{"id":3369,"date":"2026-09-09T15:08:13","date_gmt":"2026-09-09T20:08:13","guid":{"rendered":"https:\/\/minnovatenetworks.com\/blog\/cyber-insurance-questionnaire\/"},"modified":"2026-09-09T15:43:29","modified_gmt":"2026-09-09T20:43:29","slug":"cyber-insurance-questionnaire","status":"publish","type":"post","link":"https:\/\/minnovatenetworks.com\/blog\/cyber-insurance-questionnaire\/","title":{"rendered":"Your cyber insurance form is a security audit, and you signed it"},"content":{"rendered":"<p>Cyber insurance applications used to be short. Company size, revenue, whether you had been breached before, and a premium came back. That is over. The current generation of questionnaires reads like a controls audit, because that is what it is, and the signature at the bottom is yours.<\/p>\n<p>This matters more than it looks. Every question is a statement of fact about your environment that you are attesting to. If a claim is ever investigated, those answers are the first document anyone reads.<\/p>\n<h2>What they ask, and what they are really asking<\/h2>\n<p>The wording varies by carrier, but the same handful of controls come up again and again. It is worth understanding what sits behind each one.<\/p>\n<h3>&#8220;Do you enforce multi-factor authentication?&#8221;<\/h3>\n<p>The operative word is <em>enforce<\/em>. Not offered, not available, not encouraged. Enforced, so that an account cannot sign in without it.<\/p>\n<p>The follow-up is usually narrower and catches people out: multi-factor on remote access and on email specifically, and often on administrative accounts as a separate question. Most practices have it on some accounts. The exceptions tend to be a shared front-desk login and an administrator account somebody set up years ago, and those are precisely the two the question is aimed at.<\/p>\n<h3>&#8220;Do you use endpoint detection and response?&#8221;<\/h3>\n<p>They are deliberately not asking whether you have antivirus. They know the difference and they are checking whether you do. Answering yes because you have security software installed is the single most common way to get this wrong.<\/p>\n<h3>&#8220;Are backups kept offline or immutable, and are they tested?&#8221;<\/h3>\n<p>Two separate claims joined by an &#8220;and&#8221;, which means both have to be true. Immutable storage means a copy that cannot be altered or deleted within its retention window, because ransomware goes looking for backups before it encrypts anything. Tested means somebody has performed a restore recently and can tell you how long it took.<\/p>\n<p>&#8220;We have backups&#8221; is not a yes to this question. It is a yes to a different, easier question that nobody asked.<\/p>\n<h3>&#8220;Do you have email filtering and user awareness training?&#8221;<\/h3>\n<p>Filtering is usually the easy half. Training is the half that gets an optimistic answer. If the honest position is that you sent an article round once, the honest answer is no.<\/p>\n<h3>&#8220;Are systems patched within a defined window?&#8221;<\/h3>\n<p>The word &#8220;defined&#8221; is doing the work. This is asking whether patching is a process with a schedule and a record, or whether it is something that happens when a machine nags someone enough.<\/p>\n<h3>&#8220;Do you have an incident response plan?&#8221;<\/h3>\n<p>Meaning a written document naming who is called, in what order, with what phone numbers, and what gets done in the first hour. Not an intention to work it out at the time.<\/p>\n<h2>Why a hopeful yes is the worst possible answer<\/h2>\n<p>There is a strong temptation to give the answer that gets the policy issued, particularly when the form is long, the renewal is due, and the person filling it in is not the person who would know.<\/p>\n<p>Consider the sequence that follows. You have an incident. You claim. The carrier investigates, as they will for anything significant, and part of that investigation is establishing what controls were actually in place. If the forensic report shows no endpoint detection on the machine where it started, and your application says you had it, the conversation stops being about your loss and starts being about your representation.<\/p>\n<p>You are then in a coverage dispute, without the payout, at the precise moment the payout was the reason you bought the policy. A &#8220;no&#8221; that priced the policy higher would have been immeasurably cheaper.<\/p>\n<h2>Use the form as a to-do list<\/h2>\n<p>The genuinely useful thing about these questionnaires is that carriers have done the work of identifying which controls actually reduce claims. They are not asking at random. The list is, in effect, a free prioritised security roadmap written by people with financial exposure to being wrong.<\/p>\n<p>So take the form and go through it honestly, marking each answer as yes, no, or &#8220;I do not know&#8221;. The &#8220;I do not know&#8221; answers are the interesting ones. Then close the gaps in the order the form implies, because that order reflects what actually goes wrong.<\/p>\n<h2>Where HIPAA overlaps, and where it does not<\/h2>\n<p>For dental practices there is a second set of obligations running alongside. The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, and it requires a documented risk analysis, reviewed and updated rather than done once and filed.<\/p>\n<p>The good news is that the overlap is substantial. Access control, audit logging, a contingency plan, workforce training: doing these properly satisfies both the regulation and most of the insurance questionnaire at the same time.<\/p>\n<p>The distinction worth holding onto is that HIPAA is not a checklist you can pass. It requires you to assess your own risks and address them reasonably, and to be able to show your reasoning. Nobody can certify you as HIPAA compliant, and any vendor who offers to is selling something that does not exist. What you can have is evidence: decisions recorded, controls implemented, reviews dated.<\/p>\n<p>None of this is legal advice, and your broker and your counsel should see anything you are about to sign. But go into that conversation knowing which of your own answers are true.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyber insurance applications quietly turned into control checklists with your signature underneath. Here is what they ask, what the answers mean, and why a hopeful yes is worse than a no.<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[67,64,65,66],"class_list":["post-3369","post","type-post","status-publish","format-standard","hentry","category-compliance","tag-compliance","tag-cyber-insurance","tag-hipaa","tag-risk"],"_links":{"self":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts\/3369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=3369"}],"version-history":[{"count":1,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts\/3369\/revisions"}],"predecessor-version":[{"id":3374,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts\/3369\/revisions\/3374"}],"wp:attachment":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=3369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=3369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=3369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}