Skip to main content
A municipal finance officer working through a multi-page cyber insurance renewal questionnaire at an office desk, with several questions circled and a laptop beside the form showing a security control checklist
Compliance / Risk

The Cyber Insurance Renewal Questionnaire, Line by Line

Nine question blocks, what the underwriter is actually asking behind each one, what evidence supports a yes, and what to write when the honest answer is no.

By William Bradshaw | July 30, 2026 | 11 min read

The renewal questionnaire is the highest-stakes document in a small organization's insurance year, and it is usually the one nobody owns. It arrives as a PDF from the broker, lands with a fiscal officer or an office administrator who does not run the network, and is due in a week. The questions look like a checklist. They are not. Each one is a coverage condition, and the answers become part of the contract.

That is the part worth slowing down for. An inaccurate yes does not simply inflate a premium. It creates a defect the carrier can point at during the one event the policy exists to cover. An accurate no, paired with a date and an owner, is a weaker-looking answer that holds up far better.

This walkthrough takes the standard question blocks in the order they usually appear. For each, it explains what the underwriter is really asking, what evidence supports a yes, and what to do when the honest answer is no. If you have not yet seen which controls carriers now treat as mandatory, start with our guide to Ohio cyber insurance requirements for 2026, which maps each control to ORC 9.64 and the NIST Cybersecurity Framework 2.0. This article is the next step: the form itself.

Before You Answer Anything: the Application Is Part of the Contract

Cyber policies are underwritten on the representations in the application. If a control you attested to was not actually in place when a loss occurred, the carrier has grounds to reduce the payout, deny the claim outright, or in serious cases rescind the policy and return the premium. This is not a hypothetical risk in a market where ransomware losses are concentrated in exactly the controls the questionnaire asks about.

Three practical rules follow from that. First, whoever signs should not be the only person who answers: the questions are technical, and the signature carries the representation. Get the person who administers the systems to answer the technical blocks in writing, then keep that correspondence. Second, answer as of today, not as of the plan. "We are deploying it next month" is a no with a note, not a yes. Third, when a question is ambiguous, ask the broker to get the carrier's definition in writing rather than interpreting it yourself.

One more framing point. Most of these questions have a partial-credit answer that the form does not offer. The form gives you a checkbox; reality gives you "on four of five systems." Where that is the case, check the box that is literally true and use the remarks field. Underwriters read remarks. Adjusters read them too, and a documented partial deployment is very different from an overstated one.

Block 1: Multi-Factor Authentication

What it usually asks: whether MFA is enforced on email, on remote access such as VPN and remote desktop, on privileged and administrator accounts, and on cloud administration consoles. Some carriers break these into four separate questions, some into one. Assume the four-part version is what they mean.

What the underwriter is really asking: can a single stolen password produce a loss? This is the question that decides whether many carriers will quote at all. It is no longer a rating factor at the margin; it functions as a threshold. Partial deployment is the trap. MFA on Microsoft 365 but not on the VPN, or on staff accounts but not on the administrator account nobody logs into daily, is commonly read as a no once the follow-up questions arrive.

What supports a yes: a per-system report showing enforcement and coverage, not a policy statement saying MFA is required. For Microsoft 365, a conditional access or security defaults report showing enrolled and enforced user counts. For remote access, the configuration showing the second factor is required rather than optional. Note any exclusions explicitly, including service accounts and break-glass accounts, and say how those are otherwise protected.

If the honest answer is no: this is the highest-return gap on the entire form and often the fastest to close. Enforcing MFA on email and remote access is typically days of work, not months, and it is usually included in licensing you already hold. If renewal is imminent, close email and remote access first, then answer accurately about the rest with dates. Carriers respond very differently to "no, closing by September 15" than to silence.

Block 2: Backup and Recovery

What it usually asks: backup frequency, whether a copy is held offline, immutable, or air-gapped, whether backups are segmented from the production domain, and when a restore was last tested.

