The Application Form Became the Hard Part
A decade ago, buying cyber cover meant answering a handful of questions about turnover and the kind of data you held. The underwriter priced the risk with limited information, and almost everyone who asked for a quote received one. That era has ended. Insurers absorbed several years of ransomware losses that ran well ahead of the premium they collected, and the response across the market was to start underwriting the controls rather than the industry. Today the application form is where most of the decision gets made, and businesses that cannot answer it well are finding themselves quoted at a loading, offered a restricted policy, or declined outright.
This shift catches out plenty of owners who assumed insurance was something you bought instead of doing the security work. The current position is closer to the opposite — the policy is priced on the assumption that a baseline of controls is already in place, and the questions exist to verify it. The useful way to read a cyber proposal form is as a checklist of what the market considers reasonable practice. Answering it honestly tells you a great deal about where your business actually sits.
Multi-Factor Authentication Is the Threshold Question
If there is one control that determines whether a quote appears, it is multi-factor authentication. Most insurers now ask whether MFA is enabled on email, on remote access, and on administrative accounts, and a growing number treat a no on any of those three as a decline rather than a loading. The reasoning is straightforward. Compromised credentials sit behind the majority of claims an insurer sees, and MFA removes most of that pathway at effectively no cost to the business.
Where businesses trip up is on scope. Enabling MFA for the management team while leaving it off for shared mailboxes, contractor accounts, or the legacy service account that nobody wants to touch will not satisfy an underwriter who asks the question precisely. Nor will MFA on the email platform alone if remote desktop access is still protected by a password. Before completing an application, it is worth having whoever administers your systems confirm in writing which accounts are covered and which are exempt, because that answer becomes part of the contract. Telling an insurer you have MFA everywhere when you do not is a disclosure problem that surfaces at exactly the wrong moment.
Backups That Have Actually Been Tested
The second question every underwriter asks concerns backups, and it is rarely a simple yes or no. Insurers want to know whether backups are held separately from the production network, whether at least one copy is offline or immutable, how frequently they run, and — the question that separates the prepared from the hopeful — when you last performed a test restore.
This matters because ransomware operators specifically target backup infrastructure. An attacker who gains administrative access will look for the backup server before encrypting anything, because a business with working backups has little reason to pay. Backups sitting on a network share that uses the same credentials as everything else offer almost no protection. Offline copies, immutable cloud storage, or a separately credentialed backup platform change the economics of the entire incident.
The test restore question is worth taking seriously on its own merits, insurance aside. A meaningful proportion of businesses that believe they have good backups discover during a live incident that the job had been failing silently for months, that a critical database was never included, or that restoring the full environment would take three weeks rather than the two days assumed. A documented restore test each quarter answers the underwriter and protects you regardless of whether you ever claim.
Endpoint Detection, Patching and Email Filtering
Beyond the two headline controls, applications commonly ask about endpoint detection and response software, patch management, and email security. Traditional antivirus is increasingly treated as insufficient at the mid-market end, where insurers expect a detection platform capable of identifying suspicious behaviour rather than matching known signatures. For very small businesses, the built-in protection in a well-configured Microsoft or Google environment is often accepted, provided it is actually enabled and monitored.
Patching questions usually focus on how quickly critical vulnerabilities are addressed and whether any unsupported software remains in use. Honesty here is essential, since most policies contain wording that limits cover where a loss flows from a known unpatched vulnerability or end-of-life system. Disclosing a legacy application and having it priced is a far better outcome than staying silent and finding the exclusion applies.
Email filtering questions have grown more detailed as business email compromise became the most frequently reported claim type across the local market. Underwriters want to see spam and phishing filtering, and increasingly ask about external sender warnings and whether staff receive periodic awareness training.
Payment Verification Procedures
Businesses that make regular supplier payments should expect specific questions about how bank account changes are verified. The standard the market expects is a call-back to a phone number already held on file — not a number supplied in the email requesting the change — before any payment details are altered. Some policies make this a condition of social engineering cover rather than merely a rating factor, which means a claim arising from an unverified payment change can be reduced or declined even though the fraud itself is clearly the sort of loss the section was written for.
Putting a written verification procedure in place costs nothing, takes an afternoon, and directly protects the cover you are paying for. It also happens to prevent the loss in a large share of cases, which is the point.
How Your Answers Translate Into Premium
Controls affect cyber pricing more than almost any other factor at the smaller end of the market. Two businesses of identical size and sector can receive quotes that differ substantially based purely on how the proposal form was answered, and in some cases the difference between a declined risk and a competitively priced one comes down to a control that could have been implemented in a week.
That creates a practical opportunity. If your application is going to reveal gaps, it is usually worth closing the cheap ones first and applying afterwards rather than accepting a loaded premium and intending to improve later. Enabling MFA across all accounts, moving a backup copy offline, and documenting a payment verification process are inexpensive actions with measurable effect on both the premium and the underlying risk. An adviser who places cyber cover regularly will be able to tell you which of your gaps the market cares most about, and which insurers take a more accommodating view of the others.
Getting the Disclosure Right
One theme runs through all of this. The proposal form is a disclosure document, and the answers become part of the basis on which the policy is issued. Overstating your controls to secure a better price creates a risk far worse than the premium saving, because it gives the insurer grounds to question the claim at the point you most need it paid. Where you are unsure of an answer, say so and let the underwriter ask a follow-up question. Where a control is partially in place, describe the scope rather than answering yes.
Businesses that approach the application as an honest stocktake generally end up better protected and better insured than those who treat it as an obstacle. If you would like help working through a cyber proposal form, or a comparison of how different insurers assess the same set of controls, complete the enquiry form and one of our referred advisers will be in touch to discuss your situation and arrange terms. Financial advice is provided by Cover4You, Registered Financial Service Providers.
About the Author
CyberCover Team is part of the CyberCover team — dedicated to making cyber insurance transparent and accessible for NZ businesses of all sizes.