Cyber insurance applications increasingly ask detailed questions about controls. The safest approach is to answer from verified configurations and documented processes rather than assumptions.

Treat every answer as a factual representation

Applications and renewal forms may ask whether a control applies to all users, all remote access, all privileged accounts, all endpoints, or all critical systems. Words such as “all,” “always,” and “within” matter. Validate the technical configuration and operational process before answering.

Multi-factor authentication

Confirm MFA coverage for Microsoft 365, remote access, cloud applications, administrative accounts, backup consoles, security tools, and vendor access. Review exceptions, legacy authentication, recovery methods, service accounts, enrollment, and whether modern phishing-resistant options are appropriate for higher-risk users.

Endpoint protection and managed response

Document which devices are covered, how inactive or unhealthy agents are detected, who reviews alerts, when response occurs, and what authority the response team has. Installing software is different from operating a monitored security process.

Backup and recovery

Validate the systems and data covered, frequency, retention, encryption, offsite or isolated copies, privileged access, immutability where appropriate, alert ownership, and restoration tests. Record the date and result of tests rather than relying only on backup success status.

Patching and vulnerability management

Define supported operating systems, applications, firmware, network devices, and remediation timelines. Identify exceptions, unsupported systems, ownership, compensating controls, and evidence that the process is working.

Email and payment-fraud controls

Review anti-phishing, impersonation protection, domain authentication, external sender indicators, malicious link and attachment defenses, user reporting, awareness training, and independent verification for payment changes.

Privileged access and remote access

Separate administrative accounts, minimize privileges, require strong authentication, monitor use, remove access promptly, control vendor connectivity, and document emergency access. Remote tools should be inventoried and authorized.

Incident response

Maintain current contacts for leadership, IT, security, legal counsel, insurer, broker, forensic provider, communications, law enforcement, and critical vendors. Practice decisions through a tabletop exercise before an incident.

Build an evidence package

Keep diagrams, inventories, reports, policy excerpts, configuration screenshots, test records, remediation plans, and responsible owners. Evidence makes renewal easier and helps identify differences between the written answer and actual operation.

DH
About the author

Donovan Huff leads Huff Data Systems, a Texas-based managed IT and cybersecurity company focused on reliable operations, cybersecurity, cloud, and CTO-level technology leadership for growing businesses.

View author profile →
Editorial purpose: This resource provides general business and technology education. It is not legal, insurance, compliance, or financial advice. Requirements should be reviewed with the appropriate qualified professionals.