Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Knowledge base›Cyber insurance
Cyber insurance

What cyber insurers actually ask before they quote

A cyber insurance questionnaire is not a formality but a risk assessment somebody else is doing about you. The questions get more specific every year, and an inaccurate answer can become grounds for declining a claim.

Daniel Bara, PhD7 July 20266 min read

Over the past few years cyber insurance has moved from a product sold on a short questionnaire to a product underwritten after a technical assessment. The reason is simple: ransomware losses showed insurers they cannot price the risk without visibility into specific controls.

The questions that recur

Wording differs, but the substance converges. These are the areas that appear in almost every questionnaire:

Authentication and access

  • Is multi-factor authentication enabled for remote access, for email, and for administrator accounts? All three are asked separately.
  • How many privileged accounts are there and how are they approved?
  • Are there separate accounts for administrative tasks?

Backups

  • Is there a copy that is unreachable from the production network?
  • When was a restore last tested, and how long did it take?
  • Are backups encrypted, and is access to them behind multi-factor authentication?

Detection and response

  • Is there endpoint protection with detection and response capability?
  • Are logs monitored, and by whom outside working hours?
  • Is there an incident response plan, and has it been exercised?

Vulnerability management and supply chain

  • How quickly are critical vulnerabilities patched on internet-facing systems?
  • Who are the key suppliers and do they have access to your systems?
  • Are there systems past vendor end-of-support?
Why precision matters

The questionnaire forms part of the contract. Answering "yes, we have multi-factor authentication" when it covers ninety per cent of users, and the attack comes through the other ten, opens an argument about whether the risk was accurately presented. A narrower answer with a caveat is always a better position than a broad one without.

What lowers the premium, and what is a precondition

It helps to separate two groups. Some controls affect price; others are a precondition for a quote existing at all. In recent years multi-factor authentication for remote access, an isolated backup copy and endpoint detection have all moved into the second group.

An organisation lacking those generally does not get a more expensive policy but no policy - or one with an exclusion covering precisely the scenario most likely to affect it.

Using what you already have

An organisation that has complied with the Croatian Cybersecurity Act or holds ISO 27001 already possesses nearly all the evidence the questionnaire asks for, only in a different format:

The questionnaire asks forYou already have it in
Critical asset list and unsupported systemsThe asset register (measure 2)
Patching and endpoint protection practiceMeasure 5, cyber hygiene
Access control and MFAMeasure 7
Incident response plan and exercise recordsMeasure 11
Restore testsMeasure 12 and the BIA
Supplier risk assessmentMeasure 8

The practical consequence: negotiations go better when the questionnaire is accompanied by a compliance status report with scores per measure. To an underwriter that is stronger evidence than a column of yes answers, and it gives you a negotiating position on both premium and breadth of cover.

Insurance does not replace controls, and it does not cover regulatory consequences the way it covers direct loss. Administrative fines under cybersecurity and data protection law are excluded or capped in most policies - check that before a risk management plan comes to rely on the policy.

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.