Skip to content
Resources

Guide

Cyber insurance readiness: what underwriters actually ask

Cyber insurance stopped being a checkbox purchase years ago. Underwriters now ask detailed technical questions, and your answers become warranties. This guide covers what they ask, why, and how to prepare evidence that stands up at claim time.

9 min readLast reviewed July 2026

How the market changed

After the ransomware loss years of 2020–2022, cyber underwriters stopped pricing on turnover and sector alone. Proposal forms grew from one page to many; some controls moved from “nice to have” to effectively mandatory for cover at any price. The market has softened and hardened in cycles since, but the underlying shift is permanent: insurers price the controls you can prove, not the intentions you describe.

For an SME this cuts both ways. Weak answers mean higher premiums, co-insurance, ransomware sub-limits or outright declinature. Strong, evidenced answers put you in the better half of the risk pool — and increasingly, insurers supplement your answers with outside-in scans of your domains, so the form is not the only input.

The questions that matter most

Forms differ by insurer, but a consistent core has emerged. Expect direct, specific questions on:

  • Multi-factor authentication — on email, remote access, admin accounts and increasingly all cloud services. This is the closest thing the market has to a knockout question: many insurers will not quote without MFA on email and remote access.
  • Backups — existence, frequency, whether a copy is offline or otherwise separated from production credentials, and whether restoration is actually tested.
  • Patching — your window for applying critical security updates, and whether anything unsupported remains in the estate.
  • Endpoint protection — what runs on every machine; some insurers now distinguish basic antivirus from EDR.
  • Email security — filtering, and anti-spoofing records (SPF, DKIM, DMARC) on your domains. These are externally checkable, so the answer is verified whether you like it or not.
  • Privileged access — separate admin accounts, and who holds domain or global-admin rights.
  • Incident readiness — a written response plan, and any prior incidents or claims (answer this one with complete candour; non-disclosure is the classic route to a voided policy).
  • Funds-transfer controls — call-back verification for changed bank details, dual authorisation over thresholds. Social-engineering fraud is a large share of SME claims, and insurers price these controls directly.

How posture maps to premiums

Underwriters generally band risks rather than price continuously. The practical consequence: a small number of controls move you between bands, and the rest fine-tune within a band.

SignalTypical underwriting effect
No MFA on email or remote accessDeclinature or heavy terms from many markets
No separated/offline backupRansomware sub-limits or co-insurance clauses
Unsupported operating systems in the estateExclusions for incidents traceable to them, or declinature
Cyber Essentials / Cyber Essentials PlusSmoother acceptance; some markets offer preferential terms
EDR, tested restores, documented response planAccess to better bands and higher limits

Precise discounts vary by insurer and cycle, so treat any specific percentage you read as marketing until it is on your quote schedule. The durable rule: the controls above are the levers; everything else is decoration.

Your answers become warranties

The proposal form is not a survey — it is the basis of the contract. If you answer “yes, MFA is enforced everywhere” and a claim investigation finds a shared mailbox without it, you have a coverage argument at the worst possible time. Under the Insurance Act 2015, a UK business proposer owes a duty of fair presentation; deliberate or reckless misrepresentation can void the policy entirely.

Three disciplines protect you:

  1. Answer from evidence, not memory. Check the actual tenant settings, the actual backup job, the actual patch report — on the day you fill in the form.
  2. Qualify honestly. “MFA enforced for all users except two service accounts, which are IP-restricted” is a better answer than a clean “yes” that is not quite true.
  3. Keep the evidence you answered from. If the estate drifts after binding, you want to know — some policies expect material changes to be notified, and you want to fix drift before it becomes a claims dispute.

Preparing an evidence pack

Assemble the following before you approach brokers — it shortens the process and signals a well-run risk:

  • MFA enforcement report from your identity provider (Microsoft 365 / Google Workspace).
  • Backup configuration and the date and result of your last test restore.
  • Patch/update status export showing supported versions and update cadence.
  • Endpoint protection coverage list — every device, what runs on it.
  • DMARC/SPF/DKIM records (externally checkable — make sure they are right first).
  • One-page incident response plan with named owners and out-of-hours contacts.
  • Certificates you hold (Cyber Essentials, ISO 27001) and their dates.

This is the same evidence a continuous rating draws from. TrustQuant’s agentless assessment reads this state directly from your cloud estate and keeps it current, so the pack exists the day a broker asks — see a sample report for what that looks like.

Renewal discipline

Renewal is where preparation compounds. Diarise it eight weeks out, re-verify every answer against current state (estates drift in twelve months), and lead with improvements — new controls since last year justify re-banding. If your posture has strengthened, make the market work for it: a broker can approach alternative insurers with your evidence pack rather than rolling the incumbent quote.

The SMEs that do best treat the insurer like any other counterparty who needs proof of resilience: keep the evidence continuous, and the annual form becomes an export rather than an excavation.

Reading is preparation. Measuring is proof — see where you stand in minutes, without installing anything.

Read a sample report

Turn this guide into a score

Run a free preview of your resilience rating, or apply for the Q3 2026 pilot cohort.