Cyber Insurance Requirements FAQ: 15 Questions Owners Actually Ask
By Jonathan Fykes, CTO · Published · Last updated
TL;DR — what carriers actually do and don't ask, demystified
- You don't need to pass every question on the questionnaire to renew. You need credible answers and a written plan with dates for any gap. Disclosure with a fix date almost always beats an optimistic yes.
- Most SMB carriers do not require a dedicated SIEM or 24/7 SOC. They want logs retained for 12 months and active alerting, which Microsoft 365 plus a managed detection service can deliver for under $20 per user per month.
- "MFA is enabled" and "MFA is enforced" are different answers. Carriers know the difference and now ask about MFA on email, MFA on VPN, and MFA on admin accounts as three separate questions.
- Carriers verify some controls at underwriting (screenshots of Conditional Access, backup vendor name, last tabletop date) and almost everything else at claim time through forensics. Misrepresentation discovered at claim time is the failure mode that ends coverage.
- Your MSP can sign off on M365 controls. They can't sign off on the IR plan, the vendor risk review, or the tabletop. Those are governance work and usually need internal ownership or a fractional CISO arrangement.
You're holding a 2026 renewal questionnaire. It runs 80-plus questions, half of them sound like an IT audit, and your broker keeps using the word "carefully." If you're the owner, the CFO, or the office manager who got this packet on your desk, the goal of this page is simple: take the panic out, give you a sense of control, and walk you through the 15 questions we hear most from people in the same seat.
This is the practical companion to the full 2026 cyber insurance requirements guide. That post is the comprehensive overview of the 12 controls behind the questionnaire. This one goes deeper on the individual questions a non-technical reader actually has when they sit down to fill out the form.
Quick definition before we start, because this stuff comes up in every answer: M365 is shorthand for Microsoft 365, the email and document suite most small businesses run (Outlook, Teams, SharePoint, OneDrive). MFA is multi-factor authentication, the second login step after your password, usually a code from your phone or a tap on an app. EDR is endpoint detection and response, a type of security software that runs on laptops and looks for attacker behavior, not just known viruses. We'll define everything else as we go.
Group 1: Process and timing
1. What if I can't pass every question on the renewal questionnaire?
Disclose the gap, propose a remediation date, and submit anyway. That's the answer almost nobody wants to hear and the answer carriers want most.
Here's the example we see weekly. A 25-person engineering firm gets to question 14: "Is MFA enforced for all administrative accounts?" Their IT contractor says yes, but when they actually check, two service accounts and one shared mailbox don't have MFA on. The honest answer is no. The right move is to write "Enforced on 92 percent of admin accounts today; remaining 8 percent (two service accounts and one shared mailbox) on phishing-resistant MFA by [date 30 days out]." Most carriers will take that. A flat "yes" with no remediation note becomes a misrepresentation problem if a claim happens before the gap closes. The companion worksheet on how to answer the MFA section of a 2026 questionnaire walks through this exact wording problem question by question.
What you should do next: pull the questionnaire, mark every question you can't truthfully answer "yes" on, and start a one-page disclosure document that lists the gap, the planned fix, the owner, and the target date. Hand that to your broker before you submit the questionnaire itself. Brokers have negotiated 60- and 90-day cure periods on far worse situations than yours.
2. Will my premium go up if I admit gaps?
Some gaps move premium and some don't. The four that reliably push premium up or trigger sub-limits are missing or unenforced MFA, no immutable backup, no documented incident response plan with a tabletop date, and unpatched critical vulnerabilities older than 30 days. Those are the ones carriers price hardest on.
Smaller gaps with a fix date attached usually don't move premium meaningfully. "DMARC at p=quarantine, moving to p=reject within 60 days" reads as a credible engineering plan to an underwriter. "MFA not enforced anywhere, no plan to fix" reads as a claim waiting to happen.
Real example. A 40-person law firm renewed in 2025 with three gaps disclosed: no quarterly phishing simulations, vendor risk review more than two years out of date, and DMARC at quarantine instead of reject. Premium went up 6 percent against a market average of 14 percent that year. Same firm, hidden gap on MFA enforcement, would likely have been non-renewed.
