What a cyber insurance questionnaire does not tell you
Part of a retrospective. The retrospective month groups the topic; it is not an earlier publication date. Published 18 September 2026.
Use a cyber insurance questionnaire as a disclosure task with evidence, while keeping policy interpretation, response arrangements and control effectiveness separate.
A yes-or-no question can conceal a complicated environment. Do you use multi-factor authentication? Perhaps employees do, but one supplier account and a separately managed application do not. Are backups tested? Perhaps files were restored, but nobody has demonstrated the whole service.
A cyber insurance questionnaire is a poor place to smooth those distinctions away. It is also a poor substitute for assessing whether controls work. The application response, the policy terms and the organisation's operational security position need separate attention.
Answer the question that was asked
Identify the person authorised to coordinate the response and involve the people who know the controls. The finance or procurement team should not have to infer technical coverage from a project announcement. The IT team should not guess how an insurer intends an ambiguous question to be interpreted.
Ask the broker or insurer for clarification where wording is unclear, and retain the clarification. Use a qualified adviser for disclosure duties and policy interpretation. Do not turn an uncertain answer into yes merely because there is no convenient field for an explanation.
Scope is essential. If a question refers to all systems, check whether the evidence covers cloud applications, supplier access and acquired operations as well as the managed corporate environment. Where it does not, state the limitation through the agreed response process.
The goal is accurate, supportable information. This is not legal or insurance advice, and no general article can determine what a particular policy will cover or how a particular answer should be legally treated.
Distinguish the control from its label
ASD's guidance differentiates phishing-resistant MFA from weaker implementations. If a questionnaire asks about authentication, establish which methods are permitted and what accounts are covered before responding. A product licence or enabled policy is not sufficient evidence about every relevant sign-in path.
Backups need the same discipline. The Essential Eight model includes restoration of data, applications and settings to a common point in time. A successful backup job and a successful service restoration are different claims. Use the evidence that matches the wording, and ask for clarification if the wording combines them.
Consider a hypothetical services company preparing its renewal. The infrastructure manager reports that backups are tested because a file restore succeeded. The application owner explains that the finance service has not been restored with its integrations. Both statements may be accurate within their scope; neither should be silently substituted for the other.
The response coordinator records the distinction, obtains advice on the question and assigns a separate operational task to test the service. The application is not the place to invent an optimistic recovery capability, but it can expose a gap worth addressing.
Testing backups by restoring the service explains what stronger operational evidence would involve.
Read the response arrangements before relying on them
Ask an appropriately qualified adviser to explain the actual policy's incident notification, consent and provider arrangements. Clarify who should be contacted, through which route and what information they need. Put the approved process into the incident runbook without copying confidential policy material into a broadly shared document.
Discuss proposed scenarios rather than relying on the policy name. Ask how the wording addresses the costs and circumstances the organisation is concerned about, and have the adviser identify relevant limits, conditions or exclusions. Record unresolved questions instead of treating a marketing description as an answer.
Insurance does not operate the organisation's response process. Staff still need authority to contain an incident, contact the right advisers and maintain records. If the usual email system is unavailable, the response team needs another way to find the policy contact arrangement.
A preparation exercise can test whether those contacts are usable. It cannot prove that a future claim will be accepted. Keep those conclusions separate in any report to management.
Keep the evidence and the changes together
Retain the submitted questionnaire, its scope, supporting evidence and relevant written clarifications in a controlled location. Record when the information was collected and who confirmed it. A response should be reconstructable without depending on the memory of the person who completed the form.
Ask the adviser what process applies when the organisation's circumstances change. A major acquisition, changed supplier arrangement or material change to control coverage may warrant a review of existing statements and policy obligations. Do not assume either that every change must be reported or that no change matters; establish the requirement from qualified advice.
Operationally, update the risk and exception records as well. The insurance renewal calendar should not be the only reason the organisation notices that an account has no MFA or a backup dependency remains untested.
Keep risk management independent of the renewal
A completed questionnaire is evidence that information was supplied. It does not by itself establish the effectiveness of the controls, and purchasing a policy is not a certification of security. Management still needs an honest view of exposure, recovery and the work left unfunded.
Use the questions to identify missing evidence, but prioritise remediation through the organisation's risk process. An issue that appears on a form is not automatically more important than a material issue that the form never asks about.
A security dashboard that shows the uncomfortable gaps helps maintain that independent view. The useful outcome is a truthful application, professionally reviewed policy arrangements and a separate plan for improving security. None should be presented as a guarantee supplied by the others.
Working on something similar?
If this connects with something you’re working through, I’m happy to talk about where you’re stuck and whether I can help.
See how I work