Guide · Small-business security
A cyber-insurance application is asking for evidence, not optimistic checkboxes.
The useful work is to translate each question into a specific system, group of people, control, and record—then answer the question that was actually asked.
Reviewed . This is practical technology guidance, not legal, insurance, or coverage advice. Policy language and the insurer's written interpretation control; involve your licensed insurance professional and counsel where appropriate.
The short answer
The form is trying to understand two things: the events the business could suffer and the controls that change the likelihood or consequence of those events.
The difficulty is that a one-word question often hides several boundaries. “Do you use MFA?” might mean email, remote access, administrators, vendors, every employee, or some combination. “Are backups tested?” might mean a file was recovered once or that a critical service has been restored into a clean environment within an agreed time.
Do not guess what sounds safest. Define the scope, verify the evidence, explain qualifications, and ask the insurer or broker to resolve ambiguity in writing.
Read each question as a control statement
Break a question into four parts:
- Who
- All employees, administrators, remote users, vendors, contractors, or people handling sensitive information?
- What
- Email, Microsoft 365, remote access, accounting, cloud applications, endpoints, backups, servers, or every system?
- How
- Required by technical enforcement, written policy, provider procedure, manual review, or an assumption nobody has tested?
- Evidence
- Configuration export, provider report, restore record, training log, incident plan, contract, inventory, or dated review?
This prevents a broadly worded “yes” from resting on one narrowly configured product.
The control areas that usually need owners
Applications vary, but small businesses are often asked to describe controls in several familiar areas:
- Identity and access: MFA coverage, administrative accounts, remote access, employee departures, and vendor access
- Backup and recovery: protected systems, isolation, retention, restore testing, recovery ownership, and demonstrated timing
- Endpoints and servers: security software, monitoring, patching, supported operating systems, and responsibility for remediation
- Email and people: phishing protection, awareness training, payment-change verification, and reporting suspicious activity
- Incident readiness: the response plan, outside contacts, notification process, decision authority, and exercises
- Data and vendors: sensitive information held, encryption, retention, cloud services, managed providers, and contractual responsibilities
The answer may cross several providers. The Microsoft 365 vendor knows the tenant; the line-of-business vendor knows its application; the MSP knows managed endpoints. Someone still has to assemble the complete answer for the business.
Build a small evidence pack
Instead of reconstructing the application from email each year, keep a dated set of records the business controls:
- A current inventory of users, devices, critical systems, cloud services, and technology providers
- An MFA coverage report that distinguishes employees, administrators, vendors, and exceptions
- A backup scope and the most recent restore-test record for each critical service
- A summary of endpoint protection, patch responsibility, and unsupported systems
- Training dates and the procedure for reporting suspicious email or payment requests
- The current incident-response contact sheet and decision authority
- Provider contracts or responsibility notes showing who owns each control
- A short register of known gaps, compensating measures, owners, and target dates
The pack is useful beyond insurance. It supports vendor reviews, customer questionnaires, audits, and the first hours of an incident.
Handle ambiguous yes-or-no questions carefully
Suppose the application asks, “Is MFA required for all remote access?” The environment has MFA for employee VPN access, but a software vendor retains a separate remote-support path.
A bare “yes” ignores the vendor path. A bare “no” may ignore the control that protects nearly all access. A useful response identifies the boundary: employee remote access is technically enforced; the vendor path is separately controlled, or it is a documented gap with a target date.
If the form provides no space for qualification, ask where the clarification should be recorded and retain the written response. Do not silently reinterpret “all,” “every,” “regularly,” or “tested.”
A gap is not permission to improvise
Finding a missing control during the application is valuable. It gives the business a chance to make a real decision before binding coverage or suffering an event.
The right response depends on the gap:
- Correct a narrow configuration and collect evidence.
- Add a compensating control when the preferred measure cannot be implemented immediately.
- Create a dated remediation plan and disclose it as instructed.
- Ask whether the proposed control is a condition of coverage, a pricing factor, or an underwriting preference.
- Reconsider a provider or system whose architecture makes an important control impossible.
Do not turn on a setting solely to capture a screenshot and then leave the operating process undefined. The answer must remain true after the application is submitted.
Coverage questions and security questions are different
A strong security control does not tell you what the policy covers. The Federal Trade Commission’s small-business cyber-insurance guidance recommends discussing the policy’s fit with your insurance professional, including first-party and third-party coverage and services available during an event.
Questions for the broker or insurer may include:
- Which events, systems, data, vendors, and territories are covered or excluded?
- How do business interruption, fraud, ransomware, data restoration, legal response, and regulatory matters differ under the policy?
- Which breach counsel, forensic firms, notification vendors, or response hotline must be used?
- What must the business do, and whom must it contact, before paying an invoice, engaging a responder, or communicating about an event?
- How do other policies interact with the cyber coverage?
- Which security representations remain continuing obligations during the policy period?
Those are coverage questions for licensed professionals. The technology work is to make sure the systems and evidence match the answers the business provides.
Before the application is signed
Have the business owner, the people responsible for the controls, the relevant providers, and the insurance professional review the final answers. Bring counsel in when wording, disclosure, or consequences require legal judgment.
Keep the submitted form, attachments, clarifications, supporting evidence, and later changes together. When a control changes, record the change instead of waiting for the next renewal to rediscover it.
Bottom line
Treat the questionnaire as a map of claims the business is making about itself. For each claim, name the people and systems in scope, verify the control, retain the evidence, and qualify the answer when reality is narrower than the checkbox.
The goal is not to produce the most impressive application. It is to produce an accurate one—and a short plan for the gaps it reveals.