Cyber Insurance Requirements for Small Businesses: Can You Answer the IT Questions on Your Application?
- Shay

- 4 days ago
- 13 min read

Cyber insurance applications can look straightforward until you get to the questions about the technology your business uses. That's usually where I start hearing from clients.
They may have worked through the insurance questions without a problem, but then they get to MFA, encryption, endpoint protection, backups, remote access or another security control and aren't quite sure how to answer it. One question I hear regularly is,
“Is our data encrypted at rest and in transit? I don't really know what that means when it comes to what we do.”
That's a reasonable question. A business owner, office manager or whoever has been handed the cyber insurance questionnaire shouldn't necessarily know how every security control in the company's IT environment is configured. The problem is that the questionnaire may only give you a Yes or No box when there can be quite a bit sitting behind that answer.
Before I tell a client how I would answer one of those technical questions, I want to understand what the insurer is asking and look at how the business actually operates. That can be very different from one company to another.
What IT Questions Are Cyber Insurance Companies Asking Small Businesses?
There isn't one standard cyber insurance questionnaire that every company receives. The questions depend on the insurer, the policy and the business, but there are some areas that come up regularly.
A business may be asked about:
Multi-factor authentication
Administrative or privileged accounts
Endpoint protection
Encryption
Backups and recovery
Email security
Remote access
Security updates and patching
Security awareness training
Incident response
Devices and systems the business uses
Social engineering and financial fraud controls
Some of those questions are fairly easy to answer. Others require a little more digging. A business owner may know employees use MFA but not know whether it is enforced for every account the insurer is asking about. They may know the company has backups without knowing exactly what is being backed up, how those backups are protected or when someone last verified that the data could be restored.
That doesn't mean the business has been doing something wrong. It means the person completing the insurance application may not be the same person who manages the technology behind the answers.
What Does “Data Encrypted at Rest and in Transit” Actually Mean?
This is one of the questions clients ask me about most often when they receive a cyber insurance application.
In plain language, data at rest is information while it is being stored somewhere. That could be information on an employee's computer or iPad, files in Microsoft 365, data on a server or NAS, information in a cloud application or data stored within a backup.
Data in transit is information while it is moving from one place to another. An employee connecting to Microsoft 365, data moving between systems, a backup being sent to cloud storage or someone remotely connecting to company resources are all examples.
The definitions aren't usually the difficult part. The harder question is figuring out what they mean for the way a particular business actually works.
A company may have employees working from computers in an office while field crews use iPads that move from jobsite to jobsite throughout the day. Those employees may be accessing email, documents, job information or company applications over cellular connections or Wi-Fi at different locations. Back at the office, the company may have a server, Microsoft 365, a NAS, cloud applications and backups that all store or move company information in different ways.
When an insurance application asks whether the company's data is encrypted at rest and in transit, all of that can matter. I may need to look at how computers and mobile devices are protected, where company information is stored, how employees connect to company resources and how backups and other systems are configured.
The insurance company may give you one checkbox. There can be several different systems, devices and ways of working behind that answer.
That's why I don't want to answer a question like this based on an assumption that a particular product or service must be taking care of it. I want to look at the environment and determine what we can actually verify.
Having a Security Product Doesn't Always Answer the Question
Encryption is a good example, but the same issue comes up with other questions on the application.
If a client tells me, “Yes, we have MFA,” I may still need to determine where it is being enforced. The answer for Microsoft 365 may be different from the answer for remote access or another application the company uses. If the business has backups, I want to understand what is being backed up, where those backups are stored, how they're protected and whether we know the data can actually be restored.
The same applies to endpoint protection. Knowing the business pays for a security product doesn't necessarily tell us whether all of the devices that should be protected are covered and reporting properly.
Incident response can be less straightforward than it sounds too. A business may know who it would call if something happened, but that isn't necessarily the same as having a current, documented plan that identifies who is responsible for what, who needs to be contacted and what should happen during an incident.
