A few years ago, cyber insurance applications were short forms. Today, many carriers send detailed questionnaires, request evidence and sometimes run outside scans of your internet-facing systems before offering a quote. For healthcare and senior living organizations, which hold sensitive data and have drawn attention from ransomware groups, underwriters can be particularly careful.
Understanding what they ask, and answering accurately, can affect your premiums, your coverage and whether a claim is paid. This article walks through common themes. Requirements vary by carrier, so use this as preparation and not as a guarantee.
The application is part of your insurance contract. If you say you have multi-factor authentication on all remote access and a claim investigation reveals otherwise, the insurer may dispute coverage. Treat the form as a formal statement. Involve your IT provider, your administrator and whoever signs the application, and confirm answers with evidence rather than memory.
Expect questions about the following areas.
Is MFA required for email access, especially remote or webmail?
For remote network access such as VPN or remote desktop?
For privileged and administrator accounts?
For cloud applications and backups?
This is often the most important topic. A no answer here can lead to higher premiums or a declination.
Are backups performed regularly, and how often?
Are copies stored offline or immutable, separate from the main network?
Are backups encrypted?
When did you last test a restore?
Do you use endpoint detection and response on servers and workstations?
Is someone monitoring alerts around the clock?
Are logs retained?
How quickly do you apply critical updates?
Do you run vulnerability scans?
Are any systems running unsupported software?
Do you filter email for malware and phishing?
Do you use SPF, DKIM and DMARC?
Do you use web filtering?
Are firewalls in place and configured to restrict inbound traffic?
Is remote desktop exposed to the internet?
Is the network segmented?
Do employees receive security awareness training, and how often?
Do you run phishing simulations?
Do you have a written incident response plan, and have you tested it?
Do you have a vendor management process?
Do you verify payment change requests by a second channel?
How many records containing personal or health information do you hold?
Do you encrypt laptops and portable devices?
Have you completed a HIPAA security risk analysis?
Have you had prior incidents or claims?
Start early. Begin gathering information at least 60 to 90 days before renewal, since improvements take time.
Collect evidence. Screenshots of MFA settings, backup reports, training records and policy documents can support your answers.
Fix gaps before applying. If MFA is missing on remote access, implementing it before you submit changes the outcome.
Be honest about weaknesses. Describe a compensating control or a remediation plan with dates instead of overstating.
Keep a master set of answers. Reusing consistent, verified responses saves time at each renewal.
Beyond the application, read what you are buying:
What is covered, such as forensics, legal costs, notification, business interruption, ransom negotiation and regulatory defense?
What are the limits and deductibles?
Are there sublimits for ransomware or social engineering fraud?
Are there conditions or exclusions tied to security controls?
How and when must you report an incident, and are you required to use the carrier's approved vendors?
Insurance transfers some financial risk, but it does not restore resident trust, repair operations or prevent an incident. The controls underwriters ask about are also practical protections. Treating the questionnaire as a checklist for improvement benefits you whether or not it changes your premium.
UnityCare IT can help you review application questions, gather accurate evidence and close common gaps before renewal, so your answers match what is really in place.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034