Direct answer: Treat the application as a contract, not a form. Insurers price on a small set of controls, mainly multi-factor authentication, backup isolation, endpoint detection and a tested incident response plan. Overstating any of them can void a claim at exactly the moment you need it.
Why this form is different
A customer questionnaire affects a deal. An insurance application affects whether you get paid after an incident. Insurers have declined claims on the basis that the applicant said they had MFA everywhere when they did not, and the answer was on a form somebody signed. The honest answer, even where it costs you a better premium, is the only sensible one.
What they actually price on
Multi-factor authentication on email, remote access and privileged accounts. Backups that an attacker who owns your network cannot also encrypt, which usually means immutable or offline copies. Endpoint detection that somebody watches. A written incident response plan that has been exercised rather than filed. Patching, particularly on anything internet-facing.
The gap between "we have backups" and "we have backups an attacker cannot reach" is where most ransomware losses actually happen, and it is the question insurers have got much sharper about.
The tested plan is the cheap one
Of everything on that list, the incident response plan is the least expensive to fix and the one most often left undone. A tabletop exercise takes half a day, produces a written record, and answers the question honestly at renewal. It also tends to surface the gaps in the other controls, because running a scenario is how you discover that nobody knows who declares an incident.
Use the renewal date as the deadline
Insurance renewals are one of the few genuinely fixed deadlines in security. Work backwards from it. If MFA coverage is partial, close it before you answer rather than after. The premium difference is usually smaller than the cost of an uninsured incident, but the honesty is the point either way.
Our Cyber Insurance Readiness engagement works the application backwards into a fix list, and the Incident Response Tabletop covers the exercise itself, which is usually the fastest answer to change from a no to a yes.
Read the application the way a claims adjuster will
The underwriter reads your application to price the risk. The adjuster reads it eighteen months later to decide whether the risk you described is the risk that produced the loss. Those are different readers with different incentives, and the second one has your signed answers, your logs, and a forensic report in front of them. Before you fill anything in, read each question aloud and ask what a person holding a forensic timeline would conclude if the answer turned out to be optimistic. "Do you enforce multi-factor authentication for remote access to your network?" is not asking whether MFA is available in your identity provider. It is asking whether an attacker with a valid password and no second factor can reach anything. If there is one legacy VPN account with a shared credential and an exception, that exception is the sentence you need to write down.
Warranty language, and the questions that carry it
Most cyber applications end with an attestation that the statements are true and that the insurer is relying on them to issue the policy. In some markets, specific answers are elevated further, either through a warranty endorsement or through a condition precedent to liability attached to a named control. Ransomware supplements are the usual place this appears. If your policy carries a condition precedent requiring immutable or offline backups of critical systems, and the incident happens on a system whose backups sat in the same cloud account under the same credentials, the insurer has a clean argument for reducing or declining the claim on that head of loss. Ask your broker directly which answers are warranted and which are representations, and ask for the endorsement wording rather than a summary. Then take the warranted list to the people who actually operate those systems and confirm the answer with them before you sign, not after.
How to answer the MFA question when coverage is partial
Partial MFA is the normal state of a growing company, and insurers know it. The answer that gets you a policy is not "yes" and it is not a blank. It is a scoped yes with named exceptions and a remediation date. Something on the order of: MFA is enforced through the identity provider for all staff on email, the cloud console, the VPN and the code repository; three service accounts used for scheduled data loads authenticate with rotated API keys rather than a second factor and are restricted to a named source address range; one contractor account is excluded pending offboarding on a stated date. That answer prices slightly worse than a bare yes and defends perfectly. It also gives you a written record that the exceptions were disclosed, which is the whole point. If the broker pushes back that the carrier wants a simple yes or no, put the qualifier in a cover letter and ask that the letter be attached to the submission.
