Skip to main content

Cyber Insurance Questionnaires: The Controls They Actually Check

Media Cyber Insurance Questionnaires The Controls They Actually Check

Applying for cyber insurance can feel like sitting a security exam.

The questionnaire asks whether you use multifactor authentication, endpoint detection and response, tested backups, vulnerability scanning and privileged-access controls. Some questions appear straightforward until you realise that “yes” may need to apply to every relevant user, device, administrator and remote-access route—not merely the systems IT considered first.

Insurers use these answers to estimate how likely your organisation is to experience a cyber incident and how expensive that incident could become. The controls most frequently assessed are closely linked to ransomware, account compromise, data theft and prolonged business interruption. 

The safest approach is simple:

Treat the questionnaire as a security assessment, verify every answer and retain evidence showing that the stated controls genuinely operate.

Why Cyber Insurers Ask About Security Controls

Cyber insurance may help with costs arising from incidents such as data breaches, ransomware, business interruption and cybercrime. Depending on the policy, support may include forensic investigation, legal advice, customer notification and public-relations assistance. Coverage and conditions vary between insurers and policies. 

Before offering that cover, insurers want to understand the organisation’s exposure.

They may assess:

  • How easily an attacker could gain access
  • Whether malicious activity would be detected
  • How far an attacker could move through the environment
  • Whether usable backups would support recovery
  • How quickly the organisation could respond
  • Whether one compromised administrator could control everything
  • How much sensitive information could be affected

A positive answer may not automatically produce a lower premium, and one missing control may not always prevent cover. However, controls such as endpoint detection and response, MFA and privileged-access management are repeatedly identified as important cyber-insurance risk factors. 

1. Multifactor Authentication

MFA is one of the most common controls on a cyber insurance questionnaire.

The insurer may ask whether MFA protects:

  • Microsoft 365 and other cloud services
  • Remote access and VPN connections
  • Administrator accounts
  • Email access
  • Remote desktop systems
  • Backup administration
  • Critical business applications

This is where a casual yes can become dangerous.

Your organisation may require MFA for ordinary Microsoft 365 users while an old VPN, service account or administrator portal still relies on a password alone.

The NCSC recommends MFA for corporate online services and advises organisations to use stronger, phishing-resistant methods where possible. 

Before answering, verify:

  • Which users are covered
  • Which applications are covered
  • Whether administrators use stronger authentication
  • Whether legacy authentication remains available
  • Whether exclusions exist
  • Whether emergency accounts are separately protected and monitored

Evidence might include Conditional Access exports, authentication-method reports, VPN settings and screenshots showing enforcement.

2. Endpoint Detection and Response

Traditional antivirus primarily looks for known threats. Endpoint detection and response, or EDR, continuously monitors computers and servers for suspicious behaviour and gives responders tools to investigate and contain an attack.

Insurers may ask whether EDR covers:

  • Employee laptops
  • Desktop computers
  • Servers
  • Remote workers
  • Cloud-hosted systems
  • Privileged administrative devices

EDR, logging and monitoring have been associated with reduced cyber-claim likelihood in insurance-industry analysis. 

Do not answer based only on purchasing the product.

Confirm:

  • The security agent is installed
  • Devices are actively reporting
  • Tamper protection is enabled
  • Alerts reach someone who will investigate
  • Devices can be isolated remotely
  • Servers are included where required
  • Departed or replaced devices are removed from the console

A tool showing 48 protected devices is not complete coverage if the company has 55 active endpoints.

3. Backups That Survive Ransomware

The questionnaire may ask whether backups are:

  • Regular
  • Encrypted
  • Tested
  • Offline
  • Immutable
  • Segregated from the production environment
  • Protected with separate credentials
  • Covered by MFA

The insurer is not asking only whether files are copied somewhere.

It wants to know whether an attacker who compromises the network can also delete or encrypt the backups.

The NCSC recommends that backup administration use credentials separate from ordinary network administration and that destructive backup actions require MFA. 

Ransomware-resistant backup design should include:

  • Multiple recovery points
  • A copy isolated from production
  • Restricted administrative access
  • Alerts for deletion or policy changes
  • Documented retention
  • Routine restoration tests
  • Recovery-time and recovery-point objectives

The strongest evidence is a successful restore report—not a screenshot saying the last backup job completed.

4. Privileged-Access Management

Insurers pay close attention to administrator accounts because attackers frequently use elevated access to disable security controls, spread ransomware and damage backups.