What you should do next: ask your broker for the carrier's "credit list" if they have one. A few carriers offer explicit discounts for FIDO2 admin MFA, immutable backup vendors they recognize, and 24/7 monitored detection. Knowing the credit list lets you sequence improvements by financial return.
3. How long before renewal should I start fixing things?
Ninety days is the realistic minimum. Sixty days is rushed. Thirty days is "disclose the gap and submit, you won't get it fixed in time."
The pattern that works: at 90 days out, walk through the 12 controls in the 2026 requirements guide and rate yourself honestly on each. In the first 60 days, fix the worst three or four gaps. The last 30 days are documentation and broker conversations. Anything still open at submission goes on the disclosure with a target date.
The single thing most worth fixing fast is blocking legacy authentication, because it converts an MFA "no" into an MFA "yes" and takes about a week. The cross-network walkthrough lives at M365 security in plain English and the implementation guide is the step-by-step on blocking legacy authentication.
What you should do next: put the renewal date on a calendar, count back 90 days, and put a reminder there to start the assessment. If you're already inside that window, skip to question 1.
4. Can my IT vendor verify the answers for me?
For the M365 controls, yes, and you should ask them to. The right form of that verification is a written attestation listing each control, the specific Microsoft 365 setting that satisfies it, and the date verified. That document doubles as your audit trail if a claim ever happens.
What your IT vendor probably can't sign off on is the governance side: the incident response plan with named roles, the vendor risk review, the security awareness training completion rates, and the tabletop exercise date. Those need internal ownership (someone at the company owns the document and the process) or a fractional CISO arrangement (an outside executive who owns governance under a formal contract).
The split matters because a carrier reading your file wants to see a technical attestation from someone who runs the systems and a governance signoff from someone who owns the policy. Both can be outsourced. They usually shouldn't be the same person.
What you should do next: email your IT vendor and ask for "a written attestation of our M365 security controls against the 2026 cyber insurance baseline, with each setting and verification date listed." If they ask what that looks like, the format in the cyber insurance compliance checklist is the one we hand to clients.
5. Do carriers actually verify what I claim?
Sometimes at underwriting, almost always at claim time. The split is the part most owners don't realize.
At underwriting, some carriers run external scans (looking at your DMARC record, your public domains, sometimes your patch posture) and request screenshots for the most-flagged controls. The three that get screenshot requests most often are Conditional Access policies showing MFA enforcement, the backup vendor's last successful restore date, and the cover page of the IR plan with the tabletop date. Most carriers don't go deeper than that at the SMB tier. The time cost doesn't pencil out for them on a $5,000 premium.
At claim time the picture changes. The carrier hires a forensics firm whose entire job is reconstructing what actually happened, including which controls were and weren't in place. Forensics pulls real configuration evidence: the actual Conditional Access policy state on the day of the incident, sign-in logs showing whether MFA was prompted, the audit log showing whether legacy authentication was disabled. If the forensics report contradicts what you said on the questionnaire, the questionnaire becomes a misrepresentation problem and coverage gets rescinded.
What you should do next: assume every answer will be verified at claim time, even if nobody verifies it at underwriting. Write your answers as if a forensics analyst will read them with the configuration export open next to them. Because eventually one will.
Group 2: Specific control questions
6. What's the difference between "MFA on email" and "MFA on VPN"?
They're separate enforcement points and carriers ask about them as separate questions. MFA on email means a second factor is required when someone signs in to Microsoft 365 (Outlook, Teams, the web portal at office.com). MFA on VPN means the same second factor is required when someone connects the corporate VPN to reach internal systems (file servers, line-of-business applications, on-premises tools).
Why the question matters: an attacker who steals a password can attempt both paths. If MFA is on email but not on VPN, the attacker takes the VPN path. We've seen this exact pattern in claims: MFA enforced perfectly on M365, no MFA on the Cisco AnyConnect VPN, attacker logs in over VPN with credentials from a breached password list, accesses the file server, drops ransomware. The questionnaire said "yes" to MFA. Forensics said "yes for email, no for VPN." That's a denied claim.
