Most cyber insurance applications ask about the same controls: multi-factor authentication, endpoint detection and response, backups kept apart and tested, patching, administrator access, email security and an incident plan. Answer each one from evidence rather than memory, because the answers are part of the policy.
The questions
Wording differs between insurers and changes at renewal, but these controls come up again and again:
| They ask about | What counts as a yes | Evidence to keep |
|---|---|---|
| Multi-factor authentication | On email and on every remote path, for everyone, enforced | An enforcement report and a list of exceptions |
| Endpoint detection and response | On every device, reporting to someone who acts on it | A coverage list, device by device |
| Backups | A copy kept apart from the network, and restores tested | Job results and dated restore tests |
| Patching | A defined window for critical patches | Monthly patch compliance |
| Administrator access | Named admin accounts, not shared ones | The admin list and the last review |
| Email security | Filtering, and SPF, DKIM and DMARC | The filter policy and the DNS records |
| Unsupported software | None, or a plan and a date for each | An asset register |
| Incident response | A written plan, reviewed | The plan and its review date |
The ones that trip people up
“All remote access.” Multi-factor on email isn’t the whole answer if someone can still reach a server by remote desktop or a VPN with just a password.
“Offline or immutable backups.” A backup on a drive that’s always connected to the network can be encrypted along with everything else.
“EDR” versus antivirus. Traditional antivirus matches known threats. Endpoint detection and response watches behavior and lets someone act on an alert. If your answer depends on which one you have, find out before you tick the box.
“End-of-life systems.” Windows 10 PCs without Extended Security Updates, and servers past support, count. Windows 10 after October 2026.
How to answer truthfully
Answer from evidence, not memory. If a control is partly in place, say so, and say when it will be finished. An inaccurate answer on an application can give an insurer grounds to dispute a claim later, so a careful “partially, completing by March” beats an optimistic yes. Your broker can tell you how your policy treats it.
Sixty days before renewal
- Pull last year’s application and this year’s form.
- Map every question to a control and to a record.
- Close the gaps that are quick: multi-factor, admin accounts, email records.
- Plan the ones that aren’t, with dates.
- Answer, and keep the evidence where you can find it.
Sometimes the review shows you’re already in good shape. That’s a good outcome, and worth knowing before the form arrives.
Read us first when you search.
GoogleAdd OpsWorq as a preferred source