What the underwriter is really asking: if an attacker gets domain administrator, do your backups survive, and can you actually come back without paying? Modern ransomware targets the backup system first and uses the same credentials that manage it. That is why the segmentation question matters more than the frequency question. A nightly backup reachable with domain credentials is a nightly backup the attacker also encrypts.

What supports a yes: a restore test record with a date, what was restored, how long it took, and who observed it. That single artifact answers the question better than any product name. Add the retention schedule and a note on how the offline or immutable copy is isolated, specifically whether the credentials that access it are separate from production domain credentials.

If the honest answer is no: the most common gap here is not the absence of backups but the absence of a tested restore. Run one, document it, and you have converted an unverifiable claim into evidence in an afternoon. Our guide to backup and disaster recovery for Ohio public entities covers what to test and how often, including the recovery-time expectations a board should be told about before an incident rather than during one.

Block 3: Endpoint Detection and Response

What it usually asks: whether you run endpoint detection and response, on what percentage of endpoints and servers, and whether alerts are monitored around the clock by someone.

What the underwriter is really asking: two separate things that the form often merges. First, is the tooling capable of detecting behavior rather than matching known signatures. Second, and this is the one organizations miss, is anyone watching it at two in the morning on a Sunday. An EDR console nobody reads is a detection capability with no response attached, and carriers have learned to ask the follow-up.

What supports a yes: a coverage count from the console, agents deployed against total known assets, which requires a current asset inventory to be meaningful. If a managed provider monitors the alerts, name them and state the response commitment. If nobody monitors overnight, say so.

If the honest answer is no: distinguish the two halves. Deploying EDR broadly is procurement plus a rollout. Getting alerts monitored is a service decision, and for a small organization it is almost always outsourced rather than staffed. Answer each half accurately; a yes on tooling with an explicit no on overnight monitoring is a normal and quotable posture, whereas a blanket yes that unravels during a claim is not.

Block 4: Patching and Vulnerability Management

What it usually asks: how quickly critical patches are applied, whether you scan for vulnerabilities and how often, and whether any end-of-life or unsupported operating systems remain in the environment.

What the underwriter is really asking: how long a publicly known exploitable weakness stays open on your network. The end-of-life sub-question is the one that quietly reprices policies, because an unsupported operating system is a permanent exposure by definition rather than a patch cycle behind. Carriers ask about it specifically now, and answering no when a forgotten server is still running is a material misstatement.

What supports a yes: a scan summary with a date, a count of findings by severity, and a remediation trend across at least two scans. Two scans showing critical findings going down is a stronger answer than one scan showing few findings, because it evidences a process rather than a moment. Pair it with the asset inventory that proves the scan covered everything, since a clean scan of half the network is not a clean scan.

If the honest answer is no: scanning is the cheapest gap to close on this form. A single authenticated scan produces both the answer and the remediation list. Our vulnerability scanning guide covers what to scan and how to read the output. If end-of-life systems remain, disclose them with a documented migration date; a dated plan is a defensible position, an undisclosed EOL server is not.

Block 5: Email Security and User Training

What it usually asks: whether you filter inbound email for malicious content, whether sender authentication is configured, how often staff receive security awareness training, and whether you run phishing simulations. Where funds transfer coverage is in scope, expect a separate question about out-of-band verification of payment instruction changes.

What the underwriter is really asking: how a loss most commonly starts here. For public entities the two dominant patterns are credential phishing leading to ransomware, and business email compromise leading to a fraudulent payment. The training questions address the first. The payment verification question addresses the second, and it is often the single most valuable control on the entire form for a township or district that moves money to vendors.

What supports a yes: training completion rates by percentage of staff with a date, not a statement that training is available. For sender authentication, the published DNS records. For payment verification, a written procedure requiring a callback to a previously known telephone number before any banking detail change, plus evidence it is actually followed.

If the honest answer is no: the payment verification procedure costs nothing but a written rule and a staff briefing, and it stops the loss type that hits small public bodies hardest. Write it this week regardless of the renewal date. For the training half, our article on running phishing simulations covers how to establish a baseline you can report next year.

