Find out which cyber insurance answers your firm can stand behind, which ones need work, and what to fix before renewal.
A renewal may ask whether every account uses multi-factor authentication, whether security alerts are watched, and whether backups have been tested. Those questions often look simpler than they are. “Yes” should mean the protection is in place across the firm and someone can show that it works.
We compare the form with the systems and records you have today. You get a clear view of the answers you can support, the ones that need a closer look, and the work that can still be completed before submission. Your broker remains responsible for policy advice, and the insurer decides the terms.
What we verify before anyone signs. Who is actually protected by MFA. We check staff, administrators, remote access, service accounts, and recovery methods. A high coverage percentage can still hide the one account that gives an attacker control of the firm. Who responds to a device alert. We confirm which devices are covered, who watches the alerts, whether they can isolate a device, and what happens when the alert is real. Whether backup can survive the same attack. We look for separate administration, protected copies, suitable retention, and a recent restore test. The point is to know whether the firm can recover, not simply whether a backup product is installed. How email and payment fraud are handled. We review phishing protection, domain authentication, forwarding rules, impersonation controls, and the step your team uses to confirm a change in banking details. Who can make the call during an incident. We identify who can isolate a device or account, who records the incident, and which technical records will still be available if an event has to be investigated. Whether routine security work is current. We check training, phishing exercises, patching ownership, vulnerability review, and the overdue work most likely to affect the renewal.
What the person signing the form receives. A line-by-line answer record. Each technical answer is tied to the safeguard behind it, the person responsible for it, and the record that supports it. Questions that need a different answer. We flag anything the current environment cannot support, while there is still time to clarify it with the broker or fix the underlying issue. A fix list in deadline order. The list weighs renewal relevance, business risk, effort, and the submission date, so the firm knows what has to move first. A file for next year. You know which reports, screenshots, policies, and test records to keep current so the next renewal starts from evidence rather than memory.
A good fit for firms that are approaching a cyber insurance application or renewal; have a broker asking for clearer answers or technical records; want an independent check before a partner signs the form.
Important limits. We do not sell insurance or interpret the policy. Keep your broker and counsel involved in those decisions. A readiness review cannot guarantee eligibility, price, coverage, or payment of a future claim. If the request came from a client rather than an insurer, the client questionnaire review is the better starting point.