Cyber insurance renewal time can be stressful, especially when the questionnaire starts asking about things like MFA, device protection, device protection, immutable backups and recovery testing.
If you are a small business owner, you may not know whether you have these things in place. You may also be worried that a wrong answer could affect your cover later.
That concern is fair. A cyber insurance questionnaire is not just paperwork. It is often used by the insurer to decide whether they will cover you, what premium you will pay, and what conditions apply if you make a claim.
The good news is that most of these questions can be answered clearly once someone checks your setup properly. The key is not to guess, not to overstate, and not to tick boxes just because the wording sounds familiar.
First rule: do not guess
If your insurer asks whether you use MFA, device protection or tested backups, they are asking about real controls in your business. They are not asking whether you intend to do it later or whether you think your software probably includes it.
If you answer yes and later need to make a claim, the insurer may ask for evidence. That might include screenshots, reports, policy settings, backup logs or invoices from your IT provider.
A safer approach is to treat the questionnaire as a checklist of things to confirm. Some answers may be yes. Some may be no. Some may be partly, which usually means you need to explain the gap or fix it before renewal.
What MFA means in plain English
MFA stands for multi-factor authentication. In plain English, it means staff need more than just a password to sign in.
For example, after entering a password, they may also approve a sign-in on their phone or enter a code from an app. This helps stop criminals using stolen passwords to get into your email, cloud files or business systems.
Insurers commonly ask if MFA is enabled for:
- Email accounts, such as Microsoft 365 or Google Workspace
- Remote access, including VPNs and remote desktop tools
- Cloud systems that hold client, financial or business data
- Administrator accounts, which have higher access than normal users
- Accounting, payroll and banking-related platforms
The important detail is coverage. It is not enough for MFA to be turned on for one or two people if the rest of the business can still sign in with just a password.
How to answer MFA questions honestly
If MFA is turned on for every user and every key system, the answer may be yes. If it is only used for some staff or some systems, the answer is closer to partial.
A plain-English answer might be: MFA is enabled for all Microsoft 365 users and administrator accounts. MFA is not yet enabled on one third-party cloud system, and this is being reviewed.
That is much better than simply ticking yes without checking. It shows you understand the control and have identified any gaps.
What device protection means in plain English
device protection stands for device detection and response. Most business owners do not use that phrase day to day. A better way to think about it is stronger device protection for computers and servers.
Traditional antivirus looks for known bad files. Modern device protection watches for suspicious behaviour as well, such as a program trying to scramble your files, steal passwords or spread across the network.
Some insurance forms use different wording. They may ask about device protection, moderneration antivirus, device protection, managed detection, or whether devices are monitored for threats.
These questions usually relate to laptops, desktops and servers. In some cases, they also apply to phones or tablets if those devices access business email or files.
What to check before answering device protection questions
Before you answer, check what protection is actually installed and whether it is active on every business device. It is common to find old laptops, spare computers or personal devices accessing email without proper protection.
You should check:
- Which security product is installed on each device
- Whether all business computers are reporting in
- Whether alerts are being reviewed by someone
- Whether servers are included, not just staff laptops
- Whether protection is managed centrally or left to each user
The word managed matters. If a warning appears on a computer but nobody is responsible for seeing it or acting on it, the business may not be as protected as the insurance form assumes.
A plain-English answer might be: All business laptops and servers have managed device protection installed. Alerts are monitored by our IT provider. One retired laptop is no longer in use and will be removed from access.
Backups: the questions insurers care about
Backup questions are often where businesses get caught out. Many owners know they have some sort of backup, but they do not know what is backed up, how often it runs, where it is stored, or whether it has ever been restored.
Insurers may ask whether backups are:
- Run automatically
- Stored separately from the main system
- Protected from being deleted or changed by criminals
- Tested regularly
- Kept for a certain number of days or weeks
- Covering important systems, not just one folder
The goal is simple. If your business is hit by ransomware, a deleted mailbox, a stolen laptop or a damaged server, can you get your data back without paying a criminal or rebuilding everything from scratch?
Backup evidence you may need
If you make a claim, or if the insurer asks for proof during renewal, you may need more than a verbal confirmation.
