← Notes
July 25, 2026 · 6 min read

What a cyber insurance application actually asks

The control set US carriers now underwrite small businesses on, why “not sure” is scored as a no, and why answering honestly is the answer that protects you at claim time.

Cyber insurance applications have changed sharply. A few years ago the form was short and the questions were general. After a run of ransomware losses, carriers moved to a much more specific control set, and a business that cannot evidence those controls now faces higher premiums, reduced ransomware cover, or a declined application.

The control set carriers ask about

The specifics vary by carrier, but the recurring minimum set for a small business looks like this:

  • Multi-factor authentication — and increasingly not just on email. Remote access and privileged or administrator accounts are asked about separately, because those are where an attacker goes once email is hardened.
  • Endpoint protection on every device, not most of them.
  • Backups that are automatic, and separately, backups that have been restore-tested. These are two different questions and carriers ask them as two questions.
  • Patching and software updates — how they happen, and whether anything is running past its support life.
  • Security awareness training, with some notion of cadence.
  • A written incident response plan.
  • A written security policy.
  • Whether remote desktop is exposed directly to the internet, which is one of the most common ransomware entry points and a frequent decline reason on its own.
  • Prior incidents and prior claims.

“Not sure” is scored as a no

An unanswered or hedged field does not read as neutral to an underwriter. If you cannot confirm that endpoint protection covers every device, the assumption is that it does not, because a business with the control in place can usually say so. This is worth knowing before you fill the form in: the cheapest premium improvement available to most small firms is not buying a new tool, it is spending an afternoon establishing the answers they currently do not have.

Why honesty is the self-interested answer

The temptation on an application is to answer as the business you intend to be. The problem is that the application is a set of representations, and the moment it matters most is the moment a carrier is investigating a claim — with forensic evidence of what your environment actually looked like.

Self-attestation is quietly giving way to verification. Applications increasingly ask for screenshots or policy exports, and claim-time forensics establishes the rest. A control you claimed and did not have is the failure mode that ends coverage, and it is a worse position than having disclosed the gap up front and paid slightly more.

Coverwright does not guarantee insurance acceptance, claim outcomes, or regulatory compliance. What it does is make sure the documents you hand over describe the business you actually run.

What to do before the renewal

A practical sequence, in the order that produces the most improvement per hour spent:

  • Establish the answers you are unsure of. Every “not sure” you convert into a confirmed yes is a scored control.
  • Finish multi-factor authentication beyond email — banking, administrator consoles, remote access.
  • Test a restore from backup, once, and write down the date and the result. Carriers ask about tested backups specifically, and an untested backup is a hope rather than a control.
  • Close any direct remote desktop exposure.
  • Write the policy and incident response plan down — including, honestly, the controls that are still in progress with a named owner and a date.

That last point is where a generated document set earns its place. Answering a structured questionnaire about your business produces both the documents and a readiness summary showing which controls a carrier would score as in place and which as gaps — with the gaps stated as remediation commitments rather than quietly omitted or falsely claimed.