Block 6: Privileged Access and Remote Access

What it usually asks: whether administrators use separate accounts for administrative work, whether ordinary users hold local administrator rights, whether remote desktop is exposed to the internet, and how the network is segmented.

What the underwriter is really asking: how far an intruder gets from one compromised workstation. Internet-exposed remote desktop is close to a decline on its own with many carriers, because it is a recurring root cause in claims data. The local administrator question is about blast radius: if daily-use accounts carry administrative rights, one careless click becomes an environment-wide event.

What supports a yes: a list of privileged accounts with their owners and last review date, showing administrative accounts are distinct from daily-use accounts. For remote access, evidence that it terminates on a gateway requiring the second factor rather than being published directly. For segmentation, a current network diagram showing where the boundaries actually sit.

If the honest answer is no: take exposed remote desktop off the internet before you submit the form, not after. It is the change with the largest single effect on both your risk and your quote. Separating administrative accounts is a half-day of directory work. Removing local administrator rights takes longer because it surfaces applications that depend on it, so scope it as a project with a date rather than claiming it prematurely.

Block 7: Incident Response

What it usually asks: whether you maintain a written incident response plan, when it was last tested or exercised, and whether you know how to reach the carrier's incident hotline.

What the underwriter is really asking: in the first hour, will your organization make the situation cheaper or more expensive? Carriers care about this for a concrete reason. Most policies require notification through their hotline and the use of their approved vendors, and organizations that engage their own forensics firm first sometimes find that spend is not covered. The plan question is partly about competence and partly about whether you will follow the claims process.

What supports a yes: the plan itself, with a revision date, plus a record of the last exercise even if that exercise was an hour around a table. The plan must name who has authority to declare an incident, who contacts the carrier, and where the contact list is stored offline, because a contact list that lives only on the encrypted file server is not a contact list.

If the honest answer is no: this is achievable within a renewal window. A short plan that genuinely reflects your organization beats a long template that does not. Our guide to building an incident response plan for Ohio public entities gives the structure, and running one tabletop exercise converts a written plan into a tested one for the purposes of this question.

Block 8: Data Inventory and Prior Incidents

What it usually asks: what categories of sensitive data you hold and roughly how many records, your annual revenue or budget, and whether you have experienced a claim, incident, or extortion demand in the past several years.

What the underwriter is really asking: what a breach would cost, since notification obligations scale with record counts and data types. Public entities routinely underestimate here. A township holds employee payroll and benefits records, utility billing details, permit applications, police or EMS records where applicable, and vendor banking information. The prior-incident question is a disclosure obligation and the one where non-disclosure most reliably voids a claim.

What supports a yes: a data inventory naming each significant system, what category of data it holds, an approximate record count, and who owns it. This is the artifact most small organizations lack, and it takes an afternoon of walking the systems rather than any tooling.

If the honest answer is no: estimate transparently and label the estimate. "Approximately 4,000 employee and utility billing records across three systems, estimated from system record counts on this date" is a defensible answer. A confident precise number you cannot substantiate is not. On prior incidents, disclose anything arguably reportable and let the carrier decide relevance; that decision is not yours to make on the form.

Block 9: Third Parties and Vendor Dependencies

What it usually asks: which providers hold or process your data, whether an IT provider has administrative access to your environment, and whether critical vendors carry their own cyber coverage.

What the underwriter is really asking: whether a compromise at somebody else's company becomes your claim. For a small organization with an outsourced IT provider, that provider's administrative access is one of the largest concentrations of risk in the environment, and carriers now ask about it directly.

What supports a yes: a vendor list naming each provider, what access or data they hold, and the contract or insurance certificate on file. Where a provider holds administrative access, note whether that access uses named accounts with MFA rather than a shared credential.

If the honest answer is no: request certificates of insurance from your critical providers. Most will supply one within days, and the request itself often surfaces which relationships lack a written agreement. That is useful information regardless of what the questionnaire does with it.