If a business doesn't have that documentation in place, SNL-Tech Services also offers Incident Response Planning & Guide development. The purpose is to give the business something it can actually reference during an incident rather than trying to make those decisions for the first time while an incident is already happening. It also provides something concrete to reference when a cyber insurance questionnaire asks whether the business has an incident-response plan.
What About Wire Fraud and Fraudulent Email Requests?
Cyber insurance questionnaires may also ask about procedures for wire transfers, ACH payments, changes to vendor banking information or other financial transactions. This is an area I pay particular attention to for businesses that regularly move money or have employees who receive payment instructions by email.
If an employee receives an email that appears to come from a vendor saying that banking information has changed, I don't want that email to be enough to authorize the change. I also don't want the employee calling a phone number included in the email to verify it. If the email is fraudulent, the contact information in it could be fraudulent too.
The first step should be to independently contact the vendor using a known, previously verified method. That might be a phone number already maintained in the company's records or another established way the two businesses normally communicate. The verification should happen outside of the email conversation that triggered the request.
For clients that regularly handle these types of transactions, have experienced attempted fraud or may be more likely to be targeted, I sometimes recommend adding another layer to that process: establishing a verification code word or passphrase with important vendors or business partners.
That passphrase should be established when the relationship is set up, either in person or through a known and verified method, and it should never be created or exchanged through email. If a sensitive request comes through later, the employee can contact the vendor using the known verified method and ask for the previously established passphrase as an additional way of confirming the request.
The passphrase isn't intended to replace other controls. Depending on the business and the transaction, there may also be procedures requiring a second person to approve a banking change or large payment. What I like about the passphrase is that it gives employees handling those requests another verification method that wasn't created inside the same email system an attacker may have compromised.
This is a good example of why a Cyber Insurance Readiness Assessment can involve more than checking security settings. If the insurance questionnaire asks how the business protects against fraudulent payment instructions or social engineering, I need to understand what actually happens when one of those requests reaches an employee.
Who Should Answer the IT Questions on a Cyber Insurance Application?
This is an area where responsibilities can get mixed together.
Your insurance professional understands the insurance side of the application. Questions about coverage, policy language, insurance terminology or how a particular insurer wants a question interpreted should be discussed with them.
The technical questions are where your IT provider can be useful. If a client asks me whether the company's computers are encrypted, where MFA is being enforced, what endpoint protection is installed, how the backups are configured or how employees remotely access company resources, I can review the environment and answer those questions based on what I can verify.
I don't think an owner, manager or assistant should have to guess at a technical answer simply because they happen to be the person completing the application. The business is ultimately responsible for the information it submits, but SNL-Tech Services can complete the technical questions based on the environment I review and provide documentation to support the answers as part of a Cyber Insurance Readiness Assessment.
That gives the business and its insurance professional something much more useful to work with than, “I think our IT company set that up.”
What If You Don't Know the Answer to One of the Cyber Insurance Questions?
Not knowing the answer doesn't automatically mean the security control isn't there. It may already be configured and simply needs to be verified, the business may own the technology but not be using a particular capability, or we may find a legitimate gap that needs to be addressed.
Once we know what is actually in place, the business can make an informed decision about what happens next. If there is a technical gap, we can determine what would be involved in addressing it. If there is a question about what the insurer requires, that can go back to the insurance professional with much better information.
I would rather have that conversation before the application or renewal is submitted than discover afterward that everyone was working from an assumption.
Why SNL-Tech Services Offers a Cyber Insurance Readiness Assessment
The questions clients bring me from their cyber insurance applications are one of the reasons SNL-Tech Services offers a Cyber Insurance Readiness Assessment.
This isn't meant to be a generic cybersecurity checklist that looks exactly the same for every company. The assessment is based on the business, the way its employees actually work and the technical questions being asked on its cyber insurance questionnaire.
A company where everyone works from company computers in one office can look very different from a business with field crews carrying iPads from jobsite to jobsite, employees working remotely, a local server, Microsoft 365, cloud applications and several different ways of accessing company information. I need to understand that before I can answer the technical questions accurately.
