Your cyber insurance application is a security audit. Would you pass it today?

Sixty-four checks across the eight areas underwriters ask about on current applications, including the new questions about AI. Check what is true today, not what is planned. Your section scores update as you go.

Rather work on paper? Download the Blank PDF (PDF, 13 pages).

Why the application got harder

It is priced on your controls

Insurers paid out heavily for ransomware and business email compromise. The application is how they decide whether to offer cover, at what price, and with what exclusions, and it now asks about specific controls rather than general intentions.

The answers become part of the policy

What you attest to on the application is what the insurer relies on. An answer that turns out to be wrong after an incident can put the claim in dispute. An accurate no with a dated plan is safer than a hopeful yes.

The same questions keep coming up

Multifactor authentication on email, remote access, and administrator accounts. Endpoint detection and response. Backups kept offline or immutable and actually tested. Patching on a schedule. A tested incident response plan. Verification before money moves.

AI is the newest section

Underwriters have started asking which AI tools are in use and what checks sit around them, and deepfake voice and video are now part of payment fraud. This assessment includes those questions so they do not arrive as a surprise at renewal.

What the applications ask now

These are drawn from current carrier applications and attestation forms and from federal guidance. None of them is new, but underwriters now ask for each one by name.

MFA

on email, on all remote access, and on administrator access to directory services, backups, network devices, and servers, for employees and third parties alike.

Carrier MFA attestation forms
Offline

or immutable backups, segmented from the network, with full restores tested and a ransomware scenario in the restore plan.

Carrier applications and proposal forms
EDR

on endpoints, set to isolate or block activity, with alerts fed to a monitored platform or security operations center.

Carrier proposal forms
Deepfakes

of executives on voice and video calls are now used to request transfers. Federal guidance is to verify by calling back a number you already have.

FinCEN Alert FIN-2024-Alert004; FBI IC3

How to use this assessment

Quick and practical. About ten minutes if the inventory exists, longer if it does not, which is itself a finding.

1

Answer for today

Check an item only if it is in place now and covers everyone it should. Planned, partial, or unknown stays unchecked.

2

Mind the word all

Most application questions say all users, all remote access, all administrators. One exception is usually the gap an attacker uses.

3

Bring whoever runs IT

If an outside provider manages your systems, answer with them. Several items are settings you can confirm in minutes.

4

Use the result

Your weakest sections are the ones to close before the renewal questionnaire arrives, in that order.

Section 1 of 8

Identity and Multifactor Authentication

The question most applications open with. Insurers ask where MFA is enforced, for whom, and whether any account or path gets around it.

0/ 8
Section 2 of 8

Endpoint Detection and Monitoring

Underwriters want to know whether an attack on a laptop or server would be seen and stopped, and whether anyone is watching when it happens.

0/ 8
Section 3 of 8

Email Security and Payment Controls

Business email compromise and fraudulent transfers are among the most common claims. Applications ask how email is filtered and how a payment request is verified before money moves.

0/ 8
Section 4 of 8

Backups and Recovery

The control that decides whether a ransomware event is an outage or a ransom. Insurers ask where backups live, whether an attacker could reach them, and whether a restore has ever been proven.

0/ 8
Section 5 of 8

Patching and Vulnerability Management

Applications now ask for patch timelines by severity and how often you meet them. Unsupported systems are asked about separately and are often priced as a risk on their own.

0/ 8
Section 6 of 8

Privileged Access and Segmentation

Once inside, attackers look for an administrator account and a flat network. Insurers ask how many admin accounts exist, how they are controlled, and what stops an attacker moving from one system to the next.

0/ 8
Section 7 of 8

Incident Response, Training, and Vendors

Insurers ask whether you have a plan and have practiced it, whether your people are trained to spot an attack, and whether the vendors connected to you are held to the same standard.

0/ 8
Section 8 of 8

AI Use and AI-Enabled Fraud

The newest section. Underwriters have moved from asking whether you use AI to asking which tools and what checks surround them, and attackers now use AI to write better phishing and to fake voices and faces.

0/ 8

See your readiness score

Your total, your risk band, and where to start in your weakest sections are ready. Tell us where to send the results, and when your policy renews if you know it, so the follow-up lands before the questionnaire does.

0 of 64 items checked. You can go back and change answers before you submit.

No sales sequence. One email with your results, and Will reviews every submission himself. The newsletter comes only if you leave the box ticked.

We do not sell insurance. We help you close the gaps.

Most of what an underwriter asks for comes down to backups you can restore, access you control, and a plan you have practiced. We go through your results with you, mark what closes each gap, and bring in the right backup, recovery, and detection partners where you need them. If an option would pay us, we tell you in writing before you decide.