Bay Geeks logoTampa Bay IT Support · Since 2004
Bay Geeks Guide · Compliance Business Readiness

Cyber Insurance Questionnaire: What They Ask, and How to Answer

Cyber insurance applications used to be two pages. Now they're a security audit with a premium attached, and the answers matter twice: once when the carrier prices the policy, and again when you file a claim and they check whether your yes was true.

Every year the form gets longer and the questions get more specific. That's not the carrier being difficult. It's the carrier having paid out on enough ransomware claims to know exactly which missing control caused each one. Read the questionnaire that way and it turns into something useful: a list of what actually gets small businesses breached, ranked by how much it costs.

The Short Version

Three answers move the premium more than everything else combined: multi-factor authentication on email and remote access, endpoint detection and response on every computer, and backups that are offline or immutable and have actually been restored from. Get those three right and the rest is paperwork. Answer any of them wrong on purpose and the policy may not pay when you need it.

Why the Answers Matter More Than the Premium

An application is a set of warranties. Carriers have rescinded policies after a claim when the MFA answer turned out to be false, leaving the business with the loss and the legal bill on top. The form is not a sales conversation. Treat every yes as something you would be comfortable proving with a screenshot from the console.

The Questions, Decoded

What they askWhat they meanThe honest yes
Is MFA enforced on all email accounts?Every mailbox, including the owner's, with no exceptionsA passkey or authenticator app on every Microsoft 365 or Google account, and old sign-in methods blocked.
Is MFA required for remote access?Every path into your network from outsideNo Remote Desktop open to the internet; VPN and remote tools all require MFA.
Is MFA required for privileged accounts?Admin logins are the crown jewelsSeparate admin accounts, ideally with hardware keys, never used for email.
Is EDR deployed on all endpoints?Behavior-based detection with rollback, not just antivirusBay Geeks EDR on every machine, on every plan. See MDR vs. Antivirus for the distinction carriers draw.
Do you have 24/7 monitoring, MDR or a SOC?Someone watching the alerts at 2 a.m.Bay Geeks SOC on the Advanced plan.
Are backups offline or immutable, and tested?Can ransomware reach them, and have you ever restored?Versioned cloud backup with an immutable copy, and a restore test in the last six months, written down.
How quickly are critical patches applied?Days, not monthsAutomated, tested patching with reports, which every plan includes.
Email filtering and DMARC?Phishing and spoofing defensesAdvanced filtering plus a DMARC policy at quarantine or reject.
Security awareness training?Staff trained at least yearly, ideally with phishing testsA short, repeated program with dates you can show.
Are local admin rights removed?Users can't install whatever they wantStandard user accounts; the system lockdown on every plan does this.
Any end-of-life software in use?Windows 10, old servers, unsupported line-of-business appsAn inventory, and a plan for each.
Is there a written incident response plan?Who calls whom, in what order, at 2 a.m.One page is enough. Our ransomware checklist is the skeleton.
Are laptops and mobile devices encrypted?A lost laptop isn't a breachBitLocker or FileVault on every laptop; MDM on phones.
Funds-transfer verification procedures?Could an email move your money?A written callback rule.
Any incidents in the last three to five years?Disclose, including the ones you cleaned up quietlyYes, with a sentence on what changed afterward.

What Moves the Premium

Carriers score MFA, EDR and backups first, then monitoring, then everything else. Some now decline outright without EDR, or without MFA on email. Turning on those controls a month before renewal is the single most productive thing you can do for the quote, and it usually costs less than the premium difference it produces.

Mapping the Form to a Maintenance Plan

Control the form asks aboutAutomated
$75/mo
Premium
$125/mo
Advanced
$150/mo
EDR on every endpointYesYesYes
Automated patching with reportsYesYesYes
Versioned cloud backupYesYesYes
Local admin lockdownYesYesYes
Passkey supportYesYesYes
Help desk and remote support YesYes
Mobile Device Management YesYes
24x7 SOC / MDR monitoring  Yes
Identity threat detection (ITDR)  Yes
Dark-web credential monitoring  Yes
90-day log retention  Yes
Cybersecurity event warranty  $100K*

Email filtering and DMARC come through our email services, and the evidence for all of it is what One-Click Compliance reporting produces.

Before You Sign

Quick Self-Check

QuestionIf “no” or “not sure”...
Could you produce a screenshot today proving MFA on every mailbox?Worth a call
Has anyone restored a file from backup in the last six months and written it down?Do this month
Is there a written callback rule for payment changes?Write it this week
Any Windows 10 machines still on the network?Deadline October 2026
FIXED ✓

Get to Yes Before the Renewal

The Advanced plan answers the monitoring, identity and logging questions in one line, and comes with a $100K cybersecurity event warranty that sits alongside your policy, not instead of it.

*Warranty terms & conditions apply. Ask us for details.

Frequently Asked Questions

Is the $100K warranty the same as cyber insurance?

No. It's a vendor warranty on the security stack that covers specific costs after a covered event, and it complements a policy rather than replacing one. Keep your insurance. Terms and conditions apply; ask us for the details.

What if I have to answer no to something?

Answer no. It may raise the premium or add an exclusion, but a false yes risks the whole policy being voided after a claim. Fix the control and update the carrier, or wait for renewal.

How much does cyber insurance cost for a small business?

It varies by revenue, industry and data volume, and the controls above are the lever you actually hold. Two businesses of the same size can see very different quotes based on MFA, EDR and backups alone.

Do I still need cyber insurance if I have a SOC?

Yes. A SOC lowers the odds of an incident and the damage from one. Insurance pays for the forensics, legal work and notification costs that follow. Carriers price the SOC in; they don't treat it as a substitute.

Who fills out the technical questions?

Bring the form to us. We answer from the consoles, attach the evidence, and tell you plainly which questions would be a no today and what it takes to change them.

Insurance & Compliance Hub

Where cyber insurance, HIPAA, PCI DSS and GLBA overlap, and which page covers which.

Ransomware Checklist

The proactive steps that keep your business off the list of victims.

One-Click Compliance

What HIPAA, PCI DSS and NIST reporting should actually look like.

MDR vs. Antivirus

What managed detection and response catches that antivirus can't.

WISP for Accounting Firms

The FTC Safeguards Rule, explained for firms that just found out it applies to them.

📞 727-579-4335  ·  ✉️ support@baygeeks.com  ·  Privacy Policy  ·  Terms of Service

Call Now Schedule