A cyber insurance application used to be a single page. Today it is closer to a security audit, and the answers you give decide three separate things: whether a carrier will quote you at all, what limits they will offer, and what you pay. Knowing what underwriters look for lets you fix the gaps before you apply instead of explaining them afterward.
Between 2019 and 2022, ransomware losses forced cyber insurers to rewrite how they price risk. Carriers that had been quoting on revenue and industry alone discovered that two businesses of identical size could have wildly different loss potential depending on a handful of technical controls. The market responded by turning the application into a checklist of those controls.
The result is a market that is far more disciplined than it was a few years ago. Capacity has returned, pricing has stabilized, and in many segments premiums have flattened or come down. But that stability came with conditions. Carriers now expect a baseline of security hygiene, and businesses that cannot demonstrate it are either surcharged heavily, given restricted terms, or turned away entirely.
For a small Florida professional firm, this is actually good news. The controls underwriters want are largely inexpensive and available in software you may already be paying for. The businesses that get the best terms are rarely the ones spending the most on security — they are the ones who configured what they already own.
If there is one item that determines whether you get quoted, it is multifactor authentication. Underwriters do not ask a single yes-or-no question about MFA anymore. They ask about it in layers, and each layer matters:
A firm with MFA on email but not on remote access will often still be quoted, but with a higher retention or a ransomware sublimit. A firm with no MFA anywhere is increasingly a declination, not a negotiation. Exposed remote desktop protocol without MFA is one of the fastest routes to a decline in the entire market, because it is the entry point in a large share of ransomware claims.
The second cluster of questions is about backups, and underwriters have gotten specific because attackers have. Modern ransomware crews look for backups first and encrypt or delete them before they touch production data. A backup that lives on the same network with the same credentials is not a backup from an underwriting standpoint.
Expect to answer how often you back up, whether at least one copy is offline or immutable, whether backups are segmented from the main network, and — the question most applicants stumble on — when you last tested a restore. Saying backups run nightly means little if nobody has ever confirmed the data comes back. Carriers ask about restore testing because it correlates strongly with how long a business is down after an incident, and business interruption is where cyber claims get expensive.
Underwriters want to know what is watching your computers. Traditional antivirus is no longer a satisfying answer for most carriers. They ask specifically about endpoint detection and response, or EDR, which monitors behavior rather than matching known virus signatures, and whether it is monitored by someone who will respond at 2 a.m. Managed detection and response — EDR with a human security operations center behind it — earns meaningful credit.
Patching questions focus on cadence and coverage: how quickly critical patches get applied, whether you still run end-of-life operating systems, and whether anything internet-facing is unpatched. Any Windows Server or workstation past its support date is a red flag that can shrink the list of carriers willing to look at you.
Email security rounds out this section. Carriers ask about spam and phishing filtering, whether external emails are visibly tagged, and whether you have configured the email authentication records that make spoofing your domain harder. These are free settings in most email platforms and they cost nothing but attention.
For any business that moves money — title agencies, law firms, CPA practices, contractors paying subcontractors — underwriters spend real time on wire transfer procedures. Social engineering and funds transfer fraud produce the highest claim frequency in many professional segments, and the loss is usually caused by a person, not a machine.
The questions are practical. Do you verify payment instruction changes by calling a number you already had on file, not one supplied in the email? Is dual authorization required above a dollar threshold? Do you train staff to recognize a spoofed executive request? Firms that answer yes to callback verification frequently get a higher social engineering sublimit; firms that cannot describe a procedure often get that coverage capped at a token amount or excluded. If you handle client escrow or closing funds, this section matters more to your outcome than anything technical. Real estate and law firm applicants should expect the most scrutiny here.
Underwriters need to size the potential loss, so they ask what kind of records you hold and how many. Protected health information, Social Security numbers, payment card data, and bank credentials all carry different notification costs. A dental practice with 6,000 patient records has a very different breach bill than a consultancy with 200 corporate contacts, and the limit recommendation follows from that number.
They also ask about dependency. Which vendors could take you offline if they were attacked? Do you rely on a single cloud platform for everything? Systemic risk — one provider failing and taking thousands of insureds with it — is the concern that keeps cyber underwriters up at night, and concentrated dependency can affect terms.
Finally, prior claims and known incidents. Answer honestly. Cyber applications are typically warranty statements, meaning a material misrepresentation can void coverage at the worst possible moment. If you had a business email compromise two years ago and remediated it, say so and describe the fix. Underwriters reward a documented response far more than they punish the incident itself.
Declinations cluster in a few predictable places. No MFA on remote access or email is the most common. Open remote desktop protocol exposed to the internet is next. Unsupported operating systems still in production, no offline or immutable backups, and an unremediated prior breach round out the list. Certain industries — municipalities, K-12 schools, managed service providers, cryptocurrency businesses — face a narrower market regardless of controls.
The important thing to understand is that most declines are fixable in weeks, not years. Turning on MFA across your platforms, moving one backup copy offline, and retiring a single legacy server can move an unquotable risk into a competitively priced one. If you are quoted with an unappealing ransomware sublimit or a high retention, that is usually a signal about a specific control rather than a verdict on your whole business, and it can often be renegotiated once the control is in place.
Will a carrier verify my answers, or do they take my word for it?
Increasingly they verify. Many cyber carriers run external scans of your internet-facing systems before quoting, looking for open ports, expired certificates, and unpatched services. They also check your answers against what they find after a claim, which is why accuracy on the application is not optional.
How much can better controls actually lower my premium?
The bigger effect is usually on availability and terms rather than the base rate. Adding MFA and immutable backups can take you from one reluctant quote with a 50 percent ransomware sublimit to several competitive offers with full limits. The premium difference between a well-controlled and poorly controlled risk of the same size is often substantial, but the coverage difference is larger.
My IT provider handles all of this — can they fill out the application?
They should help with the technical sections, and most good providers will. But the application is signed by the business, and the business carries the liability. Have your IT provider answer in writing so you have documentation of what was represented and when.
What if I answer no to several questions?
You may still be quotable, particularly at smaller revenue bands where some carriers use short-form applications. Expect a higher retention, sublimits on ransomware and social engineering, and fewer carrier options. It is generally worth spending 30 days closing the gaps before you bind.
Do these questions change at renewal?
Yes, and they tighten each year. A control that earned credit two years ago may be the baseline expectation now. Review the renewal questionnaire early rather than the week before expiration.
Treat the cyber application as a to-do list rather than a test you either pass or fail — most of what underwriters ask about can be fixed with configuration changes and a written procedure, not a new budget. Work through MFA, offline backups, EDR, and wire callback verification first, since those four items drive most of the pricing and most of the declines. A Truscott coverage review will walk you through the questionnaire before it goes to market so you know where you stand, and you can explore cyber insurance for Florida businesses or start a quote whenever you are ready. Reach out and we will tell you honestly what needs to change before you apply.
Motor carriers run on dispatch software, ELD data, and email-based load booking, which makes them a live target for freight fraud and ransomware. Here is what cyber insurance covers for trucking and logistics operations.
Cyber InsuranceDesign firms hold drawings, models, bid documents, and client data that criminals want. Learn how cyber insurance protects architecture and engineering practices and where it overlaps with professional liability.