A cyber-insurance application can look like a list of yes-or-no questions. The work behind an accurate “yes” is rarely that simple.
Is multifactor authentication enforced for every remote and privileged path, or only for Microsoft 365 users? Are critical systems backed up to a protected location, or does the same administrator control production and backup copies? Has the company tested recovery, or only reviewed successful job notifications?
Insurers use different applications and may ask additional questions based on industry, revenue, data, technology, or requested coverage. The safest preparation is not to memorize one questionnaire. It is to assemble current evidence that shows how each control actually operates.
Begin before the renewal deadline creates pressure. A rushed answer can hide a gap that needs remediation or describe a control more broadly than it is implemented.
Build One Evidence Owner List
Renewal preparation often stalls because no one person owns the complete answer. Identity may sit with an IT provider, endpoint security with another vendor, backups with an application owner, and incident response with leadership or counsel.
Create a working list with four fields:
| Control area | Evidence owner | Evidence date | Known exception | |—|—|—|—| | Identity and MFA | Named employee or provider | Date verified | Accounts or systems not covered | | Privileged access | Named administrator | Date reviewed | Shared or legacy administrative paths | | Endpoints and detection | Security or support owner | Date exported | Unmanaged or unsupported devices | | Backup and recovery | System or vendor owner | Last test date | Systems outside backup scope | | Incident response | Executive coordinator | Last exercise date | Missing contact or decision path |
An answer without an owner and date is an assumption. Renewal evidence should be current enough that the signer understands what is true now, not what was configured two years ago.
Prove Where MFA Is Enforced
Insurers commonly distinguish among email, remote access, cloud services, and privileged accounts. Travelers’ current multifactor authentication guidance, for example, identifies remote access points and privileged accounts as areas organizations should secure with MFA.
Useful evidence includes:
- an export or screenshot of the policy that enforces MFA;
- the users, groups, applications, and sign-in paths in scope;
- a list of excluded, emergency, service, or legacy accounts;
- the authentication methods permitted;
- the date enforcement was tested;
- ownership of exception review.
“MFA is enabled” is not the same as “MFA is enforced.” Enrollment reports can show registered users while leaving a legacy protocol, administrator path, VPN, or vendor portal outside the policy.
Document emergency access accounts separately. They may be designed differently for resilience, but they still need tight monitoring, controlled credentials, and a tested use procedure.
Review Privileged Access as Its Own Control
Administrative access deserves its own evidence because one privileged account can change security settings, create users, disable protection, or interfere with recovery.
Prepare:
- a current list of tenant, domain, server, firewall, backup, and application administrators;
- each account’s named owner and business need;
- whether daily work uses a separate non-admin identity;
- recent removal of former employees and vendors;
- restrictions on standing access;
- alerts or logs for high-risk administrative changes;
- the review and approval record.
The NIST Cybersecurity Framework 2.0 emphasizes defined roles, responsibilities, authority, and accountability. In renewal terms, that means leadership should know who can make high-impact changes and how those rights are reviewed.
Show Endpoint Coverage, Not Just a Product Name
Naming an endpoint-protection product does not establish that every relevant device is protected and reporting correctly.
Collect a device inventory and compare it with the security console. Reconcile:
- active employee laptops and desktops;
- servers and virtual machines;
- contractor or remote devices in scope;
- devices that have stopped checking in;
- operating systems that no longer receive support;
- exclusions or disabled protections;
- alert escalation and response ownership.
The useful renewal statement is not “we have endpoint detection.” It is “these device classes are enrolled, this report shows current coverage, these exceptions remain, and this person handles alerts.”
Treat Backup and Restore Evidence Separately
Backup job success proves that a process ran. It does not prove that every critical system is covered, that backup copies are protected from the same attacker, or that the business can restore them.
Insurer applications may ask about offline, separate-network, immutable, or otherwise ransomware-resistant backups. They may also distinguish recovery testing from backup completion. A Chubb cyber proposal form, for example, asks about protected backup technologies, restricted backup access, and full restore and data-integrity testing.
Prepare:
- the list of systems and data included in backup;
- retention and frequency by system;
- administrative separation and MFA controls;
- isolation or immutability design;
- the latest restore-test record;
- the measured recovery time and recovered data point;
- exceptions for SaaS platforms or vendor-managed applications.
Use VesperTek’s backup and disaster recovery planning guidance to separate backup coverage from business recovery requirements.
Make Incident Response Usable
A policy document is weak evidence if the listed people have never practiced the decisions it describes.
A usable incident-response package includes:
- the person authorized to declare an incident;
- internal technical and executive contacts;
- external IT, security, legal, insurance, and communications contacts;
- evidence-preservation instructions;
- criteria for isolating systems or disabling access;
- a communication path when normal email is unavailable;
- the date and findings of the latest tabletop exercise.
The CISA StopRansomware Guide recommends identifying critical systems and dependencies, establishing stakeholder roles, protecting backups, and planning recovery priorities. Those details help a renewal answer reflect operational capability rather than an untested document.
Map Vendor Responsibilities
Outsourcing a system does not automatically transfer every security responsibility. Ask each provider:
- Which controls do you operate, and which remain with the customer?
- Can you provide current evidence rather than a general service description?
- Who receives alerts and who is authorized to act?
- What happens outside business hours?
- How are administrative accounts protected?
- What recovery service is included, and what must the customer request?
- How quickly will you support evidence gathering after an incident?
Record disagreements before the application is signed. A provider believing that the customer owns recovery while the customer believes it is included is a material operating gap.
Reconcile Exceptions Before Signing
Do not convert a partial control into an unqualified answer. Instead:
- record the exact scope that is working;
- identify the systems or accounts outside that scope;
- determine whether the gap can be remediated before renewal;
- ask the broker or insurer how the question should be interpreted;
- retain the supporting explanation and evidence used for the final response.
This is not legal or insurance advice. The application, representations, and policy language should be reviewed with the company’s broker, insurer, and appropriate counsel.
A Renewal-Ready Evidence Package
The final package should be concise enough for leadership to review. Include the completed owner list, identity and device exports, privileged-access review, backup and restore evidence, incident-response plan, vendor responsibility map, open exceptions, and the date each item was verified.
The objective is not to claim perfect security. It is to give the signer a defensible view of what is implemented, what is not, and who owns the remaining work.
If your renewal is approaching and the answers are spread across vendors and systems, VesperTek can conduct a focused Cybersecurity Readiness Review before the questionnaire becomes a deadline. Contact VesperTek to discuss the evidence and remediation window.