OPSWORQ

Guide

What your cyber insurer will ask, and how to answer truthfully

By OpsWorq engineeringReviewed September 20267 min read

Most cyber insurance applications ask about the same controls: multi-factor authentication, endpoint detection and response, backups kept apart and tested, patching, administrator access, email security and an incident plan. Answer each one from evidence rather than memory, because the answers are part of the policy.

The questions

Wording differs between insurers and changes at renewal, but these controls come up again and again:

They ask aboutWhat counts as a yesEvidence to keep
Multi-factor authenticationOn email and on every remote path, for everyone, enforcedAn enforcement report and a list of exceptions
Endpoint detection and responseOn every device, reporting to someone who acts on itA coverage list, device by device
BackupsA copy kept apart from the network, and restores testedJob results and dated restore tests
PatchingA defined window for critical patchesMonthly patch compliance
Administrator accessNamed admin accounts, not shared onesThe admin list and the last review
Email securityFiltering, and SPF, DKIM and DMARCThe filter policy and the DNS records
Unsupported softwareNone, or a plan and a date for eachAn asset register
Incident responseA written plan, reviewedThe plan and its review date

The ones that trip people up

“All remote access.” Multi-factor on email isn’t the whole answer if someone can still reach a server by remote desktop or a VPN with just a password.

“Offline or immutable backups.” A backup on a drive that’s always connected to the network can be encrypted along with everything else.

“EDR” versus antivirus. Traditional antivirus matches known threats. Endpoint detection and response watches behavior and lets someone act on an alert. If your answer depends on which one you have, find out before you tick the box.

“End-of-life systems.” Windows 10 PCs without Extended Security Updates, and servers past support, count. Windows 10 after October 2026.

How to answer truthfully

Answer from evidence, not memory. If a control is partly in place, say so, and say when it will be finished. An inaccurate answer on an application can give an insurer grounds to dispute a claim later, so a careful “partially, completing by March” beats an optimistic yes. Your broker can tell you how your policy treats it.

Sixty days before renewal

  1. Pull last year’s application and this year’s form.
  2. Map every question to a control and to a record.
  3. Close the gaps that are quick: multi-factor, admin accounts, email records.
  4. Plan the ones that aren’t, with dates.
  5. Answer, and keep the evidence where you can find it.

Sometimes the review shows you’re already in good shape. That’s a good outcome, and worth knowing before the form arrives.

Read us first when you search.

GoogleAdd OpsWorq as a preferred source

Get started

Questions this guide didn’t answer?

1‑855‑OPSWORQ

855‑677‑9677 · Mon–Fri, 8am–5pm ET

If the business has stopped, call. Don’t use the form.

Ask the engineers who wrote it. A person replies within one business day.

What’s it about? Select all that apply.

A sentence is plenty.

A person replies within one business day. Nothing is sold, and you’re not added to a mailing list.

Prefer to talk? Pick a time for a 20‑minute review Or call 1‑855‑OPSWORQ.

Call Get your price