Questions may cover:

  • Number of Global or Domain Administrators
  • Separate accounts for administrative work
  • Time-limited administrator access
  • Approval for privileged activity
  • Password vaulting
  • Access reviews
  • Monitoring of administrator sign-ins
  • Removal of former staff and suppliers

Microsoft Entra Privileged Identity Management and similar tools can make roles eligible rather than permanently active, limiting how long elevated permissions remain available.

Even without a full privileged-access platform, a small business can improve its answer by:

  • Reducing permanent Global Administrators
  • Providing separate admin accounts
  • Requiring phishing-resistant MFA
  • Restricting admin access to managed devices
  • Reviewing roles quarterly
  • Monitoring emergency-account usage

Do not describe a password manager as privileged-access management unless it genuinely governs privileged credentials and access.

5. Patching and Vulnerability Management

A questionnaire may ask how quickly critical vulnerabilities are fixed.

Possible response options include:

  • Within 7 days
  • Within 14 days
  • Within 30 days
  • According to severity
  • No formal target

Insurers may also ask whether you scan for vulnerabilities, unsupported software and internet-facing systems.

The NCSC advises organisations to check patching and ensure security updates are applied as part of heightened-threat preparation. 

A credible patching process includes:

  • An inventory of devices and software
  • Automated operating-system updates
  • Third-party application patching
  • Defined deadlines based on severity
  • Reporting for failed updates
  • A process for emergency vulnerabilities
  • Replacement of unsupported systems
  • Documented exceptions

Answer according to what actually happens—not the target written in a policy nobody measures.

6. Email and Web Security

Because phishing remains a common initial access route, insurers frequently ask about:

  • Spam and malware filtering
  • Anti-phishing and impersonation protection
  • Attachment analysis
  • Time-of-click link scanning
  • DMARC
  • Security-awareness training
  • Phishing simulations
  • Blocking external auto-forwarding

Marsh’s commonly referenced cyber controls include email filtering and web security alongside MFA, EDR, backups and privileged-access management. 

For Microsoft 365, evidence may include:

  • Defender for Office 365 policies
  • Safe Links and Safe Attachments coverage
  • Anti-phishing settings
  • SPF, DKIM and DMARC records
  • Outbound forwarding restrictions
  • Phishing-training reports

Having an email filter does not mean every advanced protection is enabled.

7. Remote Access and Exposed Services

Remote access is attractive to attackers because it can provide a direct route into the business network.

Insurers may ask about:

  • Remote Desktop Protocol
  • VPN access
  • Remote monitoring and management tools
  • Supplier remote access
  • Internet-facing administrative portals
  • Geographical restrictions
  • MFA enforcement

Remote Desktop should not be exposed directly to the internet.

Where remote access is necessary:

  • Require MFA
  • Restrict access by user and device
  • Use a secure gateway or VPN
  • Remove unused accounts
  • Monitor successful and failed connections
  • Patch remote-access appliances
  • Review supplier access regularly

Do not overlook an old firewall rule or remote-support tool installed by a former provider.

8. Logging and Monitoring

Insurance questionnaires increasingly ask whether the organisation collects and reviews security logs.

Useful sources include:

  • Microsoft Entra sign-in logs
  • Microsoft Purview Audit
  • Endpoint detections
  • Firewall and VPN logs
  • Server security events
  • Backup activity
  • Privileged-role changes
  • Email-security alerts

The NCSC identifies logging and monitoring as part of an organisation’s defensive readiness, while insurance-sector research has associated effective monitoring with lower breach-claim probability. 

The important distinction is between collecting logs and monitoring them.

A log that nobody reviews until six months after an attack may help an investigation, but it has not provided active detection.

Document:

  • Which logs are retained
  • How long they are kept
  • Who reviews alerts
  • Whether monitoring is continuous or business-hours only
  • How incidents are escalated
  • Whether logs are protected from alteration

9. Incident Response Planning

Insurers may ask whether you have a documented incident response plan and whether it has been tested.

A credible plan should identify:

  • Incident roles
  • Emergency contacts
  • Technical containment procedures
  • Insurer notification requirements
  • Legal and regulatory escalation
  • Communications responsibilities
  • Backup and recovery processes
  • Evidence-preservation steps

Insurance-industry research published in 2025 linked proactive incident response planning with a reduction in the likelihood of breach-related claims. 

Do not answer yes merely because a generic policy exists.

A useful plan should be:

  • Specific to your organisation
  • Accessible during a Microsoft 365 outage
  • Reviewed regularly
  • Supported by incident playbooks
  • Tested through a tabletop exercise

Keep your insurer’s emergency reporting details in the plan.

