A document lands from your cyber insurer ahead of renewal: pages of detailed technical questions about your systems, your controls, your backups, your access management. It reads like an exam you did not study for, and it is tempting to pass it to whoever looks after IT and ask them to “just fill it in.” That is a mistake. The questionnaire is not paperwork. It is a technical audit, and how you answer it determines your premium, the cover you get, and — at the worst possible moment — whether a claim is paid.
What the questionnaire is really doing
Insurers have learned, expensively, which technical controls actually reduce the chance and cost of a breach. The questionnaire is how they check whether you have them. Each question maps to a control they care about, and your answers set your risk profile. A business with strong controls gets cover and a reasonable premium. A business without them gets a higher price, narrower cover, or a polite decline.
So the document is, in effect, a free assessment of your security posture, written by people with a strong financial interest in getting it right. Treated that way, it is genuinely useful. Treated as a form to tick through, it is a trap.
Free · 4 minutes
If your most senior engineer left tomorrow, would anyone still understand the system?
Fourteen questions on documentation, dependencies, and the gap between how the architecture works and how many people know it. Banded finding on screen, full sheet by email.
What they are checking
The specifics vary by insurer, but the questions cluster around a familiar set of controls. Multi-factor authentication, particularly on email, remote access and administrator accounts — the single control insurers care most about, because its absence is behind so many breaches. Endpoint protection that can detect and respond to threats, not just basic antivirus. Backups that are kept offline or otherwise out of an attacker’s reach, and — the part most businesses fail — actually tested by restoring from them. A real patching routine, so known vulnerabilities get fixed promptly. Controls on privileged access, so administrator rights are not handed out freely. Email filtering, security-awareness training for staff, and a written incident response plan that says who does what when something goes wrong.
And, increasingly, a direct question about unsupported software. This is where many businesses quietly fail, because end-of-life Windows or an unpatchable, frozen stack like the compound problem describes is exactly the exposure insurers are trying to price — or avoid covering altogether.
Why honesty is not optional
Here is the part that turns this from an administrative chore into a serious matter. Insurance works on the accuracy of what you declare. If you state that you have a control you do not actually have — multi-factor authentication everywhere, tested backups, no unsupported software — and you later make a claim, the insurer can investigate what was really in place. If your answers were wrong, they have grounds to reduce or deny the claim. You will have paid premiums for years for cover that evaporates exactly when you need it.
This is why the questionnaire must be answered accurately, and why it cannot be rushed through by someone guessing. An overstated answer is worse than a missing control, because it converts a gap you knew about into a misrepresentation that can void your protection.
What to do if you cannot honestly tick the boxes
If you go through the questionnaire and find controls you cannot honestly confirm, that is valuable information, not a disaster. You have three sound responses. Close the gaps before you answer, where they are quick wins — enabling multi-factor authentication or testing a backup restore can often be done fast. Answer accurately and accept the terms that follow, which is honest and keeps your cover sound. Or, where a gap is real and material, disclose it and discuss it with the insurer or broker rather than papering over it.
What you must not do is fudge it. The short-term comfort of a clean form is not worth a denied claim later.
There is a broader point worth noting: the controls the insurer is checking overlap heavily with what regulators now expect, including the operational-resilience requirements of DORA for financial entities. Getting them right answers several questions at once.
If a renewal is at risk, a claim has been questioned, or you are staring at a questionnaire you are not sure you can answer honestly, that is worth dealing with quickly and with the right technical input. We will work through what you actually have, where the gaps are, and how to answer without losing your cover.
Start a ConversationRelated reading
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming