Insurers have been burned, and the forms show it. Five years ago the application was a page. Now it runs to forty questions, several of which decide whether you are insurable at all, and every one of which becomes a statement you have made about your organization.
After an incident the insurer will check those statements. An answer that turns out to be optimistic is a reason to reduce or refuse the claim.
The questions that matter most
| They ask | They mean |
|---|---|
| Is MFA enforced for all users? | All. Including the owner, and the shared mailbox, and the supplier account. |
| Do you use EDR on all endpoints? | Not antivirus. Something that is watched by a person. |
| Are backups offline or immutable? | Could an attacker with your admin password delete them? |
| Are backups tested? | When did you last restore one? Have the date ready. |
| Do you have an incident response plan? | Written down, with phone numbers, somewhere other than the network. |
What to do with a "no"
Write no. Then, in the space provided or on a covering page, say what you are doing about it and by when. Underwriters deal all day with applicants who tick every box; one who says not yet, in place by March, here is the purchase order is both more believable and frequently cheaper to insure.
Keep a copy
File the completed form with the policy. At renewal, start from last year's answers and update them. At claim time, you will want to know exactly what you said.
Where we come in
For clients on the Practice plan and above we complete the technical sections with you, and attach the most recent audit report as evidence. It tends to shorten the conversation.