10. Security Awareness and Phishing Testing

Insurers may ask whether employees receive cybersecurity training and how frequently it occurs.

They may also ask whether the training includes:

  • Phishing
  • Payment fraud
  • Passwords and MFA
  • Data handling
  • Reporting procedures
  • Remote working
  • Social engineering

Annual training alone may not be enough to demonstrate an active programme.

A more effective approach combines:

  • Induction training
  • Short recurring updates
  • Phishing simulations
  • Targeted follow-up
  • Finance-specific fraud training
  • Easy reporting methods
  • Management participation

Training should improve behaviour, not merely create a completion certificate.

Cyber Essentials and Independent Assurance

Some insurers may ask whether your organisation holds Cyber Essentials or Cyber Essentials Plus.

The UK government states that organisations implementing Cyber Essentials controls experience substantially fewer insurance claims than those without them. 

Certification does not replace every control on an insurer’s questionnaire, but it can provide independent assurance around core areas such as:

  • Firewalls
  • Secure configuration
  • Security updates
  • User-access control
  • Malware protection

Cyber Essentials Plus includes technical verification, making it stronger evidence than self-assessment alone.

How to Answer Ambiguous Questions

Do not guess what a broad term means.

For example:

Is MFA enabled for all remote access?

Clarify whether this includes:

  • VPN
  • Remote desktop
  • Microsoft 365
  • Cloud administration
  • Third-party support
  • Remote monitoring tools

Another example:

Are backups offline?

Clarify whether the insurer accepts immutable cloud backups or requires a physically or logically disconnected copy.

Ask your broker or insurer to define unclear wording in writing.

A qualified answer is better than a misleading one:

MFA is enforced for all employees and administrators accessing Microsoft 365 and the corporate VPN. Two legacy service accounts are currently exempt and are scheduled for replacement by 30 September.

That gives the insurer an accurate picture and allows it to decide whether the exception matters.

Evidence to Keep With the Questionnaire

Create an evidence folder containing:

  • Completed questionnaire
  • Policy wording
  • MFA and Conditional Access reports
  • Endpoint coverage reports
  • Backup job and restore-test results
  • Vulnerability and patching reports
  • Privileged-role exports
  • Incident response plan
  • Tabletop exercise record
  • Security-training reports
  • Cyber Essentials certificate
  • Written clarifications from the insurer or broker

Record who approved each answer and the date it was verified.

Cyber controls change. An answer that was accurate at renewal may no longer be true after a migration, staffing change or policy modification.

Common Questionnaire Mistakes

Answering for Most Users Instead of All Relevant Users

One unprotected administrator or remote-access route may invalidate a broad yes.

Confusing Purchased With Implemented

Owning an EDR licence does not prove that every device is protected.

Assuming Backups Are Recoverable

A successful backup job is not the same as a tested restoration.

Ignoring Cloud Services

The questionnaire may apply to Microsoft 365, cloud applications and hosted infrastructure—not only office servers.

Overstating the Control

Avoid describing a basic antivirus product as EDR or an ordinary password manager as privileged-access management.

Completing the Form Alone

IT, management, finance, legal, the broker and relevant suppliers may each hold information needed for accurate answers.

Final Thoughts

Cyber insurance questionnaires reveal what insurers believe will influence the likelihood and cost of a serious incident.

The controls they repeatedly examine are not surprising:

  • MFA
  • Endpoint detection and response
  • Ransomware-resistant backups
  • Privileged-access management
  • Patching
  • Email security
  • Secure remote access
  • Logging and monitoring
  • Incident response
  • Employee awareness

The questionnaire should not be treated as a sales form to complete as positively as possible.

Treat it as a formal statement of your security position.

Verify the scope of every control, document exceptions and retain evidence supporting each answer. Where a gap exists, explain it honestly and provide a realistic remediation date.

A slightly imperfect but accurate application is far safer than a perfect-looking form that cannot withstand a claim investigation.

Need Help Preparing for a Cyber Insurance Application?

Hamilton Group can help your organisation review the technical controls commonly assessed by cyber insurers.

Our experts can help you:

  • Verify MFA and Conditional Access coverage
  • Review endpoint protection and EDR deployment
  • Assess backup resilience and test restoration
  • Reduce excessive administrator access
  • Review patching and vulnerability management
  • Strengthen Microsoft 365 email security
  • Secure remote access
  • Configure audit logging and monitoring
  • Build and test an incident response plan
  • Prepare evidence supporting questionnaire answers

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to identify and address cyber-insurance control gaps before renewal.