Cyber-insurance applications have become the most common reason a growing company looks seriously at its own security for the first time. The form arrives, someone in finance forwards it to whoever seems most technical, and a set of yes/no answers gets returned within a week.
That is a bad process for two reasons. The first is that an inaccurate answer can affect a claim later. The second, quieter reason is that the questionnaire is one of the few artifacts that will make a leadership team look at controls at all — and answering it carelessly wastes that.
The questions that carry the most weight
Wording varies by carrier, but the substance clusters tightly. In practice, the answers that move a quote are about who can sign in, the state of your laptops, whether backups restore, and how email is protected.
- Is multi-factor authentication enforced for all remote access and all email accounts?
- Is MFA enforced for administrative accounts specifically?
- Are backups kept offline or in an account attackers cannot reach with production credentials?
- When was the last successful restore test, and what was restored?
- Is security software installed on every company device, and how many are actually checking in?
- How quickly are accounts disabled after an employee leaves?
- Are inbound emails from outside the organization visually marked?
- Is there a documented process for verifying changes to payment details?
- Who has local administrator rights on their own laptop?
"All" is a stronger word than it looks
The most common inaccurate answer we see is affirming MFA everywhere when the true state is MFA for most users, with a handful of exceptions: a service account, a shared mailbox, an executive who found it inconvenient, a legacy protocol left enabled for one old application.
Those exceptions are exactly the accounts that get used in a compromise. If you cannot produce a list of accounts without MFA, you do not yet know the answer to that question.
Backups: the dashboard is not the evidence
A backup job reporting success is a claim that data was written. It is not a claim that the data can be read back into a working system inside a timeframe your business can survive.
Test one restore before answering the backup questions. Record what you restored, how long it took, and who verified it. That single paragraph is more useful than the rest of the form.
If the answer is no
Answering no where the truth is no does not usually disqualify a company at this size. It changes the premium, or the carrier attaches a condition with a deadline to fix it. Both outcomes are survivable. A claim denied on a misrepresentation is not.
Where a control is planned but not in place, say so and give the date. Underwriters read that as a company that knows its own environment, which is itself a signal.
A practical sequence
Give the form two weeks, not two days. Week one: pull the actual lists — accounts without MFA, administrators, unmanaged devices, disabled-account lag. Week two: run a restore test and write the answers with evidence attached.
If nothing else comes out of the renewal, you will end it holding four lists you did not have before. Every other decision gets easier once you have them.