Tolbridge Technologies

Security

The security questions your insurer will ask before your customers do

Cyber cover now renews on a questionnaire that reads like an audit. The questions are worth answering honestly, and worth answering early.

Adeyemi Tolulope OlarewajuFounder & CEO2 min read

Cyber insurance used to renew on a signature. It now renews on a questionnaire, and the questionnaire has teeth. Underwriters have spent several years watching the same handful of controls fail in the same handful of ways, and the questions they ask are a direct record of that.

That makes the renewal pack unexpectedly useful. Whatever you think of insurance, someone has done the work of narrowing thousands of possible security investments down to the few that decide whether an incident is an inconvenience or an existential event.

What they actually ask

Wording varies between insurers, but the substance converges on five things.

  • Multi-factor authentication — is it enforced on email, remote access and administrator accounts, rather than merely available to anyone who chooses to switch it on?
  • Backups — are they isolated from the network they protect, and when did you last actually restore from one?
  • Administrator access — how many people hold it, and would anyone notice if that number changed?
  • Incident response — is there a written plan for the first twenty-four hours, and does anyone outside IT know it exists?
  • Patching — how quickly do known vulnerabilities get fixed on anything facing the internet?

Read them again and notice what they have in common. Not one asks what you have bought. Every one asks whether the thing you bought is switched on, covering everyone, and known to work.

The gap is usually testing, not tooling

Most organisations we speak to can answer these in principle. Backups run. A plan exists. MFA is available. The honest answer sits one layer below that: the backups have never been restored under pressure, the plan lives in one person's inbox, and MFA covers everyone except the three people who found it inconvenient — who are, reliably, the three people with the most access.

This is good news, because the fix is rarely a purchase. It is a Tuesday afternoon, a nominated person, and a written result.

If you fix only one thing before your next renewal, make it a tested restore. An untested backup is a plan, not a control — and you find out which it is at the worst possible moment.

Answering honestly is the cheaper option

There is a temptation to answer the questionnaire aspirationally: to describe the organisation you intend to be by the end of the year. It is an expensive habit. Cover is priced on those answers, and a claim is assessed against whether they held. Anything internet-facing can often be checked from the outside without your involvement at all.

A qualified answer — not yet, here is the date it will be — is a stronger position than an optimistic yes. It also tends to produce a more useful conversation with the underwriter than the alternative.

These questions are much easier to answer when someone asked them before an insurer did.

Where to start

Start with the answers that make you uncomfortable. That discomfort is well-calibrated: it is usually pointing at the control you know is thinner than it sounds.

Write the five questions down. Answer each one with a yes, a no, or a date. Give every no an owner. That single page is worth more than most security tooling, and it takes an afternoon rather than a budget cycle.

Have a Question About This?

If this raised something you are unsure about in your own setup, bring us the actual situation.