As part of the Cyber Insurance Readiness Assessment, I review the technical portion of the company's questionnaire against its actual IT environment. Depending on the questions being asked, that may include reviewing:
MFA and authentication
Administrative and privileged accounts
Endpoint protection
Device and data encryption
Encryption at rest and in transit
Backups and recovery
Email security
Remote access
Devices and systems in use
Microsoft 365 security controls
Incident-response planning and documentation
Financial fraud or social-engineering procedures when they are part of the questionnaire
Other technical controls specifically asked about by the insurer
From there, I can provide the technical answers that I can substantiate and documentation to support what was verified during the assessment.
If something isn't configured the way the business thought it was, we know that before submitting the questionnaire. We can identify the gap, determine what needs to happen and give the business accurate information to discuss with its insurance professional.
If the assessment identifies an area that needs more attention, that doesn't necessarily mean it belongs inside the Cyber Insurance Readiness Assessment itself. Depending on what we find, a business may benefit from a more focused service, such as an IT Baseline Assessment, Microsoft 365 Audit or Incident Response Planning & Guide.
Your Cyber Insurance Assessment Can Also Become Next Year's Reference
There is another reason I think documenting the assessment matters. Cyber insurance isn't something a business deals with once and never sees again. The next renewal will come around, and both the questions and the company's technology may have changed during the year.
Maybe employees were added, the company changed its backup solution or a new cloud application was introduced. Field crews may have received new devices, Microsoft 365 policies may have changed or the insurer itself may ask different questions at renewal.
I don't want a client starting from scratch every year trying to remember how we answered a question or what was configured at the time.
The Cyber Insurance Readiness Assessment gives the business a dated reference showing what was reviewed and what could be verified at that point in time. When the next renewal arrives, we have something to go back to and can look at what has changed rather than trying to reconstruct the environment from memory.
That doesn't mean last year's answers should simply be copied onto this year's application. The documentation gives us a baseline to compare against.
What If You Want to Review More Than the Cyber Insurance Questionnaire?
The Cyber Insurance Readiness Assessment is driven by the business's cyber insurance questionnaire. I need to understand enough about the company and its technology to verify the technical controls being asked about, but it isn't intended to be a complete assessment of the company's entire IT infrastructure.
Sometimes going through the cyber insurance process raises bigger questions. Maybe nobody has a current overview of the network. The company has changed IT providers several times and isn't sure what was inherited from each one. There may be servers, network equipment, cloud services, computers, mobile devices and backups that have been added over the years without anyone stepping back and looking at the entire environment.
The business may simply want to know what it has, how everything fits together and whether the technology still makes sense for the way the company operates today.
In that situation, an SNL-Tech Services IT Baseline Assessment may be a useful addition or a better next step. The IT Baseline Assessment looks beyond the questions on an insurance application and takes a broader look at the company's IT environment and how the business actually uses its technology.
The distinction is fairly simple:
A Cyber Insurance Readiness Assessment asks: Can we accurately answer and document the technical questions our cyber insurer is asking?
An IT Baseline Assessment asks: Do we understand our overall IT environment, how it is configured and how it supports the way our business operates today?
For some businesses, the Cyber Insurance Readiness Assessment may be all they need. For others, it may uncover a reason to look more closely at Microsoft 365, the network, devices, backups or another part of the environment.
Can Better IT Security Lower Your Cyber Insurance Premium?
Possibly, but I would be careful about anyone promising that implementing a particular security product or changing one setting will automatically lower your cyber insurance premium.
Insurance pricing, eligibility and coverage are determined by the insurer and depend on many factors beyond the company's IT environment. What SNL-Tech Services can do is help a business understand its technical security posture, identify gaps and document the controls that can actually be verified.
That gives the business and its insurance professional better information to work with when applying for or renewing coverage, and having current technical documentation can also make the next renewal easier because we aren't starting from scratch.