If you don't have a VPN at all (your business runs entirely in M365 and SaaS apps), the right answer is "Not applicable: no internal network requiring VPN access. Remote access to M365 is governed by Conditional Access policies enforcing MFA." Many SMBs are in this position and don't realize it's the cleanest possible answer. The deeper version of the MFA story is in the worksheet on how to answer the MFA section of a 2026 questionnaire.
What you should do next: ask your IT contact a specific question. "Do we have a corporate VPN, and if yes, is MFA enforced on it the same way it is on Microsoft 365?" Get the answer in writing.
7. Do I need a SIEM or SOC for my carrier?
For most SMBs, no. The acronyms are intimidating. SIEM stands for security information and event management. It's a centralized log collector with alerting rules. SOC stands for security operations center, meaning people watching the SIEM 24/7. Both are expensive, and most SMB carriers do not require either at the SMB tier.
What carriers actually want at the SMB tier: log retention for 12 months, with active alerting on security events. Microsoft 365 retains audit logs for 90 days on standard plans and 12 months on E5 / Audit add-on. Forwarding those logs to Microsoft Sentinel (Microsoft's cloud SIEM) plus a managed detection and response service runs roughly $10 to $20 per user per month total. That answers the question without buying a SOC.
Above 100 employees or in regulated industries (healthcare, finance, defense supply chain), expect carriers to ask harder questions and sometimes require a managed SOC. Below that threshold, "centralized log retention via Microsoft Sentinel with managed detection from [vendor name]" is the answer that passes.
What you should do next: don't buy a SIEM because the questionnaire mentions it. Ask your broker if your specific carrier has a written requirement, and at what employee count it triggers. Most won't have one for businesses under 100.
8. What counts as a "tested backup" and how often does it need testing?
A tested backup is one where someone actually restored real data from the backup, opened it, verified it worked, and wrote down the date. The wording on most 2026 questionnaires is exact: "tested in the last 12 months" or "tested quarterly." Both are real bars. The recycle bin doesn't count. Version history doesn't count. "We assume it's working because it didn't error" doesn't count.
The standard a carrier expects for M365 data: a separate, immutable backup target (Veeam for Microsoft 365, Barracuda Cloud-to-Cloud, Datto SaaS Protection, or similar), retained for at least 30 days, with a documented restore test inside the last 12 months and ideally inside the last quarter. Immutable means an attacker who compromises your tenant cannot delete or encrypt the backup. That's the word carriers care about.
The restore test itself is not complicated. Pick a sample mailbox, a SharePoint site, and a OneDrive folder. Restore each to a separate location. Open the restored data and verify it's intact. Email the IT lead with the date, what was restored, and a screenshot. File the email in your evidence folder. Total time: under an hour. Frequency: quarterly is the gold standard, annual is the floor.
What you should do next: ask your IT vendor "when was the last time we restored real data from our M365 backup, not just confirmed the backup ran?" If the answer is "never" or "I'm not sure," book a restore test for this month and put the next one on a quarterly recurring calendar invite.
9. What's a "documented incident response plan" and what's the minimum that satisfies a carrier?
A written document that names who does what when something breaks. Not a 200-page binder. A two-pager with the right content beats a 50-page template nobody has read.
The minimum that passes a 2026 carrier:
- An incident commander: the person who runs the response and makes decisions about engaging legal, paying ransom, notifying customers (usually the owner, COO, or president).
- A communications lead: the person who handles messaging to staff, customers, and the press if needed.
- A legal/notification contact: outside counsel familiar with breach notification law in your states.
- An external forensics partner: pre-identified or on retainer; a firm you've talked to before the incident, not one you Google at 11pm on a Saturday.
- Contact information (cell phones, personal emails) for all of the above, on paper, in a place that doesn't depend on M365 still working.
- A tabletop exercise date inside the last 12 months: meaning someone walked the team through a simulated incident and the team practiced.
That's the floor. Most carriers will accept a two-page document with those six elements. Without the tabletop date, the answer fails on most 2026 forms regardless of how thick the binder is.
What you should do next: if you have a plan, check it for the six elements above. If you don't have a plan, write a two-pager this month, schedule a 90-minute tabletop with the named roles, document the date.
