Cyber insurance application check

Before you sign the application, make sure every answer holds up.

Your cyber insurance application becomes part of the policy. We combined the questions from five carrier forms into 31, grouped into 7 areas. Mark each one Have it, Partial or Missing, see where your answers would not hold up after a claim, and keep an answer sheet with the proof for each.

Application checkSAMPLE
58%
Application readiness
Gaps
MFA on backupsMissing
Payment call-backsMissing
Tested restorePartial
EDR on every deviceHave it
31 questions · 7 areas

We use this to send your results and the tracker. No newsletter sign-up. Privacy policy

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
What you are signing

Your application becomes part of the policy

31
questions combined from five carrier application forms, with the overlap removed
Void
from the start, as the parties agreed in Travelers v. International Control Services (2022) after the MFA answer did not hold up
Denied
coverage for the first fraudulent wire in Interstate Removal v. National Specialty (2024): no documented call-back procedure
$2M
New York regulator penalty against Healthplex (2025), which included compliance certifications that did not match reality

Most cyber applications make your answers part of the contract. One we reviewed says the application "shall form the basis of the contract" and "shall be deemed attached to and form a part of the Policy." Another has an executive officer sign that the statements are true "after reasonable inquiry." If a claim comes in, the application is the first thing the insurer checks.

The questions are much the same from carrier to carrier: MFA on email, remote access, admin accounts and backups; endpoint detection and response on every device; offline backups and a tested restore; patching; email security; training and phishing tests; call-back verification before money moves; and penetration testing. This check covers all of them in 7 areas: access control, email security, endpoints and updates, data protection, backup and recovery, people and payments, and testing.

How the check works: Have it means it is in place everywhere the question covers and you could show the proof today. Partial means some systems, some people or no proof. Missing or blank scores zero, and N/A is left out. Loss history questions are not scored; answer those with your broker.

Your answers stay in your browser. If you ask for the answer sheet, it arrives as an Excel file with every question, your status, the proof to keep and the sources. The same questions appear in the cyber supplement to many E&O and professional liability renewals. This is a readiness tool, not legal advice.

FAQ

Cyber insurance application questions, answered

Most ask about the same controls: multi-factor authentication on email, remote access, admin accounts and backups; endpoint detection and response on every device; offline or immutable backups and a tested restore; patching; email filtering and DMARC; staff training and phishing tests; call-back verification before money moves; and penetration testing. This check combines five carrier forms into 31 questions with no overlap, grouped into 7 areas.

Applications usually make your answers part of the contract. One we reviewed says the application "shall form the basis of the contract" and "shall be deemed attached to and form a part of the Policy." In Travelers v. International Control Services (2022), the application said MFA was in use, it was only on the firewall, and after a ransomware attack the parties agreed the policy was void from the start. Ask your broker or advisor how your policy treats a misstatement.

When it is knowing and meant to deceive, yes. Applications carry state fraud notices. The Florida notice reads: "Any person who knowingly and with intent to injure, defraud, or deceive any insurer files a statement of claim or an application containing any false, incomplete, or misleading information is guilty of a felony of the third degree." An honest mistake is different, but it can still cost you the coverage.

Have it means the control is in place everywhere the question covers and you could show proof today: a screenshot, a report or a dated policy. Partial means some systems, some people, or no proof. Missing means not in place, and a blank counts as Missing. Mark N/A only when a question does not apply to you, for example the Microsoft 365 question if you do not use it.

Yes. Many professional liability renewals, including those for accounting firms, add a cyber supplement that asks the same questions. Use the same answers on both so they match. CPA or tax firm? Also run the WISP proof check, which adds the PTIN and state rules.

Your answers stay in your browser unless you ask for the answer sheet. If you do, we keep your answers with your request so we can send it, and we never share them. Loss history questions are not part of this check; answer those with your broker.

Ground truth. Not story.

Insurers and regulators ask for proof, not policies. We test the controls in your actual systems and show what holds up.

Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.