Over the past few years cyber insurance has moved from a product sold on a short questionnaire to a product underwritten after a technical assessment. The reason is simple: ransomware losses showed insurers they cannot price the risk without visibility into specific controls.
The questions that recur
Wording differs, but the substance converges. These are the areas that appear in almost every questionnaire:
Authentication and access
- Is multi-factor authentication enabled for remote access, for email, and for administrator accounts? All three are asked separately.
- How many privileged accounts are there and how are they approved?
- Are there separate accounts for administrative tasks?
Backups
- Is there a copy that is unreachable from the production network?
- When was a restore last tested, and how long did it take?
- Are backups encrypted, and is access to them behind multi-factor authentication?
Detection and response
- Is there endpoint protection with detection and response capability?
- Are logs monitored, and by whom outside working hours?
- Is there an incident response plan, and has it been exercised?
Vulnerability management and supply chain
- How quickly are critical vulnerabilities patched on internet-facing systems?
- Who are the key suppliers and do they have access to your systems?
- Are there systems past vendor end-of-support?
The questionnaire forms part of the contract. Answering "yes, we have multi-factor authentication" when it covers ninety per cent of users, and the attack comes through the other ten, opens an argument about whether the risk was accurately presented. A narrower answer with a caveat is always a better position than a broad one without.
What lowers the premium, and what is a precondition
It helps to separate two groups. Some controls affect price; others are a precondition for a quote existing at all. In recent years multi-factor authentication for remote access, an isolated backup copy and endpoint detection have all moved into the second group.
An organisation lacking those generally does not get a more expensive policy but no policy - or one with an exclusion covering precisely the scenario most likely to affect it.
Using what you already have
An organisation that has complied with the Croatian Cybersecurity Act or holds ISO 27001 already possesses nearly all the evidence the questionnaire asks for, only in a different format:
| The questionnaire asks for | You already have it in |
|---|---|
| Critical asset list and unsupported systems | The asset register (measure 2) |
| Patching and endpoint protection practice | Measure 5, cyber hygiene |
| Access control and MFA | Measure 7 |
| Incident response plan and exercise records | Measure 11 |
| Restore tests | Measure 12 and the BIA |
| Supplier risk assessment | Measure 8 |
The practical consequence: negotiations go better when the questionnaire is accompanied by a compliance status report with scores per measure. To an underwriter that is stronger evidence than a column of yes answers, and it gives you a negotiating position on both premium and breadth of cover.
Insurance does not replace controls, and it does not cover regulatory consequences the way it covers direct loss. Administrative fines under cybersecurity and data protection law are excluded or capped in most policies - check that before a risk management plan comes to rely on the policy.
Sources
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.