10. What's the difference between "phishing simulation" and "security awareness training" — do I need both?
Training is the lesson. Simulation is the test. They're different controls and most 2026 carriers want both.
Security awareness training is a video, an interactive course, or a live session that teaches employees what phishing looks like, how to spot a suspicious link, what to do when a CFO emails late on a Friday with a wire transfer request, and how to report something they're not sure about. KnowBe4, Hoxhunt, Microsoft Attack Simulation Training, and Proofpoint Security Awareness all sell this. Pick one and run it annually with completion tracking for 100 percent of employees.
Phishing simulation is the same vendors sending fake phishing emails to your team and measuring who clicks. Most carriers want quarterly simulations with the click rate tracked. The point isn't catching people. It's identifying repeat clickers and putting them through targeted remedial training. A click rate trending down over the year is what passes the question.
What "completion tracking" actually means on the questionnaire: a report showing the percentage of employees who finished the training, by name. "We sent everyone the training video" is not completion tracking. The vendor produces the report; your job is to make sure 100 percent shows up on it.
What you should do next: if you have neither, KnowBe4 or Microsoft Attack Simulation Training (included in Defender for Office 365 Plan 2) covers both for most SMBs at roughly $3 to $5 per user per month. Schedule the first run before your next renewal, then quarterly after that.
Group 3: Failure scenarios
11. What happens if I have a claim and my carrier finds I lied on the questionnaire?
The carrier rescinds coverage, returns your premium, and refuses to pay the claim. The full claim cost goes to your balance sheet. For a ransomware event at a 30-person business that's typically $200K to $1M between forensics, legal, business interruption, customer notification, and any ransom paid. That's the exposure you're carrying when an answer on the questionnaire isn't accurate.
The legal mechanism is called material misrepresentation. The questionnaire counts as a sworn statement. If the answer was wrong about something material to underwriting (and "did you have MFA enforced" is always material), the carrier can void the policy as if it never existed. Bad-faith litigation against the carrier is rare in these cases because the documentation usually points clearly at the policyholder.
The most common pattern we see: a question gets answered "yes" because the IT contact says "yes," but the IT contact meant "MFA is available" and the questionnaire meant "MFA is enforced." The owner signs the form trusting the answer. Two years later a claim happens, forensics shows MFA wasn't actually enforced on the compromised account, and the policy is gone.
What you should do next: for every question, ask "if a forensics analyst pulled the configuration tomorrow, would they confirm this answer or contradict it?" If you can't answer that with confidence, the answer needs verification before you sign the form.
12. What if my MSP says we're compliant but we're not, who's liable?
You signed the questionnaire, so you carry the contractual exposure to the carrier. The MSP carries professional liability exposure to you, but only conditionally.
Two conditions have to line up for the MSP to actually pay if their attestation was wrong. First, the contract has to say they're responsible for compliance verification. Most MSP contracts don't; they cover "best efforts to maintain security" or similar language that doesn't translate to a hard attestation. Second, the MSP has to carry errors and omissions (E&O) insurance with limits high enough to cover your loss. Many small MSPs carry $1M E&O. Your loss might be larger.
The realistic outcome of an MSP-misattestation claim is a long argument, partial recovery if the contract language is favorable, and a soured business relationship. It's not a substitute for verifying the answers yourself.
What you should do next: when you ask your MSP for the attestation, ask them to put it on letterhead, sign it, and confirm in writing that they carry E&O of at least $1M. If they decline any of those, that tells you something about how comfortable they are standing behind the answers.
13. Can I be denied renewal mid-policy?
Mid-policy denial is rare. The three things that can happen mid-term are different from each other and worth keeping straight.
The carrier can decline to renew at the next anniversary date. That's the normal path: the policy runs out, the carrier sends a non-renewal notice with whatever advance warning your state requires (typically 60 to 90 days), and you shop for replacement coverage. This is the most common version of "I got dropped."
The carrier can non-renew with state-required notice mid-term in some states for specific reasons, usually material change in risk. This is unusual and contested. Most states protect policyholders from mid-term cancellation outside narrow circumstances.
