Your cyber insurance application is a security audit. Would you pass it today?
Sixty-four checks across the eight areas underwriters ask about on current applications, including the new questions about AI. Check what is true today, not what is planned. Your section scores update as you go.
Rather work on paper? Download the Blank PDF (PDF, 13 pages).
Why the application got harder
It is priced on your controls
Insurers paid out heavily for ransomware and business email compromise. The application is how they decide whether to offer cover, at what price, and with what exclusions, and it now asks about specific controls rather than general intentions.
The answers become part of the policy
What you attest to on the application is what the insurer relies on. An answer that turns out to be wrong after an incident can put the claim in dispute. An accurate no with a dated plan is safer than a hopeful yes.
The same questions keep coming up
Multifactor authentication on email, remote access, and administrator accounts. Endpoint detection and response. Backups kept offline or immutable and actually tested. Patching on a schedule. A tested incident response plan. Verification before money moves.
AI is the newest section
Underwriters have started asking which AI tools are in use and what checks sit around them, and deepfake voice and video are now part of payment fraud. This assessment includes those questions so they do not arrive as a surprise at renewal.
What the applications ask now
These are drawn from current carrier applications and attestation forms and from federal guidance. None of them is new, but underwriters now ask for each one by name.
on email, on all remote access, and on administrator access to directory services, backups, network devices, and servers, for employees and third parties alike.
Carrier MFA attestation formsor immutable backups, segmented from the network, with full restores tested and a ransomware scenario in the restore plan.
Carrier applications and proposal formson endpoints, set to isolate or block activity, with alerts fed to a monitored platform or security operations center.
Carrier proposal formsof executives on voice and video calls are now used to request transfers. Federal guidance is to verify by calling back a number you already have.
FinCEN Alert FIN-2024-Alert004; FBI IC3How to use this assessment
Quick and practical. About ten minutes if the inventory exists, longer if it does not, which is itself a finding.
Answer for today
Check an item only if it is in place now and covers everyone it should. Planned, partial, or unknown stays unchecked.
Mind the word all
Most application questions say all users, all remote access, all administrators. One exception is usually the gap an attacker uses.
Bring whoever runs IT
If an outside provider manages your systems, answer with them. Several items are settings you can confirm in minutes.
Use the result
Your weakest sections are the ones to close before the renewal questionnaire arrives, in that order.
Section scores, weakest first
Where to start
We do not sell insurance. We help you close the gaps.
Most of what an underwriter asks for comes down to backups you can restore, access you control, and a plan you have practiced. We go through your results with you, mark what closes each gap, and bring in the right backup, recovery, and detection partners where you need them. If an option would pay us, we tell you in writing before you decide.
Sources
- Marsh, Cyber resilience: 12 key controls to strengthen your security
- Coalition, What information do I need to quote a policy with Coalition? (application questions, updated October 1, 2025)
- Coalition, AI advancements are reshaping cyber insurance coverage (July 16, 2025)
- Chubb, Cyber Enterprise Risk Management Standard Cyber Proposal Form (06/2023)
- Travelers, Multi-Factor Authentication attestation, form CYB-14306 Rev. 03-23
- Corvus, Smart Cyber Insurance Application
- Business Insurance, Insurers, brokers adjust as AI exclusions emerge (April 7, 2026)
- CISA, Cross-Sector Cybersecurity Performance Goals
- CISA, Cybersecurity Performance Goals 2.0 (December 2025)
- NIST, Cybersecurity Framework 2.0 (February 26, 2024)
- NIST, AI Risk Management Framework 1.0, Govern function (GOVERN 1.2, 1.6, 2.1, 2.3, 6.1)
- NIST, Secure Software Development Framework (SP 800-218, practice PW.7: review and analyze code) and SP 800-218A
- NSA, CISA, FBI and partners, AI Data Security: Best Practices for Securing Data Used to Train and Operate AI Systems (May 22, 2025)
- FBI IC3, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (December 3, 2024)
- FinCEN, Alert FIN-2024-Alert004 on fraud schemes involving deepfake media (November 13, 2024)