A cyber insurance application asks for more than a list of security products. It asks the business to make representations about how identities, devices, data, backups, vendors, and incidents are actually managed.
The safest way to prepare is to treat the application as an evidence exercise. For every answer, identify the system in scope, the responsible owner, the supporting record, and any exceptions. If the answer changes by location, user group, or application, document that difference instead of forcing a convenient yes or no.
Insurance does not replace cybersecurity, and cybersecurity does not determine whether a specific loss will be covered. Policy language, exclusions, conditions, limits, retention, and claims facts matter. Work with a qualified insurance agent or broker and appropriate legal counsel on coverage questions; use IT and security professionals to verify technical statements.
1. Build an accurate scope before answering
Start with a current inventory of:
- Employees, contractors, service accounts, and privileged administrators.
- Laptops, desktops, servers, mobile devices, firewalls, switches, and other managed equipment.
- Microsoft 365 or Google Workspace, file storage, accounting, CRM, line-of-business, and remote-access systems.
- Customer, patient, employee, financial, payment, and other sensitive information.
- Locations, remote workers, hosted environments, and critical vendors.
- Backup systems, retention periods, recovery targets, and testing records.
Resolve acquisitions, old tenants, shared accounts, unsupported devices, and shadow IT before they disappear between application questions. A control that protects the main office but not a remote location should not be described as universal.
2. Verify multifactor authentication coverage
Do not answer “yes” to MFA based only on one email test. Verify coverage for:
- All workforce email and productivity accounts.
- Administrators and other privileged accounts.
- Remote access, VPNs, and remote management tools.
- Cloud consoles, backup administration, domain and DNS management.
- Financial, payroll, and other critical business applications where supported.
Record the authentication method and exceptions. Phishing-resistant methods such as security keys or passkeys can provide stronger protection than text messages or simple push approvals. CISA recommends requiring MFA wherever possible and beginning with administrative users, remote access, and people handling sensitive information.
Shared accounts create an evidence and accountability problem. Replace them with named users where feasible, and protect unavoidable service accounts with narrowly scoped permissions, managed credentials, monitoring, and a documented owner.
3. Show how endpoints and servers are protected
Create reports that demonstrate which devices are enrolled in endpoint protection, monitoring, encryption, and patch management. Investigate devices that have stopped checking in rather than assuming they are retired.
Document:
- Supported operating-system and application versions.
- Patch timelines, exception handling, and restart enforcement.
- Endpoint detection or antivirus coverage and alert ownership.
- Disk encryption and recovery-key management.
- Local-administrator controls.
- Device onboarding, replacement, and secure disposal.
If a legacy system cannot yet be replaced, record why it exists, isolate it where practical, restrict access, monitor it, and maintain a funded transition plan.
4. Prove that backups can support recovery
“We have backups” is incomplete. Identify every critical source, including servers, cloud files, email, application databases, configuration, and data held by vendors. For each source, document:
- Backup method and frequency.
- Retention and recovery-point options.
- Separation from ordinary production credentials.
- Protection against alteration or deletion.
- Monitoring and failed-job escalation.
- The most recent successful restore test.
- Expected recovery time and responsible owner.
CISA's Cyber Essentials recommends automatic, continuous protection for critical data and system configurations. Recovery testing is what turns stored copies into defensible capability.
5. Review email and payment-change risk
Business email compromise can turn a normal invoice, payroll request, or vendor conversation into a financial loss. Pair technical controls with operating procedures:
- Configure domain authentication and protective email policies.
- Block or flag suspicious forwarding and inbox rules.
- Monitor high-risk sign-ins and administrative changes.
- Require an independent, known-channel verification for payment or bank-detail changes.
- Train employees to report suspicious messages and MFA prompts quickly.
- Maintain a rapid account-compromise procedure.
Document the procedure and test it with the people who approve payments—not only the IT team.
6. Maintain a usable incident-response plan
The plan should assign authority for technical containment, business decisions, legal and privacy assessment, insurance notification, forensic support, customer or patient communications, and recovery.
Keep current contact information somewhere accessible when normal systems are unavailable. Define the events that require escalation, what evidence should be preserved, who can isolate devices or accounts, and how the organization will continue priority operations.
Run a tabletop exercise using a plausible event such as a compromised Microsoft 365 administrator, ransomware on a server, fraudulent vendor-payment request, or stolen laptop. Record decisions, gaps, owners, and deadlines.
7. Know your vendors and remote access paths
Managed service providers, software vendors, payment services, cloud platforms, and other partners may hold data or privileged access. Maintain:
- Vendor owner and business purpose.
- Data and systems accessible to the vendor.
- Named accounts, authentication method, and permission level.
- Contractual security and incident-reporting responsibilities.
- Subcontractor or hosting dependencies where relevant.
- Access-review and termination dates.
Remote support should use approved tools, protected administrative identities, least privilege, logging, and a defined removal process. Old vendor accounts and unmanaged remote tools deserve immediate attention.
8. Compare the proposed policy—not only the premium
Ask the insurance professional to explain limits, sublimits, deductibles or retentions, waiting periods, exclusions, notice requirements, consent provisions, panel vendors, and how related incidents may be grouped. Discuss the treatment of business interruption, data restoration, incident response, ransomware, social engineering, dependent-business interruption, regulatory matters, and contractual claims.
Texas Department of Insurance guidance emphasizes that policy language and terms vary and recommends reading the policy carefully and discussing applicable coverage with the insurer or agent. Do not assume that a general business policy covers cyber events or that every cyber policy responds the same way.
9. Answer truthfully and preserve the evidence
Create an application file containing the final signed form, definitions supplied by the carrier, clarification emails, control reports, test results, inventories, policies, exception records, and the names of people who verified each section.
Avoid absolute statements such as “all data is encrypted” unless scope and evidence support them. If remediation is underway, describe the current state and planned change accurately. Ask the insurance professional how the carrier wants qualified or partial answers documented.
Review representations during the policy period when the environment changes materially and begin renewal preparation early. Evidence goes stale when users, devices, vendors, or systems change.
A practical readiness packet
- Current user, device, system, data, and vendor inventories.
- MFA and privileged-access coverage reports.
- Endpoint protection, encryption, and patching reports.
- Backup scope, monitoring, and restore-test evidence.
- Incident-response plan and tabletop results.
- Security-awareness and phishing-reporting records.
- Vendor access and contract register.
- Recent vulnerability findings and remediation status.
- Completed application with definitions and clarifications.
Authoritative references
- CISA: Cyber Essentials
- CISA: Require Multifactor Authentication
- CISA: Guidance for MSPs and Small and Mid-sized Businesses
- Texas Department of Insurance: Business Interruption and Other Business Insurance
This guide is educational and is not insurance, legal, or coverage advice. Applications and policies vary. Confirm technical answers against current evidence and review all insurance questions with qualified professionals.

