Back to resources

Cyber insurance applications have gotten longer and more specific over the last few years. Where policies once asked broad questions about security practices, they now ask about specific controls: which MFA solutions you use, whether endpoints have EDR software, how frequently backups are tested, who has admin access to your systems.

This specificity matters because the application becomes the benchmark for any future claim. If you say you have a control, and a claim review shows you didn't, the claim gets denied on the grounds of material misrepresentation. Answering a question incorrectly is not just a technicality. It can void your coverage entirely.

Common questions on cyber insurance applications and what they mean

"Do you use multi-factor authentication for remote access and email?"

This is the most common question and the one with the most claim-denial risk. "We use MFA" means every user, on every covered system, consistently. Not "we have it available" or "most people use it." If any account with access to patient data can log in with just a password, the answer is not an unqualified yes.

"Do you maintain offsite or cloud backups, and are they tested?"

Backups that aren't tested are not backups for insurance purposes. They're untested files you hope will work. If your application says yes to tested backups, you should have a recent test with a documented result to point to.

"Do you have a written incident response plan?"

A plan someone described in a meeting is not a written plan. The plan needs to exist as a document, with named individuals and defined steps. If you say yes on the application, the plan needs to be locatable and current.

"Do you use endpoint detection and response (EDR) software?"

EDR software is different from standard antivirus. It monitors for behavioral indicators of attack, not just known malware signatures. Windows Defender built into Windows 10 and 11 has some EDR functionality. Traditional antivirus products (basic Norton, McAfee consumer editions) generally do not qualify.

If you're unsure what you have, ask your IT vendor explicitly: "Does what we're running qualify as EDR for cyber insurance purposes?" Get the answer in writing. Your insurer may ask the same question during a claim review.

Before you submit the application

Go through every yes/no question and verify the answer against reality. Not against what you think is in place. Against what you can prove is in place today.

If you find a control that's listed as in place but isn't, implement it before you submit the application. Don't submit an application with a known inaccuracy and plan to fix it later.

After you submit

Keep a copy of your completed application. When your policy renews, compare the new application to the prior one. If questions have changed or new requirements have been added, update your controls accordingly before renewing. An outdated control posture from last year's application won't protect you on this year's claim.


The application process feels administrative. It's actually one of the most consequential documents your practice will sign. Treat it as carefully as any other legal commitment, because in a claims situation, it functions as one.

Not sure if your practice would hold up under a claims review?

The free Cyber Health Score takes 5 minutes and covers the controls cyber insurers check most often.

Get your free Cyber Health Score