What underwriters check without asking you
Assume the carrier runs external attack surface data on your domain before quoting. Several of them buy the same commercial scanning feeds, and the results land on the underwriter's desk as a scorecard. Expired certificates, exposed remote desktop, an unpatched edge appliance, an open management interface on a forgotten staging host, mail records that permit spoofing, and credentials from third-party breaches matching your domain all show up there. None of that appears on the application, and all of it can move a quote or trigger a subjectivity you have to clear before binding. Running the same view of yourself first is cheap and takes an afternoon. Enumerate what is publicly resolvable under your domains, check the certificate and DNS records, close what should not be reachable, and keep the before and after. Bringing that to the submission changes the conversation from an argument about a score to a conversation about a fixed finding.
Sublimits are where the policy actually gets small
The headline limit is rarely the number that matters in a ransomware event. Look for the extortion sublimit, the coinsurance percentage on extortion payments, the waiting period on business interruption (often eight to twelve hours, applied before any income loss counts), the dependent business interruption terms covering your cloud and SaaS providers, and the betterment exclusion that stops the policy paying to upgrade the system you were meant to patch. A policy with a $5 million limit, a $500,000 extortion sublimit, fifty percent coinsurance on that sublimit and a twelve-hour waiting period behaves very differently from what the certificate implies. Read those numbers alongside your own recovery estimate. If you genuinely cannot restore a production database inside the waiting period, the business interruption cover is doing less for you than you think, and the money is better spent on restore testing than on buying a higher limit.
What to do if last year's answers were wrong
This happens more than anyone admits. Someone in finance completed the renewal from last year's copy, the environment moved, and now the form says something untrue. The fix is not to quietly correct it at the next renewal and hope. Tell your broker in writing that a prior answer no longer reflects the environment, state the current position, and ask for it to be submitted to the carrier as a material change. Carriers deal with this routinely. They may re-rate, add a subjectivity, or attach a condition, and any of those outcomes is better than having an undisclosed inaccuracy sitting under a live policy. Do the same mid-term when something material shifts: an acquisition that brings an unassessed network into scope, a migration that changes where backups live, the loss of the one person who ran your endpoint tooling. Materiality is judged by the carrier, so disclose and let them decide.
The evidence pack that makes renewals boring
Every question on the form has an artefact behind it, and gathering those artefacts in the week of the deadline is what produces sloppy answers. Keep a small folder, updated quarterly: an export from the identity provider showing MFA enrolment by user with the exception list; a screenshot or API output showing backup immutability settings and retention on the critical systems, plus the date and result of the last restore test; the endpoint agent coverage report against the asset inventory, with unmanaged devices named; the patch status of internet-facing systems; the incident response plan with its version date and the notes from the last tabletop, including who declared the incident and how long the call took to convene; and the current list of privileged accounts with owners. That folder answers roughly eighty percent of any carrier's application, and it answers a customer security questionnaire at the same time. If you want somewhere to keep it that is not a shared drive nobody trusts, the free traztech Workspace exists for exactly that.
When you should not hire us for this
If you are buying your first policy at under a million dollars of limit, your whole company runs on Google Workspace and one cloud account, and you have fewer than thirty staff, you do not need a consultancy to complete the application. A good specialist broker will walk you through it at no direct cost to you, and the honest answer to most of the questions is within reach of your own engineering lead in a day. Spend the money on the controls instead: enforce MFA everywhere including the exceptions, turn on immutable backup retention, and run a restore test. That is a better use of a few thousand dollars than any advisory hour. The point at which outside help earns its keep is narrower than the marketing suggests. It is when a warranted answer is genuinely ambiguous and the limit is large, when a carrier has attached subjectivities you cannot clear alone, when an acquisition has brought an environment nobody has assessed into the policy, or when you are trying to reconcile insurance answers with what you have already told auditors and customers and the two do not match. If that is you, our retainer work covers it, and pricing is published.
The twenty minutes before you call the broker
Write down three numbers first. How long it takes to restore your primary production data store from a backup an attacker could not have touched, measured by an actual test rather than an estimate. How many accounts can reach production without a second factor. How many hours of downtime the business absorbs before revenue is genuinely affected. Those three answers determine the shape of the cover you should be buying, and they are the answers most applicants cannot give. Walking into the renewal with them turns the process into a negotiation about price rather than an interrogation about controls, and it usually tells you which control to fix before you spend another dollar on premium.
Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.
Talk to usOr talk about a retainer