Before You Check the Box, Know What's Behind the Answer
You don't need to become a cybersecurity expert to apply for cyber insurance. I don't expect a business owner to understand encryption methods, authentication policies, endpoint security or backup configurations just to run their business.
But when an insurance company asks whether those protections are in place, somebody should be able to answer the technical questions based on what is actually happening within the business.
If your cyber insurance questionnaire is sitting in front of you and you're finding questions you can't confidently answer, don't guess at them. That may be exactly the right time to have someone look at the technology and business processes behind those questions.
That's what the SNL-Tech Services Cyber Insurance Readiness Assessment is designed to do.
Frequently Asked Questions About Cyber Insurance and IT
What does encryption at rest and in transit mean on a cyber insurance application?
Encryption at rest refers to protecting information while it is stored, such as data on computers, mobile devices, servers, backups or cloud services. Encryption in transit protects information while it is moving between devices, systems or services. Determining whether a business has both in place may require reviewing several parts of its environment rather than checking one setting.
Does cyber insurance require MFA?
Many cyber insurance applications ask about MFA, but the exact requirements depend on the insurer, policy and business. The application may also ask where MFA is enforced, such as email, remote access or administrative accounts. The technical configuration can be verified by the IT provider, while questions about what a particular insurer requires should be discussed with the business's insurance professional.
Do cyber insurance companies ask about wire fraud and social engineering?
They can. Depending on the insurer and coverage, a business may be asked about how it handles funds transfers, changes to banking information, independent verification, dual approvals and employee training. Businesses should also ask their insurance professional what coverage they actually have for social engineering, fraudulent payment instructions and funds-transfer fraud because coverage and limits can vary.
Can SNL-Tech Services answer the technical questions on our cyber insurance questionnaire?
As part of the Cyber Insurance Readiness Assessment, SNL-Tech Services can review the technical questions against the company's actual IT environment, provide answers based on what can be verified and provide supporting documentation for those findings. The business and its insurance professional remain responsible for the insurance application itself and questions involving policy language, coverage or insurer interpretation.
What if our business doesn't have an Incident Response Plan?
If the questionnaire asks about incident response and the business doesn't have a documented plan, that may be an area worth addressing rather than simply deciding how to answer the question. SNL-Tech Services offers Incident Response Planning & Guide development for businesses that need help documenting who is responsible, who should be contacted and how the business should respond when an incident occurs.
What happens if we don't have one of the security controls our insurer asks about?
First, verify whether the control is actually missing and make sure the question is understood correctly. If there is a gap, SNL-Tech Services can identify the technical issue and what would be involved in addressing it. The business should discuss any effect on eligibility, coverage or the application with its insurance professional.
Should we do a Cyber Insurance Readiness Assessment every year?
An assessment can be particularly useful before an application or renewal because technology and insurance questionnaires can change. Keeping documentation from the previous assessment also provides a reference for the next renewal so the business can see what has changed rather than starting from scratch.
What's the difference between a Cyber Insurance Readiness Assessment and an IT Baseline Assessment?
The Cyber Insurance Readiness Assessment is focused on the company's cyber insurance questionnaire and verifying and documenting the technical controls needed to support its answers.
The IT Baseline Assessment is broader. It looks at the company's overall IT environment, how its technology is configured and how it is being used. A business may choose one or both depending on what it is trying to understand.
Can a Cyber Insurance Readiness Assessment guarantee that we'll qualify for coverage or get a lower premium?
No. Insurance eligibility, coverage and pricing are determined by the insurer. The assessment is intended to help the business understand and document its technical environment so it and its insurance professional have accurate information to work with.
Sources and Further Reading
This article provides general information about cybersecurity and the technical and operational controls that may appear on cyber insurance applications. Cyber insurance applications, underwriting requirements, coverage and policy terms vary by insurer and business. SNL-Tech Services does not provide insurance or legal advice. Questions about coverage, policy language or how an insurer wants a question interpreted should be discussed with your insurance professional.




Comments