Licensed Agency · NPN #22222940·Prefer a human? Call our Orlando team: +1 (689) 353-8505
Truscott Insurance SolutionsTruscott Insurance Solutions
FeaturesHow It WorksBlog
Truscott Insurance SolutionsTruscott Insurance Solutions

Your insurance ally. We simplify policies, coach you on claims, and monitor for gotchas, so you're never caught off guard.

Call us: +1 (689) 353-8505

Tools

  • Policy Simplified
  • Claims Coach
  • Blog

Products

  • Auto Insurance
  • Home Insurance
  • Business Insurance
  • Cyber Insurance

Legal

  • Privacy Policy
  • Do Not Sell My Personal Information
  • Terms of Service
  • Licenses

© 2026 Truscott Inc. All rights reserved.

Truscott provides insurance information tools. AI-generated analyses are for informational purposes only and do not constitute insurance advice, legal advice, or coverage guarantees.

Back to Blog
Cyber Insurance

What Do Cyber Insurance Underwriters Ask About?

Truscott Team
August 29, 2026
7 min read

A cyber insurance application used to be a single page. Today it is closer to a security audit, and the answers you give decide three separate things: whether a carrier will quote you at all, what limits they will offer, and what you pay. Knowing what underwriters look for lets you fix the gaps before you apply instead of explaining them afterward.

Why the application got so much harder

Between 2019 and 2022, ransomware losses forced cyber insurers to rewrite how they price risk. Carriers that had been quoting on revenue and industry alone discovered that two businesses of identical size could have wildly different loss potential depending on a handful of technical controls. The market responded by turning the application into a checklist of those controls.

The result is a market that is far more disciplined than it was a few years ago. Capacity has returned, pricing has stabilized, and in many segments premiums have flattened or come down. But that stability came with conditions. Carriers now expect a baseline of security hygiene, and businesses that cannot demonstrate it are either surcharged heavily, given restricted terms, or turned away entirely.

For a small Florida professional firm, this is actually good news. The controls underwriters want are largely inexpensive and available in software you may already be paying for. The businesses that get the best terms are rarely the ones spending the most on security — they are the ones who configured what they already own.

Multifactor authentication: the single biggest question

If there is one item that determines whether you get quoted, it is multifactor authentication. Underwriters do not ask a single yes-or-no question about MFA anymore. They ask about it in layers, and each layer matters:

  • Email: is MFA enforced on all email accounts, including executives and shared mailboxes?
  • Remote access: is MFA required for VPN, remote desktop, or any external entry into your network?
  • Privileged accounts: do administrators authenticate with MFA when making system-level changes?
  • Cloud and critical applications: is MFA on your practice management, accounting, or client portal software?

A firm with MFA on email but not on remote access will often still be quoted, but with a higher retention or a ransomware sublimit. A firm with no MFA anywhere is increasingly a declination, not a negotiation. Exposed remote desktop protocol without MFA is one of the fastest routes to a decline in the entire market, because it is the entry point in a large share of ransomware claims.

Backups, and whether they would actually survive an attack

The second cluster of questions is about backups, and underwriters have gotten specific because attackers have. Modern ransomware crews look for backups first and encrypt or delete them before they touch production data. A backup that lives on the same network with the same credentials is not a backup from an underwriting standpoint.

Expect to answer how often you back up, whether at least one copy is offline or immutable, whether backups are segmented from the main network, and — the question most applicants stumble on — when you last tested a restore. Saying backups run nightly means little if nobody has ever confirmed the data comes back. Carriers ask about restore testing because it correlates strongly with how long a business is down after an incident, and business interruption is where cyber claims get expensive.

Endpoint protection, patching, and email filtering

Underwriters want to know what is watching your computers. Traditional antivirus is no longer a satisfying answer for most carriers. They ask specifically about endpoint detection and response, or EDR, which monitors behavior rather than matching known virus signatures, and whether it is monitored by someone who will respond at 2 a.m. Managed detection and response — EDR with a human security operations center behind it — earns meaningful credit.

Patching questions focus on cadence and coverage: how quickly critical patches get applied, whether you still run end-of-life operating systems, and whether anything internet-facing is unpatched. Any Windows Server or workstation past its support date is a red flag that can shrink the list of carriers willing to look at you.

Email security rounds out this section. Carriers ask about spam and phishing filtering, whether external emails are visibly tagged, and whether you have configured the email authentication records that make spoofing your domain harder. These are free settings in most email platforms and they cost nothing but attention.

