Free resource
Cyber insurance questionnaire and application: the 2026 worksheet.
A cyber insurance questionnaire is the 20-to-40-question application a carrier uses to underwrite your policy. In 2026 it decides eligibility, price, and whether a future claim pays. Ten controls show up on every SMB application we have reviewed (MFA, EDR/MDR, tested backups, an incident response plan, and six more). The wrong answer to any one of them can void coverage after a loss.
What's inside
What does a cyber insurance application ask in 2026?
The worksheet reproduces the ten controls carriers actually score, in underwriter language, with the “quiet disqualifier” answer for each: the response that looks survivable to you but reads as a hollow control to the person binding the policy. Plus a shortlist of the answers that quietly tank applications, and notes for 12 SMB verticals (law, dental, accounting, real estate, financial services, manufacturing, retail, auto dealers, and more).
Of the U.S. cyber insurance claims closed in 2024, roughly three in four closed without any payment to the policyholder: 28,555 of 38,496 (source: NAIC 2025 Cybersecurity Insurance Market Report, Figure 9). “Closed without payment” is not the same as denied. It also covers claims that fell under the deductible or outside policy terms. But some portion is denials, and the most preventable denial is a misstatement on the application.
- Multi-factor authentication on every system, not just the VPN
- Endpoint detection (EDR/MDR) on servers, not just laptops
- Backups that are immutable or MFA-locked, and actually restore-tested
- Privileged access separated, vaulted, and monitored on admin accounts
- Email security with a real gateway and sandboxing, not a spam filter
- Patch and vulnerability management, and no internet-facing EOL software
- Incident response plan in writing, with named roles, and tested
- Network exposure controlled: no flat networks, no naked RDP on port 3389
- Funds-transfer controls with out-of-band verification on every wire
- Security awareness training with phishing simulations, including finance staff
Why it's accurate
Which cyber insurance application questions are in the worksheet?
Every question, threshold, and gotcha is pulled from current cyber applications and ransomware supplementals issued by Coalition, Corvus by Travelers, Beazley, At-Bay, The Hanover, Fusion / Tokio Marine Kiln, Tokio Marine HCC. The dollar thresholds ($25,000 funds-transfer verification), the recovery-time bars (3-day restore), the deployment ladders that expose servers without EDR: those are the carriers' own words, not our paraphrase. If a control is not on a real form, it is not in the worksheet. Not sure what a ransomware week actually costs? Model the range.
Why applications get declined
What answers get a cyber insurance application declined?
MFA on email but not on the VPN or the two admin accounts. EDR on the laptops but not on the server that got encrypted. Nightly backups that have never been restored. A written incident response plan that was drafted in 2022 and has never been read. Internet-facing end-of-life software. RDP open on port 3389. No out-of-band verification on wires above the carrier's stated threshold. Any one of these is a decline reason on an application and, more expensively, a denial reason after a loss. In 2022 Travelers moved to rescind a cyber policy against an Illinois control-systems manufacturer that had attested to multifactor authentication across its digital assets when the environment showed MFA only on the firewall. After a ransomware loss, the parties agreed to a judgment rescinding the policy from inception (source: Travelers Property Casualty Co. of America v. International Control Services, Inc., C.D. Ill. No. 22-cv-2145).
Want the reasoning behind each question?
Why does the questionnaire ask for these twenty-two controls?
The worksheet above is the form. The companion article is the control-by-control explanation underneath it — what each question is really testing, which answers trigger a non-quote, and what evidence an underwriter will accept when you say yes.
Still translating the vocabulary?
Is the application asking about antivirus, EDR, or MDR?
The 2026 application asks a specific question about endpoint protection — antivirus, EDR, or MDR — that trips up first-time SMB applicants. This walk-through defines each term the way the underwriter reads it, shows exactly what the application asks, and helps you answer accurately without overcommitting.
Questions buyers ask
Cyber insurance questionnaire FAQ
What is a cyber insurance questionnaire?
A cyber insurance questionnaire is the 20-to-40-question application a carrier uses to underwrite a policy. It asks what security controls you operate (MFA, EDR/MDR, backups, incident response, and about a dozen others), quantifies your revenue and record volumes, and drives eligibility, price, sublimits, and whether a future claim actually pays.
What is a cyber insurance application in 2026?
The 2026 cyber insurance application is the same instrument as the questionnaire: a written attestation of your security posture that the carrier binds coverage against. What changed after 2021 is that the answers became controls-warranty language: a misrepresented control (typically MFA scope) is one of the most common reasons a carrier rescinds a policy or denies a ransomware claim.
What are the cyber insurance application questions carriers actually ask?
Ten controls show up on every U.S. SMB cyber application we have reviewed across seven carriers: MFA on email and remote access and admin accounts, EDR or MDR on workstations and servers, immutable or MFA-locked backups with tested restores, privileged access separation, email gateway with sandboxing, patch and EOL management, a written and tested incident response plan, no flat networks or exposed RDP, funds-transfer verification, and security awareness training with phishing simulations.
What is a cyber insurance audit?
In the SMB market, a cyber insurance audit is either the application itself (self-attested), a carrier-commissioned scan of your external attack surface run before binding, or a post-loss forensic review that reconciles what you said on the application with what the environment actually showed. All three anchor on the same 10-control checklist.
What answers get a cyber insurance application declined?
The quiet declines: MFA on email but not on VPN or admin accounts; EDR on laptops but not on servers; nightly backups that have never been restored; no written incident response plan; internet-facing end-of-life software; RDP open on port 3389; no out-of-band verification on wires above a stated threshold (commonly $25,000). Any one of these can also become the reason a paid policy does not pay after a loss.
How do I fill out a cyber insurance application?
Walk each question in order and answer honestly with evidence you can produce: an MFA coverage report from your identity provider, an EDR coverage list from your endpoint console, restore-test logs with a date and an initials block, the current incident response plan file, a vendor inventory, and the training completion report. If a control is only partially deployed, disclose the scope and accept the pricing. Both are safer than a yes you cannot evidence.
When can a cyber insurance policy be voided?
A policy can be rescinded, denied, or voided from inception when a material misstatement on the application is discovered, typically after a loss. In 2022 Travelers filed to rescind a cyber policy against an Illinois control-systems manufacturer that had attested to multifactor authentication across its digital assets when MFA protected only the firewall. After a ransomware loss, the parties agreed to a judgment rescinding the policy from inception (source: Travelers Property Casualty Co. of America v. International Control Services, Inc., C.D. Ill. No. 22-cv-2145).
How can a small business lower cyber insurance costs?
The single largest premium mover is closing gaps against the 10 controls before renewal, in the exact language the carrier will use on the form. Documented restore tests, MFA on every admin account, an operating EDR with named monitoring, and a written IR plan reviewed in the last 12 months change the underwriting conversation more than shopping brokers.
After the worksheet
How do you close the gaps a cyber insurance application uncovers?
The questionnaire tells you where you stand. The Cyber Insurance Readiness Sprint turns your environment into the evidence packet underwriters accept: the Conditional Access exports, the restore-test logs, the tested IR plan. Fixed scope, 7 business days, $1,500 to $3,500. CISSP-led, operated end-to-end by Obsidian Ridge.
This page is general information for educational purposes, not legal or insurance advice. Application language, statutory duties, and rule interpretations vary by carrier and by state, and change over time. Consult qualified counsel and your licensed broker before relying on any specific framing. Last reviewed: August 21, 2026 by Kfir Yair, Founder.
