Renewing a cyber insurance policy used to involve a short form and a quick check. Today, applications often include pages of technical questions, and some insurers request supporting evidence. For long-term care operators, clinics and senior-living communities, the answers affect both price and whether coverage is offered at all.
This post explains the questions you are likely to see, why accuracy matters, and how to prepare so renewal is less stressful.
Insurers have seen how common ransomware and business email compromise claims have become, and they want to know which applicants have basic protections in place. The questions are a proxy for how likely you are to have a loss and how severe it might be. Policies and questions vary by carrier, so treat the list below as typical rather than universal.
Do you require multi-factor authentication for email, remote access and administrator accounts?
Is MFA required for access to backups and cloud management consoles?
Are backups taken regularly and kept offline, immutable or otherwise separated from your network?
Have you tested restoring from backups, and how recently?
Do you have a written incident response and business continuity plan, and have you tested it?
Do you use endpoint detection and response or next-generation antivirus on all workstations and servers?
Do you have a firewall with current support, and is remote desktop exposed to the internet?
How quickly do you apply critical patches?
Do you use any software that has reached end of life?
Do you filter email for malicious links and attachments?
Do you conduct security awareness training and phishing simulations?
Do you verify wire transfers or banking changes by phone?
How many resident or patient records do you hold?
Do you encrypt laptops and portable devices?
Do you require vendors to carry insurance or sign security terms?
Answer honestly. If an application states that MFA is enabled everywhere and it is not, an insurer could dispute a claim later on the basis of misrepresentation. Have the person who actually manages your systems review the answers rather than guessing. If a control is only partly in place, say so and describe the plan to finish it. Your broker can advise how to word partial answers.
Start sixty to ninety days ahead, since fixing gaps takes time.
Gather evidence: MFA settings, backup reports, patch reports, training completion records and your incident response plan.
Fix cheap, high-value gaps first. MFA, backup isolation and removing exposed remote desktop are typical priorities.
Meet with your broker to understand what your policy covers, including breach response costs, business interruption, and any waiting periods or sublimits.
Ask what services come with the policy. Some carriers include incident response hotlines, which you should add to your contact list.
Many policies require prompt notice, use of approved vendors, and consent before paying expenses. Print the claims instructions and keep them with your incident plan, since email may not be available when you need them. Also confirm whether coverage conditions require you to maintain specific safeguards throughout the policy period, not just at signing.
Consider the cost of a control against the cost and likelihood of the loss it prevents. Better controls can improve insurability, and in some cases they may help with premiums, though there are no guarantees. Spread projects across the year and keep a record of each improvement.
Insurance is a way to transfer financial risk, not a replacement for protection. UnityCare IT can help you review an application, verify what is actually in place, and close the gaps that underwriters care about most. If your renewal is approaching, reach out early so there is time to act.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172