The carrier can void the policy retroactively if it discovers a material misrepresentation on the original application. That's not a denial, it's a rescission, and it's the failure mode covered in question 11. It typically only surfaces when a claim triggers forensics.
What you should do next: don't lose sleep about mid-term cancellation. Worry about not getting renewed (manageable with 90 days of preparation) and about misrepresentation (manageable with honest answers). The mid-policy fear is mostly noise.
Group 4: Practical
14. Is it cheaper to get cyber insurance with a good security stack, or no insurance and good security?
For most small businesses, insurance plus a good security stack is cheaper than self-insuring. The math comes down to one number: how big a check can you write tomorrow without flinching?
A single ransomware event at a 30-person business runs $200K to $1M when you add up forensics ($30K to $100K), outside legal ($20K to $80K), customer notification and credit monitoring ($10K to $200K depending on records exposed), business interruption (variable but commonly $50K to $300K), and any ransom paid (median 2025 ransom for the SMB segment was around $40K, but the long tail goes much higher). Cyber insurance premium for the same business with strong controls is typically $3,000 to $8,000 per year for $1M to $2M of coverage.
Self-insurance only makes sense if you can absorb the worst-case loss without it threatening the business. For a profitable 30-person company with $500K in liquid reserves, a $400K ransomware event is survivable but painful. For the same company with $50K in reserves, it's existential.
The other variable: insurance buys access. The carrier has a forensics firm on speed dial, a breach coach who calls within an hour, a legal team that knows your state's notification law, and a public relations firm if it gets that far. Self-insured businesses assemble that team after the incident, when prices double and quality varies. The retainer relationships matter as much as the dollars.
What you should do next: ask your accountant for the largest unbudgeted check the business could write next month without compromising payroll. If that number is comfortably above $500K, self-insurance is at least worth modeling. Below that, the premium is the cheaper option in almost every scenario.
15. What does "supply-chain security" mean on the questionnaire?
Carriers use "supply-chain security" to mean the security of vendors that have access to your systems or data. The 2025 attacks on managed service providers (MSPs) and SaaS vendors put this on every 2026 questionnaire, but the bar at the SMB tier is still reasonable.
What passes for an SMB:
- An annual vendor review of your top 10 vendors by data sensitivity. Top 10 means by how much of your data they touch, not by how much you spend with them. Your payroll vendor is probably on the list. Your office supply vendor is not.
- SOC 2 Type II reports collected for any vendor processing regulated or sensitive data (PII, PHI, payment cards). The vendor produces the report and you file it. SOC 2 stands for Service Organization Control 2, an independent audit of security controls.
- A documented offboarding process when a vendor relationship ends, covering revoked access, data return or deletion, and a final attestation.
- Admin consent gating for OAuth apps in M365, meaning users can't approve third-party apps to read their mail without an admin reviewing the request first. This closes a specific door (consent phishing) that's been exploited heavily in the last two years.
Software bill of materials (SBOM) and signed third-party attestations are starting to appear on questionnaires for businesses above 100 employees. SMBs aren't seeing those broadly yet. If you operate in regulated industries, expect them sooner.
What you should do next: open a spreadsheet, list your top 10 vendors by data sensitivity, and put a column for "SOC 2 on file (Y/N)" and "last review date." Spend a Friday afternoon emailing the missing SOC 2 reports. That's the documentation a carrier wants to see.
Where to go from here
The questionnaire is winnable. The pattern that works for most owners we talk to: take the 12 controls in the 2026 requirements overview, rate yourself honestly, work the worst three or four gaps, document the rest. Use the compliance checklist as your tracking sheet. When something is a "no," disclose it with a date, don't hide it.
Most premium increases at renewal aren't about the controls. They're about the answers. Strong controls with weak documentation lose to mediocre controls with strong documentation almost every time, because the underwriter has paper to grade and you have evidence to point at.
If you're filling out a questionnaire this quarter and want a sanity check on the answers, run your tenant through the free assessment below. The output is a control-by-control map of what's actually in place versus what the 2026 carriers want to see, in language you can hand directly to your broker.
See where you stand before renewal
Free assessment maps your tenant against the 12 controls every 2026 carrier asks about. Output is a one-page report you can hand to your broker.
Check My Risk