Cyber insurance has become a standard part of risk management for many businesses. But having a policy does not necessarily mean every cyber incident will be covered. 
One area that can create problems is the information provided during the application and renewal process. 
Cyber insurance applications commonly ask businesses about security controls such as multi-factor authentication, backups, employee security training, patch management, and endpoint protection. Insurers use those answers to evaluate risk and determine coverage terms. 
The challenge is that businesses do not always have an accurate picture of what is actually in place. 
An organization may report that MFA is enabled, for example, without realizing that certain accounts or systems are excluded. A company may have reliable backups but no documented history of testing restores. Security awareness training may exist, but completion records may be incomplete. 
Those distinctions can become important when a claim is reviewed. 
Cyber insurance applications can be surprisingly specific. 
A question may not simply ask whether your organization uses MFA. It may ask whether MFA is required for email, remote access, administrative accounts, or other systems. 
The same applies to backups. An application may distinguish between having backups, protecting backups from unauthorized access, and regularly testing whether those backups can be restored. 
This is why technical questions should be verified rather than answered based on assumptions or previous configurations. 
Your environment also changes over time. New employees, applications, devices, locations, vendors, and remote access methods can all affect whether an answer that was accurate last year remains accurate today. 
Confirm exactly where MFA is required and whether there are accounts, applications, or access methods that are exceptions. 
Pay particular attention to email, remote access, administrative accounts, and any other systems specifically identified on the application. 
Verify what systems and data are backed up, how frequently backups occur, where they are stored, and whether recovery is tested. 
If your application states that backups or restores are tested regularly, maintain records of those tests. 
Confirm that required training is actually being completed and documented. 
Training records should identify who completed the training and when. If phishing simulations or other ongoing training are part of your security program, those records should also be maintained. 
Make sure the patching process described on the application reflects how systems are actually managed. 
This includes identifying devices that may have fallen outside normal management processes and understanding how operating systems and applications are kept current. 
Confirm that endpoint security tools are installed, active, and appropriately managed across applicable devices. 
New computers and other changes to the environment can create gaps if deployment is not regularly reviewed. 
It is useful to be able to demonstrate how a security control is configured rather than simply state that it exists. 
Depending on the control, documentation may include configuration reports, backup logs, restore-test results, training records, device inventories, patching reports, or endpoint-security reports. 
Good documentation serves more than an insurance purpose. It also gives the business a clearer understanding of its own security posture. 
If there is uncertainty about a technical question on an insurance application, the IT team or provider responsible for the environment should verify the answer. Questions about policy language, coverage, or how an insurer wants a particular question interpreted should be addressed with the insurance broker or carrier. 
One common mistake during renewal is relying too heavily on the previous year’s answers. 
A business can change significantly in twelve months. It may add employees, introduce new software, replace infrastructure, expand remote access, or change how data is stored. 
The renewal process is a good opportunity to compare the application against the current environment rather than simply confirming what was reported previously. 
A technical review should include the security controls addressed by the application as well as any significant technology changes that occurred during the policy period. 
For organizations using vCIO & IT Strategy services, this type of review can become part of the broader technology planning process rather than a separate exercise each year. 
No security review can guarantee that a future claim will be covered. Coverage depends on the policy, the circumstances of the incident, and applicable law. 
What a business can control is the accuracy of the information it provides. 
Before submitting or renewing a cyber insurance application, verify the technical answers, document the controls that are in place, and correct information that is no longer accurate. 
The objective is straightforward: the security environment described on the application should accurately reflect the security environment the business is operating. 
InfiNet Solutions helps organizations understand and document their technology environments, identify security gaps, and verify the technical controls that may appear on cyber insurance applications. 
If your cyber insurance renewal is approaching, we can help you review the technology side before you submit it. 
Claims can be denied for many reasons depending on the policy and circumstances. One potential issue is a material difference between information provided during the application process and the controls that were actually in place. The effect of any discrepancy depends on the policy language, facts of the incident, and applicable law. 
Confirm which users, accounts, applications, and access methods require MFA. Pay particular attention to email, remote access, and privileged or administrative accounts, as these are commonly addressed on cyber insurance applications. 
If your insurance application asks whether backups or recovery procedures are tested, verify that your practices support the answer you provide. Regardless of insurance requirements, restore testing is an important part of determining whether backups can actually be used during an incident. 
Documentation may include MFA configuration, backup and restore records, security awareness training records, device inventories, patching reports, and endpoint-security reports. The appropriate documentation depends on the controls your organization uses and the questions on your application. 
Your IT provider can help verify technical information about your environment. Questions involving coverage, policy interpretation, or insurance requirements should be discussed with your broker or carrier. 
Review it at every renewal and after significant changes to your technology environment. Rather than assuming last year’s answers are still correct, verify them against the systems and controls currently in place.

Talk to our Team