Cyber insurance questions we can answer for you

Cyber insurance questions we can answer for you

Cyber insurance applications and renewals used to be a page. Now they ask specific technical questions, and getting one wrong can mean a higher premium, a condition on the policy, or an argument at exactly the wrong moment.

Most of these questions are about systems we manage, so you do not have to guess. Send them to us and we will answer them accurately.

The questions insurers ask most

  • Is multi-factor authentication enabled on email, remote access and administrative accounts? Multi-factor authentication is the code or approval on your phone. This is the question insurers care about most, and increasingly they will not offer cover without it. They usually ask separately about each of the three, because many businesses have it on email only.
  • How often are backups taken, where are they kept, and have they been tested? The tested part is the one people answer too casually. Insurers are asking whether a restore has actually been performed, not whether backups run.
  • Are backups kept separate from the main network? They want to know whether an attacker on your network could also destroy the backups.
  • How quickly are security updates applied to computers and servers? Often phrased as a number of days for critical updates.
  • How many people have administrative accounts, and are those accounts used for day-to-day work?
  • Is there endpoint protection on every device, and is it centrally monitored? Endpoint protection is the software that detects and blocks malicious activity on a computer.
  • Do you still run any operating systems or software that is no longer supported by the vendor?
  • How is remote access provided? Insurers are looking for whether anything is exposed directly to the internet.
  • Do staff receive security awareness training, and how often?
  • Do you have a written process for verifying changes to bank details? This one is about payment redirection fraud, and it is a business process question rather than a technical one.
  • Do you have a documented incident response plan, and who would you call?

What we can answer, and what has to come from you

Where we manage your environment, we can answer the technical questions from what is actually configured rather than from memory. That covers multi-factor authentication, backups and restore testing, patching, endpoint protection, administrative access, remote access, and unsupported software.

The questions that must come from you are the business ones: training, your payment verification process, your policies, your claims history, your revenue and the kinds of personal or sensitive information you hold. We can help you describe the first two if you are unsure how to phrase them.

Answer these accurately, not optimistically

This is the part worth being blunt about. Insurance applications are declarations. If you tell an insurer that multi-factor authentication is enforced everywhere and it turns out to be on for three of your twelve staff, that discrepancy will be found during a claim, which is the least convenient moment in the life of your business to discover a gap in your cover.

An honest answer, including an honest no, is the safe answer. Insurers price the risk they can see. They are far more comfortable with a business that says "multi-factor is on email and remote access, not yet on the accounting system, and that work is scheduled" than with a business that says yes to everything and cannot support it.

If a question describes something you do not have and the insurer is treating it as a requirement, tell us. Some of these gaps are quick and inexpensive to close, and closing one before you submit is often cheaper than the premium loading for leaving it open.

Two practical tips

Start earlier than feels necessary. Renewal questions frequently reveal work that takes a fortnight, and a fortnight before the expiry date is not enough. A month is comfortable.

Keep the completed form. Next year's will be similar, and it also gives you a dated record of what you told the insurer, which is useful if anything is ever queried.

Talk to us

Send the application or renewal questionnaire to admin@yougrowit.com.au along with the date it is due. We will complete the technical sections, flag anything that is not accurate today, and give you a short list of what would be worth fixing before you submit.

Work to close gaps identified by an insurer is scoped and quoted rather than priced from a list, because it depends entirely on what the insurer is asking for and what is already in place. You will have the quote in writing before anything starts.

One thing we cannot do is give you insurance advice. Which policy to take, what cover you need and how much is a conversation for your broker.

    • Related Articles

    • You have been sent a security questionnaire: what to do

      A client, a prospective client, an insurer or a head contractor has sent you a spreadsheet or an online form with anywhere from twenty to three hundred security questions, and a due date that is sooner than you would like. It arrives with no warning ...
    • The Essential Eight in plain English

      Someone has asked whether you follow the Essential Eight, probably in a tender document, an insurance form or a client questionnaire. Here is what it is, without the jargon. The Essential Eight is a list of eight practical controls published by the ...
    • Evidence we can provide for a tender or a client audit

      Winning larger work increasingly means proving things rather than asserting them. A tender asks for evidence of your security arrangements, a big client's procurement team wants documentation before they will onboard you, or an auditor asks to see ...
    • Notifiable data breaches: your obligations in plain English

      If personal information held by your business is lost, or accessed or disclosed without authorisation, you may have obligations under Australian privacy law. This article explains the scheme in plain terms so that you know what you are dealing with. ...