Cyber Insurance

What to do when a cyber insurance form asks about login security, device protection and backups

Woman working at home on a laptop displaying a cybersecurity checklist with digital shield and cloud security icons overlaid

Cyber insurance forms often ask technical questions about multi-factor authentication, device protection and backups. A small business owner may recognise the product names but still not know whether the setup meets the insurer's definition.

Do not guess. Check the exact question, confirm the current setup and keep evidence for the answer.

The insurer or broker should explain unclear policy wording. Your IT provider can explain what is installed and how it is configured, but should not decide what the insurer means.

Check the scope before answering

A control may protect some staff or systems without covering the whole business. Before choosing yes or no, look for words such as "all", "remote access", "administrators", "servers" or "business-critical systems".

If the form allows comments, explain partial coverage clearly. If it only allows yes or no, ask the insurer or broker how to answer a mixed situation.

Use dates and specific systems where useful. Do not copy a sample answer unless it matches the business and the question.

What multi-factor authentication means

Multi-factor authentication, often shortened to MFA, requires more than a password to sign in. A user may approve a request in an app or use a separate security key.

The form may ask whether MFA protects email, remote access, administrator accounts and cloud services holding customer or financial data.

Check every active user and each system named in the question. MFA on the owner's account does not protect other accounts that still accept only a password.

Evidence for MFA

Evidence may include settings, reports or user lists showing who is covered. Protect any screenshots that reveal account or security details.

A clear description could state which named systems require MFA for all users and identify any system that is not yet covered. Have the insurer or broker confirm whether that supports the selected answer.

What managed device protection means

Some insurance forms use terms such as EDR, managed detection, advanced antivirus or monitored device security. These terms are not always interchangeable.

In plain English, the insurer may be asking whether business computers and servers have software that watches for suspicious behaviour, reports alerts and allows someone to respond. Ask what definition applies to the form.

Check every active device

Confirm which product is installed, which laptops, desktops and servers report to it, whether protection is active and who responds to alerts. Include spare, old and approved personal devices that can still reach business data.

A product installed on most laptops may not justify an answer that says every device is protected. Remove retired devices from access and investigate equipment that has stopped reporting.

Evidence for device protection

Useful evidence may include an up-to-date device list, coverage report, alert process and service record from the IT provider. The required proof depends on the form and policy.

What backup questions are asking

A backup question may cover which systems are included, how often backups run, how recovery copies are protected and when a restore was last tested. It may also ask how long copies are retained and who responds when a job fails.

Check servers, Microsoft 365 data, important cloud applications and any information stored only on a laptop. The scope should match the wording on the form.

Cloud storage and backup are not always the same

OneDrive, SharePoint, Dropbox and Google Drive may offer version history, deleted-item recovery or other recovery features. Whether that counts as a backup depends on the service, configuration, retention period and the insurer's definition.

Confirm what can be restored after accidental deletion, account compromise or a large-scale change. If the business relies on a separate backup service, check that it covers the intended email, files and sites.

Evidence for backups

Keep recent job reports, the list of protected systems, retention settings and restore test records. A restore test should record the date, the information recovered and the result.

Do not describe backups as tested if nobody has confirmed that usable information can be restored.

Review the rest of the form

Questionnaires may also ask about former staff accounts, updates, administrator access, staff training, payment checks, incident plans and outside providers. Use the same process for each item: read the scope, check the setup, collect evidence and clarify uncertain wording.

Handle partial coverage honestly

A real setup may not fit neatly into yes or no. For example, MFA may cover Microsoft 365 but not a booking system, or device protection may cover laptops but not an old server.

Where comments are allowed, state what is covered and what is not. Include a planned completion date only when the work has been approved and scheduled.

Do not describe future work as a current control.

Fix gaps in the right order

A review may find missing MFA, old accounts, unprotected devices or untested backups. Record each gap, the business risk and the person responsible for fixing it.

Priorities depend on the business and the form. Email and administrator access, active business devices and recoverable backups usually deserve early attention because they affect core operations. Confirm deadlines with the insurer before changing an answer.

Keep the submitted answers and evidence

Save a copy of the completed questionnaire, the insurer's clarifications and the evidence used. Record the date because settings and staff change.

Review the answers before the next renewal rather than copying last year's form. A previously accurate answer may no longer match the business.

Get help reviewing the form

JCPIT can review the technical parts of a questionnaire and explain what appears to be in place. We can identify missing evidence and security gaps, but the answers must remain accurate to the business and the insurer's definitions.

Before you submit the form, ask JCPIT to review the technical questions and arrange an approved secure way to send it. We will compare the questions with the evidence you provide and list anything that still needs checking. For policy interpretation, cover or claim questions, speak with the insurer, broker or a suitable legal adviser.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
Microsoft 365 backup: what Microsoft can and cannot restore
Next Article →
The 7 Microsoft 365 Settings Every Small Business Should Check