Useful backup evidence can include:
- Backup reports showing successful jobs
- A list of systems included in the backup
- Screenshots of backup settings
- Records of restore tests
- Details of where backups are stored
- Retention settings showing how long backups are kept
A restore test is especially important. A backup is only useful if you can actually recover from it. Many businesses have discovered too late that their backup was incomplete, failing silently, or only protecting part of the business.
A plain-English answer might be: Backups run daily for our server and Microsoft 365 data. Backups are stored separately from our office systems. A test restore was completed in March and recorded.
Do not confuse cloud storage with backup
This is a common issue. Using OneDrive, SharePoint, Dropbox or Google Drive does not automatically mean you have a proper backup.
Cloud storage helps staff access and share files. It may also keep deleted files for a limited time. But it is not always the same as a separate backup designed for recovery after an attack, mass deletion or account compromise.
If your questionnaire asks about backups, do not assume cloud storage is enough. Check whether you have a separate backup service for email, files and key cloud data.
What to check before your renewal
Do not leave the questionnaire until the day it is due. Give yourself time to confirm the answers and fix simple gaps.
Before renewal, check these areas:
- MFA: Is it on for all users, all administrators, email, remote access and key cloud systems?
- Device protection: Are all business computers and servers protected and reporting properly?
- Backups: Are important systems backed up, stored separately and tested?
- Access: Have old staff accounts been disabled and old devices removed?
- Updates: Are computers, servers and important apps receiving security updates?
- Admin rights: Are staff using normal accounts for daily work, rather than administrator accounts?
- Evidence: Can you show reports, screenshots or records if the insurer asks?
These checks are not just for insurance. They reduce the chance of a cyber incident hurting your business in the first place.
How to handle questions you do not understand
If a question is unclear, do not try to translate it yourself. Insurance forms often use technical wording, and different insurers may phrase the same control in different ways.
A good IT provider should be able to mark up the questionnaire in plain English. That means explaining what the question is really asking, whether you meet it, what evidence supports the answer, and what needs to be fixed.
The answer should not be inflated to make the business look better. It should be accurate. If there is a gap, it is better to know before renewal than after an incident.
Be careful with yes and no answers
Some questionnaires only give yes or no options. Real life is often messier than that.
For example, MFA might be enabled for Microsoft 365 but not for a separate booking system. Device protection might cover staff laptops but not an old server. Backups might run daily, but no one has tested a restore in the last year.
In those cases, ask your broker or insurer whether you can add comments. A short explanation can be more accurate than forcing a yes or no answer that does not tell the full story.
Where possible, include dates and details. For example: MFA enabled for all Microsoft 365 users on 12 May. Backup restore test completed on 4 June. That kind of wording is clear and useful.
What if you find gaps?
Finding a gap is not a failure. It is the point of doing the review before renewal.
Some fixes are quick, such as turning on MFA for remaining users, removing old accounts, or confirming backup reports. Others may take longer, such as replacing weak device protection, setting up cloud backups, or improving remote access.
Prioritise the items that create the biggest business risk. Email MFA, administrator protection, managed device security and reliable backups are usually near the top of the list for small businesses.
If you need to tell the insurer about a gap, be factual. Explain what is in place now, what is not yet complete, and when it will be addressed.
Keep your own copy of the answers
Once the questionnaire is submitted, keep a copy with supporting evidence. Do not rely on memory or scattered emails.
Create a simple folder with the completed questionnaire, screenshots, reports, backup test notes and any comments from your IT provider. If you need to answer similar questions next year, this will save time and reduce stress.
It also helps if you ever need to make a claim. Clear records make it easier to show what was in place at the time.
Need help with the questionnaire?
If your cyber insurance questionnaire is asking about MFA, device protection, backups or other security controls, you do not have to work through it alone.
JCPIT can review the questionnaire and mark it up in plain English. We will tell you what each question means, what appears to be in place, what evidence you may need, and where the answers should not be guessed.
We will not rubber-stamp answers just to get the form done. You will get honest, practical guidance so you can respond with confidence.
If your renewal is coming up, send JCPIT the questionnaire and book a free security check. We will help you understand the gaps before the insurer, or a cyber incident, finds them for you.