What is a cyber insurer really evaluating?
Insurers are trying to understand the likelihood and potential impact of a cyber event. Security questionnaires are one way to evaluate how well the organization controls common sources of loss such as credential compromise, ransomware, business email compromise, unpatched systems and failed recovery. A strong response is therefore more than a yes-or-no answer. The organization should know the scope of the control, where it applies, who owns it and how its effectiveness can be demonstrated.
Evidence mattersA control that exists only in a license, policy document or administrator’s assumption may not provide the protection leadership believes it does. Validate configuration and enforcement before representing the control as implemented.
Common control areas to review
Different insurers ask different questions, but several security themes appear frequently because they directly affect common loss scenarios.01
Multi-Factor Authentication
Understand where MFA is enforced for remote access, email, cloud applications, administrators and other important systems.02
Endpoint Protection
Confirm endpoint security coverage, monitoring, response capabilities and whether critical systems are actually enrolled.03
Backup & Recovery
Document backup coverage, retention, isolation, monitoring and evidence that restoration procedures have been tested.04
Email Security
Review anti-phishing, impersonation protection, domain authentication and controls for malicious forwarding or account takeover.05
Patch & Vulnerability Management
Know how systems are updated, how vulnerabilities are identified and how urgent remediation is prioritized.06
Administrative Security
Review privileged accounts, separate administration, least privilege and controls protecting high-impact identities.Do not confuse MFA registration with MFA enforcement
One of the most common areas of misunderstanding is multi-factor authentication. A user can have an authentication method registered without MFA being required for every relevant sign-in. Organizations should be able to explain which users, administrators, remote access methods and cloud services require MFA, which exceptions remain and what technical mechanism enforces the policy. For Microsoft 365 environments, this often means reviewing Entra ID authentication methods, Conditional Access policies, legacy authentication and administrative accounts rather than relying only on a user registration report.A backup is not the same as a recovery strategy
Cyber insurance questionnaires frequently pay attention to backup because ransomware and destructive incidents can create significant business interruption. The important question is not simply whether backups exist. Leadership should understand:- Which systems and data are included in backup coverage.
- How long recovery points are retained.
- Whether backup administration is protected from ordinary account compromise.
- Whether copies are isolated or otherwise resilient against destructive attack.
- How backup failures are monitored and escalated.
- When a representative restoration was last tested.
- What recovery time is realistically achievable for critical systems.
Recovery evidence is stronger than backup assumptionsA successful backup job proves that data was copied. A successful restore test provides much stronger evidence that the organization can actually recover.
Business email compromise deserves specific attention
Email compromise remains a major business risk because a single compromised identity can expose sensitive information, redirect payments, impersonate executives or establish persistence through mailbox rules and forwarding. A security review should consider MFA, anti-phishing controls, impersonation protection, mailbox auditing, suspicious forwarding, administrative access and domain authentication such as SPF, DKIM and DMARC.Endpoint and vulnerability controls should be measurable
Endpoint protection should be evaluated by coverage and operational response rather than product ownership alone. Leadership should know whether supported devices are enrolled, whether alerts are monitored and what happens when a high-severity event is detected. Similarly, vulnerability and patch management should have an identifiable process. Critical vulnerabilities, internet-facing systems and unsupported software should not remain unresolved simply because ordinary patch cycles exist.Prepare the response process before the incident
An incident response plan gives the organization a starting structure when normal decision making is under pressure. The plan should identify internal leadership, technology providers, legal and insurance contacts, communication responsibilities and escalation paths. It should also be realistic. A template that has never been reviewed with the people expected to execute it provides limited value during an actual event.A practical pre-renewal review process
Organizations can reduce uncertainty by reviewing the environment before completing the insurance application or renewal questionnaire.01
Collect
Gather the insurer’s questions, prior application, policy requirements and relevant technology documentation.02
Validate
Confirm the actual configuration, coverage and enforcement of the controls being represented.03
Remediate
Address meaningful gaps where practical and document known exceptions or dependencies.04
Document
Maintain evidence, ownership and concise explanations supporting the organization’s responses.What evidence should the organization keep?
| Control | Example Evidence | Question to Answer |
|---|---|---|
| MFA | Conditional Access policies, authentication reports, remote-access configuration. | Where is MFA actually enforced? |
| Endpoint security | Device inventory, coverage report, monitoring and response process. | Are supported endpoints protected and monitored? |
| Backups | Backup jobs, retention settings, restore test results, escalation process. | Can critical systems be recovered after a destructive event? |
| Email security | Anti-phishing policies, SPF/DKIM/DMARC, forwarding controls, audit settings. | What reduces account takeover and impersonation risk? |
| Patch management | Patch reports, vulnerability findings, remediation workflow. | How are urgent vulnerabilities identified and addressed? |
| Incident response | Response plan, contact list, tabletop or review records. | Who does what when an incident occurs? |