Funds transfer procedures and the human controls

For any business that moves money — title agencies, law firms, CPA practices, contractors paying subcontractors — underwriters spend real time on wire transfer procedures. Social engineering and funds transfer fraud produce the highest claim frequency in many professional segments, and the loss is usually caused by a person, not a machine.

The questions are practical. Do you verify payment instruction changes by calling a number you already had on file, not one supplied in the email? Is dual authorization required above a dollar threshold? Do you train staff to recognize a spoofed executive request? Firms that answer yes to callback verification frequently get a higher social engineering sublimit; firms that cannot describe a procedure often get that coverage capped at a token amount or excluded. If you handle client escrow or closing funds, this section matters more to your outcome than anything technical. Real estate and law firm applicants should expect the most scrutiny here.

Your data, your dependencies, and your claim history

Underwriters need to size the potential loss, so they ask what kind of records you hold and how many. Protected health information, Social Security numbers, payment card data, and bank credentials all carry different notification costs. A dental practice with 6,000 patient records has a very different breach bill than a consultancy with 200 corporate contacts, and the limit recommendation follows from that number.

They also ask about dependency. Which vendors could take you offline if they were attacked? Do you rely on a single cloud platform for everything? Systemic risk — one provider failing and taking thousands of insureds with it — is the concern that keeps cyber underwriters up at night, and concentrated dependency can affect terms.

Finally, prior claims and known incidents. Answer honestly. Cyber applications are typically warranty statements, meaning a material misrepresentation can void coverage at the worst possible moment. If you had a business email compromise two years ago and remediated it, say so and describe the fix. Underwriters reward a documented response far more than they punish the incident itself.

Where applications most often get declined

Declinations cluster in a few predictable places. No MFA on remote access or email is the most common. Open remote desktop protocol exposed to the internet is next. Unsupported operating systems still in production, no offline or immutable backups, and an unremediated prior breach round out the list. Certain industries — municipalities, K-12 schools, managed service providers, cryptocurrency businesses — face a narrower market regardless of controls.

The important thing to understand is that most declines are fixable in weeks, not years. Turning on MFA across your platforms, moving one backup copy offline, and retiring a single legacy server can move an unquotable risk into a competitively priced one. If you are quoted with an unappealing ransomware sublimit or a high retention, that is usually a signal about a specific control rather than a verdict on your whole business, and it can often be renegotiated once the control is in place.

Frequently asked questions

Will a carrier verify my answers, or do they take my word for it?

Increasingly they verify. Many cyber carriers run external scans of your internet-facing systems before quoting, looking for open ports, expired certificates, and unpatched services. They also check your answers against what they find after a claim, which is why accuracy on the application is not optional.

How much can better controls actually lower my premium?

The bigger effect is usually on availability and terms rather than the base rate. Adding MFA and immutable backups can take you from one reluctant quote with a 50 percent ransomware sublimit to several competitive offers with full limits. The premium difference between a well-controlled and poorly controlled risk of the same size is often substantial, but the coverage difference is larger.

My IT provider handles all of this — can they fill out the application?

They should help with the technical sections, and most good providers will. But the application is signed by the business, and the business carries the liability. Have your IT provider answer in writing so you have documentation of what was represented and when.

What if I answer no to several questions?

You may still be quotable, particularly at smaller revenue bands where some carriers use short-form applications. Expect a higher retention, sublimits on ransomware and social engineering, and fewer carrier options. It is generally worth spending 30 days closing the gaps before you bind.

Do these questions change at renewal?

Yes, and they tighten each year. A control that earned credit two years ago may be the baseline expectation now. Review the renewal questionnaire early rather than the week before expiration.

What Truscott recommends

Treat the cyber application as a to-do list rather than a test you either pass or fail — most of what underwriters ask about can be fixed with configuration changes and a written procedure, not a new budget. Work through MFA, offline backups, EDR, and wire callback verification first, since those four items drive most of the pricing and most of the declines. A Truscott coverage review will walk you through the questionnaire before it goes to market so you know where you stand, and you can explore cyber insurance for Florida businesses or start a quote whenever you are ready. Reach out and we will tell you honestly what needs to change before you apply.

Free tools from Truscott

  • Cyber insurance
  • Florida cyber insurance

More from the blog

Cyber Insurance

What Changes at Your Cyber Insurance Renewal?

Cyber renewals move more than most lines of insurance. Learn what underwriters re-examine each year, which security controls drive pricing, and how to prepare your application before it goes back to market.

Cyber Insurance

What Happens After a HIPAA Breach: Notification, Penalties, and Coverage?

A HIPAA breach starts a federal notification clock, a penalty assessment, and a cascade of costs. Here is what happens at each stage and which parts of a cyber policy respond.