Cyber insurance has changed from a simple form to a detailed security questionnaire. Carriers want to know how you protect your systems before they will quote a price, and some will decline applicants who lack basic controls. For a care provider holding sensitive resident information, understanding these questions is useful even before you shop for a policy.
This question-and-answer guide explains what carriers commonly ask, and why.
This is usually the first question and often the most important. Carriers typically ask whether MFA is required for email, remote access, administrator accounts and sometimes backups. A yes should mean enforced for everyone in that category, not available for those who opt in.
How to prepare: Verify with your IT provider exactly where MFA is enforced. Partial answers lead to trouble at claim time.
Underwriters ask how often backups run, whether a copy is kept offline or immutable, and whether restores have been tested. They ask because ransomware attacks aim at backups first.
How to prepare: Document your backup schedule and the date of your last successful test restore.
Basic antivirus is no longer the benchmark. Carriers increasingly ask about endpoint detection and response tools that monitor computers for suspicious behavior, and whether someone watches the alerts around the clock.
How to prepare: Confirm which tool is on every workstation and server, and who responds to alerts, especially overnight.
Expect questions about how quickly critical updates are applied, and whether any unsupported operating systems remain in use.
How to prepare: Keep a list of any end-of-life systems and record compensating controls.
Many applications ask about security awareness training and phishing simulations.
How to prepare: Keep training records showing dates and attendance.
Carriers want to know whether a written plan exists, whether it names contacts and whether it has been practiced.
How to prepare: Write a short plan and run a tabletop exercise. Even a one-hour exercise is meaningful.
Questions often cover spam filtering, protections against spoofed email and whether links and attachments are scanned.
The number of resident or patient records, and the types of data such as payment information, influence your premium and limits. Be accurate and revisit the answer if your census changes.
Applications are signed statements. If a claim is filed and the carrier discovers that a control you claimed was not in place, the insurer may dispute or deny coverage. Do not guess. If you do not know, ask your IT provider and document the answer.
The application is only part of the picture. When comparing policies, read for:
First-party costs such as forensic investigation, data restoration, business interruption and extortion payments
Third-party costs such as legal defense, regulatory proceedings and notification expenses
Breach response services such as access to forensic firms and breach counsel
Sublimits and exclusions, including those for ransomware, social engineering and unencrypted data
Waiting periods before business interruption coverage begins
Requirements to use approved vendors during an incident
A policy can help pay for recovery, but it cannot restore trust or return resident data. Treat the application questions as a free checklist of controls worth having regardless of coverage.
Start working on any gaps several months before renewal rather than during the final week. Collect your documentation in a single folder: MFA settings, backup test results, training logs, the incident response plan and your latest risk analysis.
UnityCare IT can help you complete the technical sections of a cyber insurance application accurately, close gaps that affect your quote and gather the supporting documents so renewal is less stressful.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034