Cyber insurance applications have changed quite a bit. What used to be a relatively straightforward questionnaire about firewalls, antivirus, and a few basic security practices has become a much closer look at how a business actually manages cyber risk. There is a reason for that. Insurers have years of claims experience showing them which conditions tend to make an incident more expensive. They want to understand how likely a loss is, how large it could become, and whether the business has the ability to keep an incident from turning into a much larger financial problem.
For business leaders, this can make the application difficult to navigate. Many of the questions sound technical, so it is easy to send the application to IT or an outside provider and ask them to complete it. The answers come back, someone in leadership approves them, and the application gets submitted. The problem is that this process can put too much emphasis on completing the form and not enough on understanding what the company is actually telling the insurer.
This Is More Than an IT Questionnaire
The answers provided on a cyber insurance application are representations about the business. The insurer may rely on those answers when deciding whether to provide coverage and under what terms. They can influence premiums, deductibles, coverage limits, exclusions, and other policy conditions. They may also become important after an incident when the insurer looks at what actually existed and compares it with what the company represented during underwriting.
That does not mean the CEO, CFO, or business owner needs to personally understand every technical configuration in the company. It does mean that leadership should understand what is being represented and know that the answers have been verified by the people who actually understand the environment.
Multifactor authentication (MFA) is a good example. A business leader may ask whether the company has MFA and receive a yes from IT. The insurer, however, may be asking whether MFA is enforced for email, remote access, administrative accounts, cloud applications, servers, or all users. A company can have MFA in place and still have gaps that make a broad yes answer inaccurate.
The same issue comes up with endpoint security. A company may have purchased endpoint detection and response (EDR) and leadership may reasonably believe that means someone is watching for threats around the clock. That is not always the case. EDR is the technology detecting suspicious activity. Managed Detection and Response adds the people responsible for monitoring and responding to that activity. An alert generated outside normal business hours provides limited value when nobody is responsible for seeing it until the next working day.
Knowing the Answer Is Different From Assuming It
A better way to approach the cyber insurance application is to treat it as a verification process rather than simply a questionnaire. When the company answers yes to an important question, there should be some reasonable evidence supporting that answer.
If the business says employees receive security awareness training, there should be records showing who completed it. If endpoint protection is supposed to cover company devices, someone should be able to produce a report showing which devices are protected. If backups are being performed, the business should understand whether the information can actually be restored when it is needed. If the company says vulnerabilities are addressed within a certain timeframe, reports should support what is being represented.
This does not mean creating an enormous collection of documentation simply for the insurer. The evidence should give the business reasonable confidence that its answers are accurate. When nobody can find evidence supporting an important answer, that is worth investigating before the application is submitted.
Sometimes the Answer Is No
There can be pressure to make every answer on an insurance application look favorable. Nobody wants to discover a problem that might affect the premium or result in additional underwriting questions. That can lead businesses to answer based on what they believe should be happening instead of what is actually happening.
Sometimes the correct answer is no. In other cases, a control exists but does not cover everything included in the question. That should lead to a conversation with the people responsible for the control and, when appropriate, the company's insurance broker. The business may discover that the gap can be corrected before the application is finalized, or that additional information should be provided to explain the answer. Finding a weakness during underwriting is usually much better than discovering it during a claim.
Why Third Wave Is Providing This Guide
Written by the author of Can We Insure This? A Business Leader's Guide to Cyber Risk, AI, Insurance, and Business Survivability the Cyber Insurance Application Guide: What Business Leaders Need to Know Before They Answer the Questions to make this process easier for business owners, executives, and financial leaders.
The guide walks through the areas commonly found on cyber insurance applications and explains what the insurer is trying to understand. It helps business leaders determine who inside the organization should be involved in answering each question and what evidence may be available to support the answer. The intent is not to turn business leaders into cybersecurity experts. It is to give them enough context to understand what their company is representing before the application is submitted.
This fits naturally with the work Third Wave already does. Our Managed Detection and Response, Security Awareness Training and Phishing Simulation, Vulnerability and Penetration Testing, and Cyber Risk Protection services address many of the same areas that appear throughout cyber insurance applications. Our role is not to replace the company's IT team, MSP, insurance broker, finance team, or other people involved in the process. We can help businesses understand whether the controls they depend on are actually operating and provide evidence that supports the answers they are giving.
Buying a security product does not necessarily mean the company is getting the protection leadership believes it purchased. An endpoint security platform may not cover every device. Employees may have access to security awareness training without actually completing it. Vulnerabilities may be identified without being addressed. Security technology may generate alerts without anyone actively monitoring them. The insurance application can bring some of those differences to the surface.
The Application Can Be Useful Beyond Insurance
There is value in cyber insurance beyond simply paying a claim. A serious cyber event can create costs that many businesses would have difficulty absorbing on their own. Depending on the policy and carrier, insurance may also provide access to breach counsel, forensic investigators, incident response specialists, notification providers, and other resources that a business may need quickly during an event.
Insurance still cannot replace the work required to prepare the business for an incident. The company needs to understand its technology, know where its important information resides, protect access to its systems, prepare employees, detect suspicious activity, and be able to recover when something goes wrong. Cyber insurance helps address the financial consequences that remain after the business has taken reasonable steps to manage the risk.
This is why the application can be more useful than it first appears. It gives leadership an opportunity to compare what the company believes is happening with what can actually be demonstrated. If the two do not match, the business has learned something worth knowing before an incident occurs.
Third Wave is providing the Cyber Insurance Application Guide at no cost to businesses, insurance brokers, MSPs, and others who may find it useful. If your cyber insurance renewal is approaching, use it before you start checking the boxes. Understanding the questions and verifying the answers can make the application process more useful to the insurer, but more importantly, it can give you a much clearer picture of how prepared your business really is.
Get the Free Cyber Insurance Application Guide
Get the Free Cyber Insurance Application Guide