← Guides

What cyber insurers ask small businesses, and how to answer

The security questions on a typical cyber insurance proposal form, what the insurer is really checking, and how to get ready before renewal.

Cyber insurance proposal forms vary between insurers, but the core questions are remarkably consistent. They focus on the few controls that make the biggest difference to claims: stolen passwords, ransomware and payment fraud.

Multi-factor authentication (MFA)

Expect questions on whether MFA is enforced for email, remote access and administrator accounts. This is often the single most important answer on the form. If you use Microsoft 365 or Google Workspace, MFA can be switched on for everyone in an afternoon.

Backups

Insurers want to know that you back up regularly, that at least one copy is kept separate from your main systems (offline or immutable), and that you have tested restoring from it. Many businesses assume Microsoft 365 or Google keeps a backup. They keep your data available, which is not the same thing.

A written incident response plan

"Do you have an incident response plan?" appears on almost every form. The insurer wants to know you will act quickly, contact them early, and not make things worse. A good plan fits on two pages: who to call, what to do in the first 15 minutes, and when to notify the regulator.

Payment fraud controls

Invoice and bank-detail fraud is one of the most common small-business losses. Expect a question about how you verify changes to supplier bank details. The answer insurers want: a call-back to a known number, and a second person approving new payees.

Updates and anti-malware

How quickly are security updates installed? Do all computers run anti-malware? Is any software out of support? A policy that sets deadlines (for example, critical updates within 14 days) plus automatic updates gives you a clear answer.

Staff training

Most attacks start with an email to a person. Insurers ask whether staff receive security awareness training, typically at induction and at least once a year.

How to get ready

  • Answer honestly. An inaccurate answer can invalidate a claim.
  • Close the quick wins first: MFA everywhere, a proper backup, and the bank-detail call-back rule.
  • Put written policies in place, signed and dated, so you can answer "yes" to the policy questions and prove it.
  • Keep evidence: screenshots of MFA settings, a backup test record, a training attendance list.

PolicyPack Pro includes a Cyber Insurance Readiness Checklist that shows your status on each of these controls based on your answers, plus a one-page Information Security Summary to send to your broker.

Get your policies in place in 10 minutes

12 tailored IT and cybersecurity policies in Word and PDF, from €149.

See the policy pack