Access export, exception register.

A reliable completion process

Assign one accountable coordinator

Manage versions, questions, evidence, decisions, and deadlines without inventing technical answers.

Classify every question

Route technical controls to IT, governance to leadership, coverage details to finance or the broker, and privacy questions to legal or compliance.

Validate the current state

Review actual settings, reports, contracts, inventories, plans, and operating practices.

Document scope and exceptions

Record where controls apply, where they do not, and what compensating safeguards exist.

Review contradictions

Related answers about MFA, administrators, VPN, backups, incidents, and vendors must tell one consistent story.

Approve before submission

Leadership, IT, and the broker should review material representations together and retain the submitted version.

Evidence worth organizing in advance

Identity

MFA exports, privileged account lists, offboarding records, and access reviews.

Endpoint

EDR coverage, MDR agreements, inventories, and alert procedures.

Recovery

Backup architecture, immutability, retention, restore tests, and objectives.

Response

Incident plan, call tree, tabletop record, counsel, and forensic contacts.

Vulnerability

Scan summaries, patch standards, metrics, exceptions, and assessments.

Governance

Policies, vendor inventory, risk register, board reporting, and training records.

Pre-submission checklist

Leadership

  • Material gaps understood
  • Incident history accurate
  • Exceptions approved
  • Continuity claims verified
  • Final representations reviewed

IT and security

  • Control scope confirmed
  • Exceptions documented
  • Evidence matches answers
  • Configuration data current
  • Answers are consistent

Broker

  • Ambiguous wording clarified
  • Carrier expectations known
  • Attachments complete
  • Coverage changes discussed
  • Submitted copy retained

Frequently asked questions

Who should complete a cyber insurance questionnaire?

Use a collaborative team: an accountable coordinator, leadership, IT or the managed service provider, finance, legal or privacy stakeholders when applicable, and the broker.

Can our IT provider answer every question?

No. The provider can validate technical controls, but leadership must own governance, prior incidents, continuity, data handling, contracts, and risk acceptance.

Should we answer “no” when a control is partially implemented?

Ask the broker how the carrier wants partial implementation represented, then document scope, exceptions, and remediation clearly.

What happens if an answer is inaccurate?

An inaccurate material representation can delay underwriting, affect terms, or create disputes during a claim.

Do carriers verify questionnaire answers?

Practices vary, but carriers may use external scanning, follow-up questions, requested documentation, third-party reports, or claim-time investigation.

Review the answers before they become representations.

Clear Path Tech Assurance helps organizations interpret questionnaire language, validate controls, identify gaps, organize evidence, and prepare defensible responses before application or renewal.

Request a Questionnaire Review

See the Questionnaire Help service →