Cyber insurance can help with some costs after a cyber incident. Depending on the policy, this may include response work, legal advice, business interruption and required notifications.
Insurers often ask how the business protects its accounts, devices and data before they offer or renew cover. The questions and required evidence vary by insurer and policy.
Answer from the business's current setup, not from memory or plans for future work.
What insurers may ask about
Multi-factor authentication
Multi-factor authentication means a person needs more than a password to sign in. For example, they may approve the sign-in through an app on a registered device.
A questionnaire may ask whether this is required for email, remote access, cloud services and administrator accounts. Check every relevant user and system before answering.
Backups and recovery tests
The form may ask what is backed up, how often backups run and whether criminals could change or delete them.
It may also ask when the business last restored data from a backup. Keep reports and test records that show what was recovered and when.
Protection for computers and servers
Insurers may ask whether laptops, desktops and servers have current security protection. Check that every active business device is covered, reporting to a central service and generating alerts that someone reviews.
An installed product is not enough if it is out of date or nobody responds to warnings.
Software updates
Expect questions about how the business updates computers, servers, routers and important applications. A clear process should identify unsupported systems and confirm that updates complete.
Staff training
Training should help staff recognise fake invoices, changed bank details, suspicious login pages and urgent requests for passwords or payments.
Keep a record of when training occurred and who completed it if the questionnaire asks for evidence.
Email and payment controls
The insurer may ask about spam filtering, login protection and controls for fake sender addresses. It may also ask how the business checks a request to change bank details.
Use a known phone number to verify a payment change. Do not use contact details supplied in the request being checked.
Access control
Staff should have access only to the files and systems needed for their role. Remove access promptly when someone leaves and limit administrator accounts.
Avoid shared logins where the service supports individual accounts. Individual accounts make access easier to remove and actions easier to review.
An incident response plan
A useful plan tells staff who to call, how to report a problem and where to find insurer details if normal systems are unavailable.
It should cover affected device isolation, backups, communication and when to seek legal, privacy or regulatory advice. Keep an offline copy and review it after changes to staff or providers.
Why accurate answers matter
An insurer may ask for reports, screenshots, settings or other evidence. If an answer is inaccurate, the effect on an application or claim will depend on the policy, the circumstances and applicable law.
Do not guess or choose "yes" because a product name sounds familiar. Ask the insurer or broker what an unclear question means. Ask your IT provider to confirm what is in place. Get legal advice where needed.
Insurance does not replace security
A policy may help with covered costs, but it cannot stop work from being disrupted or repair customer trust. It may also contain limits, conditions and exclusions.
Treat insurance as one part of the business's response plan. Good day-to-day controls can reduce the chance and impact of an incident.
Prepare before renewal
Before completing the form, check sign-in protection, active devices, old accounts, supported updates and backup recovery. Review staff payment checks and the incident plan, then save the evidence with a copy of the submitted answers.
Renewal coming up? Ask JCPIT about collecting the technical evidence behind your answers. We will confirm the systems and access in scope, then give you a plain-English list of evidence and gaps to discuss with your insurer or broker.