The questionnaire got longer. The questions got harder. Somewhere on the form is a control you either have or you do not. And the premium — or the renewal itself — turns on that answer. A cyber-insurance application is now a security exam with a price attached.
Twenty-seven percent of small businesses carry no cyber coverage at all. The ones that do now earn their premium with controls, not paperwork (Guardz, Dec 2025). This is prep, not fear. Walk in knowing what they will ask and where you stand.
Performance Connectivity is a managed IT and technology advisory firm in Purchase, NY. We help Westchester and Fairfield County businesses pass cyber-insurance underwriting. A modern renewal turns on four controls: enforced MFA, EDR on every device, tested backups, and a written incident-response plan. This page breaks down the ten questions insurers ask, so you know where you stand before you sign.
Underwriters have settled on the same short list. Get these four right and most of the form answers itself. Get one wrong and you will feel it in the premium, or in a denied claim later.
For each item you get three things. The question the way the application asks it. What a real “yes” takes. And the gap most firms find when they look honestly. Tell us where to send it, and it opens right here on this page.
Read each one against your own setup. Where you cannot answer honestly, that is not a failure. It is your list of things to fix before renewal, in the order an underwriter cares about.
“Do you enforce multi-factor authentication on email, remote access, and every admin account?”
What a real yes requires: MFA enforced by policy. Not optional. Not “most people use it.” On email, VPN and remote access, and every admin account, including the ones nobody signs into daily.
The gap most firms find: A service account, a shared mailbox, or an old remote-access path with MFA quietly turned off. One gap is all an underwriter, or an attacker, needs.
“Do you run endpoint detection and response (EDR) on every workstation and server?”
What a real yes requires: A managed EDR tool that someone watches. It spots behavior, not just known viruses, and can cut a hacked machine off the network.
The gap most firms find: Built-in antivirus counted as EDR. Or EDR on laptops but never on the server it most needs to guard. Coverage on “most” devices reads as “no” to an underwriter.
“Are backups encrypted and kept offline or locked, and have you test-restored one in the last 12 months?”
What a real yes requires: At least one copy an attacker cannot reach or lock. Plus a written restore you have actually run, with a recovery time you can say out loud.
The gap most firms find: Backups that run green every night but have never been restored. Or backups that live in the same cloud account ransomware would also lock. “It is backing up” is not the question.
“Do you keep a written incident-response plan, and have you reviewed or practiced it in the past year?”
What a real yes requires: A written plan that names who does what in the first hour. Who to call. How to notify. Who decides. Reviewed or walked through in the last twelve months.
The gap most firms find: No plan, or a template downloaded and never opened. Only 34% have one built with a professional. And it is the control that most changes the outcome when something happens.
“Do you filter email, and do staff do security training or phishing tests?”
What a real yes requires: Strong filtering in front of the inbox. Plus training you can prove, with dates, completion, and phishing-test results. Not a one-time video from years ago.
The gap most firms find: Filtering left at the mail provider’s defaults. And “training” that means an email nobody read. Email fraud is the claim insurers see most, so they price this line hard.
“Do you apply critical patches on a set schedule, and do you know what is out of support?”
What a real yes requires: A managed process that patches critical holes on a set schedule. And one that flags dead, unsupported systems before they become the way in.
The gap most firms find: An unsupported server everyone forgot about. Or workstations that update whenever the user gets around to it. “When we can” is not a schedule an underwriter accepts.
“Do you limit local admin rights and keep admin accounts separate from everyday ones?”
What a real yes requires: Standard users who cannot install software at will. And admin logins used only for admin work, never the same login someone reads email with all day.
The gap most firms find: Everyone running as a local admin “because it is easier.” It is easier for ransomware too. It inherits whatever the logged-in user can do.
“Is your data encrypted at rest and in transit, including on laptops and phones?”
What a real yes requires: Disk encryption on every laptop that leaves the office. Encryption in transit for anything sensitive. And a way to prove a lost device was encrypted.
The gap most firms find: Encryption available but never turned on across the fleet. Under the NY SHIELD Act, a lost encrypted laptop is a non-event. An unencrypted one can be a reportable breach.
“Is RDP turned off or kept behind a VPN with MFA, and do you scan what faces the internet?”
What a real yes requires: No RDP open to the public internet. Remote access behind a VPN with MFA. And someone who actually checks what your firewall exposes.
The gap most firms find: An open RDP port left over from a setup years ago that nobody remembers opening. It is one of the most common ways ransomware gets in. Insurers scan for it before they quote.
“How many sensitive records do you hold, and how do outside vendors reach your systems and data?”
What a real yes requires: A real count of the private records you hold: client, financial, health. And a list of which vendors touch your systems, and with what access.
The gap most firms find: No one has ever counted, so the total is a guess. And that guess drives your coverage limit. The same inventory is what NYDFS Part 500, SEC Reg S-P, and a SOC 2 review each ask for, from a different angle.
These controls are not only an insurance form. NYDFS Part 500’s final rules are in effect, and the first annual certification is already past its April 2026 due date. The SEC’s Reg S-P changes reached smaller firms in June 2026. The NY SHIELD Act covers any business that holds New York residents’ private data. And enterprise clients keep asking for SOC 2. The cyber-insurance application is simply the one place all of it gets asked at once, with a number attached.
Fifteen minutes with a partner, not a pitch from a rep. Bring the application, or just the questions that made you pause. We will tell you which lines move the premium, which put the coverage at risk, and which can wait.
A copy of your details is on its way to Tim — he reads these himself and replies the same business day. 5.0 average across 15 Google reviews · Same three partners since 1997.
Modern applications focus on a short list of controls. Enforced multi-factor login. Endpoint detection and response (EDR). Tested, restorable backups. A written incident-response plan. Email filtering with staff training. Patching. Limited admin rights. Encryption. And controlled remote access. Underwriters settled on these because they predict claims. Get them right and most of the form answers itself.
Insurers now price on controls, not paperwork. The questionnaire got longer and the questions got harder. Carriers are underwriting the real security behind each answer. A gap on one required control shows up as a higher premium or a declined renewal. Think MFA that is not enforced everywhere, or backups that have never been test-restored.
Yes, and that is the real risk. When you bind or renew, you attest to specific controls. If a claim check shows the attestation was not true, the carrier can deny coverage at the moment you need it most. Maybe MFA was off on an account, or a backup was never restorable. That is why every "yes" should be backed by something you could show them.
EDR, or endpoint detection and response, watches for attacker behavior and can cut off a hacked machine. The antivirus bundled with a laptop cannot do that. Underwriters ask for EDR on every workstation and server, not most of them. Built-in antivirus counted as EDR is one of the most common gaps firms find.
We review your setup against the exact controls the application asks for. We show you which answers are a real yes and which are a gap. Then we fix what is worth fixing before you submit. Bring the application, or just the questions that made you pause. Fifteen minutes with a partner is usually enough to know where you stand.