Guide · 10 minute read
Answering the cyber insurance questionnaire honestly
Field testedWhat the questions actually mean, which controls insurers now require, and how to turn a no into a yes before renewal.
By Nate Weigel, Protection Director · August 2026
Three companies, three accounting systems, nineteen years of records. The plan that worked was the one written for the client, not for a vendor.
The three-company merger Gold Star survey"Service is excellent, quick to respond and quick to complete. Thank you!"
Cheri, small businessMore from the survey wallWhy the questionnaire matters more than it used to
Insurers have paid out on ransomware for years and have started asking specific technical questions before they will renew. A wrong answer can raise the premium; a false one can void a claim. The questionnaire has quietly become a security audit, and the business owner is signing it.
The questions that decide the premium
- Multi-factor authentication on email, remote access and administrator accounts. Insurers now treat this as non-negotiable.
- Endpoint detection and response on every computer, not just antivirus.
- Backups that are offline or immutable, tested, and separated from the network they protect.
- Patching within a defined window, with evidence.
- Security awareness training for staff, with records.
- An incident response plan, written down, with names in it.
- Email filtering and protection against spoofed domains.
- Privileged access: who has administrator rights and why.
How to turn a no into a yes
Most no answers are two to four weeks of work each, and several overlap. Multi-factor everywhere is days. Endpoint detection is a rollout. Tested backups are a project with a date. The mistake is treating the questionnaire as paperwork due Friday instead of a list of work due before renewal season. Start ninety days out and every answer can be yes, with evidence you can attach.
What to keep on file
For every yes, the proof: a screenshot of the multi-factor policy, the endpoint console, the last restore test log, the training completion report. Insurers increasingly ask for it at claim time, when it is far too late to produce.
Proof it works
The stories where we did this, and what the clients said afterwards.
Every laptop managed, every login checked, without anyone noticing
Construction · Mobile devicesTablets in the field, plans in hand, and nothing lost when one goes in the mud

A backup that has never been restored is a hope, not a plan. Ask for the date of the last tested restore.
What to actually test TechnologyMulti-factor on email but not on the remote gateway is a locked front door with the back door open. Do all of them.
Multi-factor everywhereQuestions this guide gets asked
Our agent says our current answers are fine. Should we worry?
Ask whether the agent has seen the evidence. The insurer will, at claim time.
Can Midwest IT fill in the questionnaire for us?
We fill it in with you and tell you honestly which answers are already yes and which need work, then we do the work.
Do these controls apply to a ten-person business?
Yes. Attackers do not check headcount, and neither do insurers.

"Ryan is great. Fixed my issue quickly and explained it thoroughly."
Kelly, insurance agencyMeet Ryan- A technician who knows your setup takes every request. Not a dispatcher, not a queue.
- Every closed ticket is surveyed and a partner reads every response.
- 99.5% of surveys come back positive.
- Family-owned since 2005. 21 years in the same corner of Wisconsin, not going anywhere.
"Service is excellent, quick to respond and quick to complete. Thank you!"
Cheri, small businessTalk to a partner, not a sales script.
Tell us what is going on. A partner will call you back the same business day, look at what you have, and tell you honestly whether we are the right fit. No pricing pressure, no pitch deck.
