Josh DargieInfrastructure · Cloud · Software

Blog / for growing businesses

What cyber insurance forms really ask about your IT

A renewal questionnaire is really a short security audit. Here is what each question is asking, the answers owners get wrong, and what to fix first.

Every year or two a renewal form lands in a business owner's inbox with forty questions about their network, and I get a forwarded email that says "can you just fill this in?"

I usually can. The more useful thing is to read the form as what it actually is: a short security audit written by the people who have to pay out when it fails.

The form is the audit

Insurers are not asking out of curiosity. They have claims data, and the questions track the small number of controls that turn up in most of the incidents they pay for. That is why forms from different carriers look so similar: multi-factor authentication, backups, patching, endpoint protection, administrator accounts, email filtering, staff training, and how money leaves the business.

So if you answer honestly and half the answers are no, you have been handed a priority list for free. Most owners treat the thing as paperwork to get past. It is better written than a lot of security assessments I have read.

What the questions are really asking

"Do you require multi-factor authentication on email?" means every mailbox, including the shared ones, the owner's phone, and whatever the bookkeeper logs into. Partial coverage is a no.

"Do you allow remote access to your network?" means VPN, RDP, remote support tools, and the camera recorder somebody put a port forward on three years ago. The follow-up is always whether that access has MFA in front of it.

"Are backups offline or immutable?" means a copy that cannot be deleted by someone holding your administrator password. A second copy inside the same cloud tenant does not qualify, and neither does the drive that lives permanently plugged into the server. I went through what a small business backup plan actually needs in an owner's backup strategy.

"Do you have an incident response plan?" means a document with names and phone numbers in it, including after hours, and a decision already made about who can authorize taking systems offline.

"Who can approve a change to payment details?" is not an IT question at all. It is the fraud question. Change-of-banking-details requests are the attack I see attempted most often against small companies, and they succeed without any malware involved.

The answers people get wrong

I have never met an owner who lied on one of these forms. They answer from memory, and the memory is two years old.

The usual ones:

  • Microsoft 365 or Google Workspace counted as a backup. That is replication, not retention.
  • MFA reported as enabled because most staff have it. The exceptions are exactly where the problem lives.
  • Endpoint protection listed as managed when nothing has reported in for months and nobody would know if it had stopped.
  • Patching described as automatic, which is true for the workstations and not true for the firewall, the switch or the NAS.
  • A provider named as responsible for something their agreement does not actually cover. Read the contract before you put their name in that box, and see the fine print on warranty and support.

One more thing worth checking while the form is open is whether the accounts behind those answers are in the business's name at all. A questionnaire will not catch a domain or a firewall login sitting in a former contractor's personal account, and that is covered in who owns your business accounts.

Why a wrong answer is expensive

I am not a broker or a lawyer, so take the coverage question to the people who are. The mechanical part is what I can speak to. Your answers become part of the application, and an insurer looking at a ransomware claim will go back and read what you declared. If the form said immutable backups and there were none, that conversation happens with your systems down and your lawyer on the call.

Which is why I would rather hand back a form with four honest noes on it than a tidy page of yeses that nobody verified.

Answer with evidence, not memory

Before I sign off on one of these, I want to see the actual state of things rather than what we believe it to be.

That means a current list of accounts with MFA status rather than an impression, every way into the network from outside, built by looking instead of remembering, patch status for the network gear and the storage, and the administrator accounts with a name attached to each one.

And a restore. Not a backup report showing green, an actual file pulled back from last Tuesday while somebody times how long it takes. That one test answers three questions on the form and teaches you more than the rest of the exercise.

Treat it as a free roadmap

The Canadian Centre for Cyber Security publishes thirteen baseline controls for small and medium organizations. The overlap with a typical insurance questionnaire is close to complete, which makes sense, because both are working from the same incident data. Work through that document over a couple of quarters and most of next year's form answers itself.

Worth knowing where the bar sits. In the Insurance Bureau of Canada's 2025 survey, only 22 per cent of Canadian businesses carried cyber insurance of any kind, while 73 per cent of small businesses had already been through a security incident.

If a questionnaire is sitting on your desk and you are not confident which answers are true, that is a tidy, bounded piece of work. I go through it with you, verify what can be verified, and give you the short list of what to fix first. That is what the assessment is for, quoted as a fixed fee or hourly depending on scope, and you can get in touch if you want to put a date on it.

Sources

← All posts

Start with a conversation

Thirty minutes, no charge, no pitch.

Tell me the problem. I'll tell you whether I'm the right person for it, and if not, who is.