Before you sign the application, make sure every answer holds up.
Your cyber insurance application becomes part of the policy. We combined the questions from five carrier forms into 31, grouped into 7 areas. Mark each one Have it, Partial or Missing, see where your answers would not hold up after a claim, and keep an answer sheet with the proof for each.
Your application becomes part of the policy
Most cyber applications make your answers part of the contract. One we reviewed says the application "shall form the basis of the contract" and "shall be deemed attached to and form a part of the Policy." Another has an executive officer sign that the statements are true "after reasonable inquiry." If a claim comes in, the application is the first thing the insurer checks.
The questions are much the same from carrier to carrier: MFA on email, remote access, admin accounts and backups; endpoint detection and response on every device; offline backups and a tested restore; patching; email security; training and phishing tests; call-back verification before money moves; and penetration testing. This check covers all of them in 7 areas: access control, email security, endpoints and updates, data protection, backup and recovery, people and payments, and testing.
How the check works: Have it means it is in place everywhere the question covers and you could show the proof today. Partial means some systems, some people or no proof. Missing or blank scores zero, and N/A is left out. Loss history questions are not scored; answer those with your broker.
Your answers stay in your browser. If you ask for the answer sheet, it arrives as an Excel file with every question, your status, the proof to keep and the sources. The same questions appear in the cyber supplement to many E&O and professional liability renewals. This is a readiness tool, not legal advice.
Cyber insurance application questions, answered
Insurers and regulators ask for proof, not policies. We test the controls in your actual systems and show what holds up.
Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.
.png)