How to Write a No That Helps You

A bare no invites the underwriter to assume the worst. A no with structure does the opposite, and it costs three sentences. Name the current state precisely, name the compensating control that reduces the exposure today, and name the remediation with an owner and a date.

For example, rather than answering no to overnight EDR monitoring, write: alerts are reviewed each business morning by the IT administrator; endpoints are isolated automatically on high-severity detections; a managed monitoring service is scoped for the fourth quarter with the fiscal officer as owner. That answer describes a smaller risk than the checkbox does, and it is verifiable.

This is also where the compliance program pays for itself twice. If you are running an ORC 9.64 program, your remediation dates already exist in that plan, so the questionnaire becomes a reporting exercise rather than a scramble. Our guide to maintaining ORC 9.64 after July 1 describes the recurring cycle that keeps those dates current between renewals.

The Evidence Packet: Assemble Once, Reuse Annually

Nearly every question above is answered by one of nine artifacts. Build the folder once, refresh it on a calendar reminder ninety days before renewal, and the questionnaire stops being a research project. Each item should carry a date and a named owner.

1. MFA coverage report

Per system: email, remote access, privileged accounts, cloud consoles. Enrolled and enforced counts, with exclusions named.

2. Restore test record

Date, what was restored, elapsed time, who observed it. The single most persuasive artifact in the packet.

3. Endpoint coverage count

Agents deployed against total known assets, plus who monitors alerts and during which hours.

4. Vulnerability scan summary

Findings by severity across at least two scans, so the trend is visible rather than a single snapshot.

5. Asset inventory

Every server, workstation, and network device, with operating system versions and any end-of-life systems flagged.

6. Training completion record

Percentage of staff completed, date of the last cycle, and phishing simulation results if you run them.

7. Incident response plan

Revision date, last exercise date, and the offline contact list including the carrier hotline.

8. Data inventory

Systems, data categories, approximate record counts, and the owner of each system.

9. Vendor and access register

Providers, what data or access each holds, whether that access uses named accounts with MFA, and insurance certificates on file. This is the artifact most often missing entirely, and the one that takes the longest to gather because it depends on other people responding.

A Ninety-Day Renewal Runway

Days 90 to 60: gather and find the gaps. Assemble the nine artifacts. Do not remediate yet. The goal is an accurate picture, and the gaps you discover here are the agenda for the next thirty days. Most organizations find between two and four genuine gaps, and at least one they did not know about.

Days 60 to 30: close what closes quickly. Prioritize by underwriting weight rather than by effort: MFA coverage first, internet-exposed remote desktop second, a restore test third, a written payment verification procedure fourth. Each of these is achievable inside thirty days and each moves a threshold question from no to yes.

Days 30 to 0: answer, document, and let the broker work. Complete the form with the evidence attached and the remaining gaps written up in the structured-no format. Give the broker enough runway to take the risk to more than one market, which is difficult in the final week and is where accurate answers translate into actual pricing.

If the renewal is already inside thirty days, invert the order: close MFA on email and remote access, take remote desktop off the internet, and write the structured-no notes for everything else. Those three moves address the questions most likely to affect whether you are quoted at all.

A Note on Scope

This article describes the security controls behind common questionnaire language and how to evidence them. It is not insurance advice, and it does not interpret any specific policy. Questionnaire wording, definitions, and consequences vary by carrier and by form. Confirm what a given question means, and what an answer commits you to, with your broker and your own legal counsel before you sign. Where a control is genuinely absent, disclose it; the guidance here is about answering accurately, never about presenting a gap as closed.

Need the Evidence Before Your Renewal Date?

Bullium works with Ohio townships, fire and EMS districts, and small organizations to produce exactly the artifacts this form asks for: an asset inventory, a scan with a remediation trend, an MFA coverage report, and a tested restore. We walk your questionnaire block by block, identify which answers your current environment actually supports, and scope the gaps you choose to close. No commitment to engage further.