What a Cyber Insurance Application Asks: MFA, Backups, Training, and More

A cyber insurance application asks about your business, the data you hold, and your security controls: multifactor authentication, backups, endpoint protection, patching, email security, training, and how you verify payments. It also asks about prior incidents and anything you know that could lead to a claim. The answers become part of the policy, so each one has to be accurate.

By Trella Commercial · Updated October 4, 2026

The short version

  • Cyber applications are security questionnaires. Expect 20 to 60 questions, most of them about how your systems are protected.
  • Who should answer: the owner or officer who signs, together with whoever runs your IT, whether that is an employee or an outside provider.
  • The answers are part of the contract. An inaccurate "yes," especially on multifactor authentication or backups, can give the insurer grounds to deny a claim or rescind the policy.
  • Fix before you apply. If a control is missing, adding it first usually gets better terms than explaining the gap.
  • Insurers check from the outside too. Most scan your website, email domain, and internet-facing systems before quoting.

Section 1: About your business

QuestionWhy they askTip
Legal name, address, and websiteIdentifies the insured and the domain they will scanList every website and email domain you use
Industry and description of operationsSets the base rateBe specific; "dental practice" rates differently from "health care"
Annual revenue, current and projectedProxy for size and downtime costUse the same figure as your other applications
Number of employeesIndicates attack surfaceInclude contractors with network access
Subsidiaries and other locationsDetermines who is coveredList every entity that should be insured

Section 2: The data you hold

QuestionWhy they askTip
How many records containing personal information do you hold?Breach response and liability costs scale with itCount customers, patients, clients, and current and former employees
What types: Social Security numbers, health, financial, card data, biometric?Sensitive data costs more after a breachWashington's breach law covers all of these; see what counts
Do you store card numbers, and are you PCI compliant?Card breaches bring brand assessmentsUsing a processor's hosted payment page usually means you do not store card data
Is sensitive data encrypted at rest and in transit, including laptops?Encrypted data usually does not trigger breach noticeConfirm full-disk encryption on every laptop
Do you collect health data or biometric data?Privacy law claims riskIn Washington, think about the My Health My Data Act

Section 3: Multifactor authentication

Usually the first and most important controls section. Many insurers decline or exclude ransomware without good answers here.

QuestionWhat a strong answer looks like
Is MFA required for all employees to access email?Yes, for every mailbox, including shared and former-employee accounts
Is MFA required for remote access to your network (VPN, remote desktop)?Yes, or you have no remote access to the network
Is MFA required for administrator and privileged accounts?Yes, with separate admin accounts used only for admin tasks
Is MFA required for cloud apps and backups?Yes, including your backup console and banking
Is remote desktop (RDP) open to the internet?No

Check before you answer. It is common to find a few mailboxes, an old admin account, or a vendor login without MFA.

Section 4: Backups and recovery

QuestionWhat a strong answer looks like
How often do you back up critical data?At least daily for systems you cannot run without
Are backups kept offline, immutable, or otherwise separated from your network?Yes; ransomware cannot reach or delete them
Are backups encrypted?Yes
Have you tested restoring from backup, and when?Yes, with a recent date
How long would it take to restore critical systems?A realistic estimate, based on the test

Section 5: Endpoint protection, patching, and email

QuestionWhat a strong answer looks like
Do you use endpoint detection and response (EDR) on all computers and servers?Yes, ideally monitored around the clock by a provider
How quickly are critical security patches applied?Within a defined window, such as 14 or 30 days, faster for actively exploited flaws
Do you run any unsupported or end-of-life software or operating systems?No, or it is isolated from the network
Do you filter incoming email for malicious links and attachments?Yes
Have you set up SPF, DKIM, and DMARC on your email domain?Yes
Do users have local administrator rights on their computers?No

Section 6: People and procedures

QuestionWhat a strong answer looks like
Do employees receive security awareness training?Yes, at least annually, with phishing simulations
Before changing vendor bank details or sending a large payment, do you verify by calling a known number?Yes, always, using a number already on file, not one from the request
Do you have a written incident response plan?Yes, including who to call first: your insurer's breach hotline
How do you manage vendors with access to your systems or data?Contracts with security requirements, and MFA on their access
Do you have an outside IT or managed security provider?Name them; they may need to help answer the application

Section 7: Prior incidents and known circumstances

QuestionWhy it matters
Have you had a breach, ransomware attack, or funds transfer fraud in the past several years?Prior incidents affect price and terms
Have you received a claim or regulatory inquiry about privacy or security?Same
Are you aware of any circumstance that could reasonably lead to a claim?Known circumstances are typically excluded from the new policy
Has another insurer declined, canceled, or non-renewed your cyber coverage?Underwriting history

The known-circumstances question deserves care. If you know about suspicious activity, a phishing incident, or a demand letter, disclose it. Coverage for that matter usually belongs with a prior policy, if any, and hiding it can void the new one.

How to prepare

  1. Get your IT person or provider in the room. Most "I'm not sure" answers are settled in a 30 minute call with them.
  2. Run an MFA audit. Check email, remote access, admin accounts, cloud apps, backups, and banking for every user.
  3. Do a test restore from backup and write down the date and how long it took.
  4. List your records: how many people, and what types of data.
  5. Confirm laptop encryption and EDR coverage on every device.
  6. Check your domain: SPF, DKIM, and DMARC, plus anything open to the internet that should not be.
  7. Write your payment verification rule if it is not already written.
  8. Gather incident history for the past several years.

What happens if an answer is wrong

The signed application is typically attached to and made part of the policy. If a material answer was untrue, for example MFA was not actually required on email, the insurer may deny a related claim or try to rescind the policy entirely. Some policies also exclude losses caused by failing to maintain the controls described in the application. If something changes after you apply, such as a control being turned off, tell your broker before the policy binds.

Common questions

What questions are on a cyber insurance application?

Questions about your business and revenue, the types and number of records you hold, multifactor authentication, backups, endpoint protection, patching, email security, training, payment verification procedures, vendor access, prior incidents, and known circumstances that could lead to a claim.

Can I get cyber insurance without MFA?

Some insurers will decline or exclude ransomware coverage without multifactor authentication on email and remote access. Adding MFA before you apply is usually the most effective way to improve both eligibility and price.

Who should fill out the cyber insurance application?

The officer who signs it, working with whoever manages your IT. Technical questions about backups, endpoint protection, and patching are best answered by your IT staff or managed service provider, but the signer is responsible for the answers.

What happens if I answer a cyber application question wrong?

Because the application becomes part of the policy, a material misstatement can let the insurer deny a claim or rescind the policy. If you discover an error or a control changes, tell your broker promptly so the application can be corrected.

Do insurers check my answers?

Many insurers scan your internet-facing systems before quoting and may ask follow-up questions about what they find. After a claim, forensic investigators will see how your systems were actually configured.

Sources

This page describes questions commonly found on cyber insurance applications. Each insurer's application differs. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.