Skip to content

Compliance · Cyber insurance

Your renewal application asks harder questions than your last audit did.

Carriers no longer sell cyber coverage on a signature and a premium. They require enforced MFA, EDR, tested backups, and more, and every answer you give is a statement they can hold you to when a claim arrives. Our job is simple: make the honest answer to every question yes, and give you the paperwork that proves it.

Where coverage actually fails.

Denied and rescinded claims rarely come from exotic hacking. They come from the application itself. Three patterns cover most of it:

The "aspirational yes"

Answering yes because MFA is mostly on, or backups probably work. If a claim investigation finds the answer was wrong on the day you signed, the carrier can rescind the policy. In one widely reported 2022 case, an insurer did exactly that after a ransomware claim, because the application said MFA was enforced and it was not.

The unasked follow-up

Applications are short; investigations are not. "Do you have EDR" becomes "show us the deployment coverage report for the day of the incident." The documentation is the part most businesses cannot produce.

The renewal drift

Controls that were true at binding quietly degrade: an exception here, a disabled policy there. The renewal restates the answers, and nobody re-checks them.

The questionnaire, decoded

Eight questions on essentially every application, and what a defensible "yes" requires.

Exact wording varies by carrier. The substance does not.

The application asks

“Is multi-factor authentication enforced for all email accounts?”

What it means

Not "available". Enforced, for every user, with legacy sign-in protocols that bypass MFA turned off.

What we implement

MFA enforcement and conditional access across Microsoft 365 or Google Workspace, legacy authentication disabled, exceptions documented.

The application asks

“Is MFA required for remote network access and privileged accounts?”

What it means

VPN, remote desktop, and every admin account, not just the everyday users.

What we implement

MFA on remote access paths, separate hardened admin accounts, least-privilege role assignment.

The application asks

“Do you use endpoint detection and response (EDR)?”

What it means

Modern behavioral detection with a response capability, not 2018 antivirus.

What we implement

Huntress EDR on every endpoint, with 24/7 threat hunting behind it.

The application asks

“Do you maintain backups that are offline, encrypted, or otherwise separated?”

What it means

Backups ransomware cannot reach and delete with the same credentials it stole.

What we implement

Separated, encrypted backups with restricted access, and verification that they actually restore.

The application asks

“Are backups tested?”

What it means

A green checkmark is not a test. Carriers mean periodic, documented restore tests.

What we implement

Scheduled test restores with results documented, so "yes" has evidence behind it.

The application asks

“Do you have a patch-management process?”

What it means

A cadence you can describe, with critical vulnerabilities handled on a defined timeline.

What we implement

Managed patching on a tested schedule across operating systems and third-party software.

The application asks

“Do you provide security awareness training?”

What it means

Recurring training and, increasingly, phishing simulation, not a one-time onboarding video.

What we implement

Security awareness training and phishing simulations under the Compliance-grade tier.

The application asks

“Do you have an incident response plan?”

What it means

A written plan that names who does what, kept somewhere reachable when systems are down.

What we implement

A real incident response plan, written with you, that exists before the incident.

An honest word on what we are, and aren't

We are not an insurance broker, and nothing here is coverage advice; your broker owns the policy conversation. What we own is the technical truth underneath it. We implement the controls, keep them from drifting between renewals, and hand you evidence, current configurations, test-restore results, deployment coverage, in writing. If a control is not in place yet, we will tell you that too, before you sign a document that says otherwise.

Cyber-insurance FAQ.

Can you fill out the insurance application for us?

We prepare the technical answers and the evidence behind them, in writing, and we will sit with you or your broker while the application is completed. The signature stays yours, and the answers we give you are ones your environment can actually back up.

Will these controls lower our premium?

Often, but that is between your broker and the carrier. What the controls reliably do is keep you insurable, keep a claim payable, and reduce the chance you ever need to file one. Treat premium relief as a bonus, not the goal.

What if we already answered yes to something that isn't true?

Fix the control first, then talk to your broker about correcting the application. Carriers treat a proactive correction very differently from a misrepresentation discovered during a claim investigation. We can close the gap quickly and give you the documentation that shows when it was closed.

We are a small shop. Do carriers really check?

The application is a legal document at every size, and post-incident forensics is precisely when it gets checked. Small businesses are also where the required controls tend to be cheapest to implement, because most of them are configuration, not new licenses.

Which controls should we do first?

Enforced MFA with legacy authentication disabled, then EDR, then separated and tested backups. Those three appear on every application we have seen, and they are the three most often misstated.

Renewal coming up?

Bring the application. In a free 30-minute IT Health Check we will walk the questions against your real environment and tell you, in writing, which answers are defensible today and which ones need work first.