Cyber insurance applications have become a security questionnaire. Many ask whether you use multi-factor sign-in, whether your backups are tested and how quickly you patch. Owners and office managers often fill them in from memory, a few days before renewal.
This guide explains what a cyber policy generally covers, which controls insurers commonly ask about, and how to check your own answers before you sign. We are an IT company, not an insurer or a law firm. Use this to prepare for the conversation with your broker, not to replace it.
Who needs cyber insurance?
The Federal Trade Commission describes cyber insurance as "one option that can help protect your business against losses resulting from a cyber attack." NIST's Cybersecurity Framework 2.0 Small Business Quick-Start Guide lists it as a decision to make: "Assess whether cybersecurity insurance is appropriate for your business."
Neither source treats it as a general legal requirement. In plain terms, it deserves a conversation with your broker if:
- You hold customer, patient or payment data.
- Your business would struggle to operate while its computers, email or files were unavailable.
- A client, landlord or lender has asked you to carry it. Check your contracts; that requirement comes from the agreement, not from this guide.
Do not assume your existing policies already cover it. The National Association of Insurance Commissioners (NAIC) says "most commercial property and general liability policies do not cover cyber risks."
What a cyber policy generally covers
The FTC, which developed its guidance with the NAIC, splits coverage into two parts:
- First-party coverage pays your own costs after an incident. The FTC's list includes legal counsel on notification duties, recovery of lost data, customer notification, lost income from business interruption, cyber extortion and fraud, and forensic investigation.
- Third-party coverage protects you when someone else makes a claim against you. The FTC lists payments to affected consumers, settlement expenses, litigation costs and the cost of responding to regulatory inquiries.
The FTC also suggests asking whether the insurer will defend you in a lawsuit or regulatory investigation (look for "duty to defend" wording) and whether it offers a breach hotline "available every day of the year at all times." Which of these you need, and in what amounts, is a question for your broker.
What insurers ask about on the application
There is no standard application. The U.S. Government Accountability Office found "there is no standard cybersecurity risk assessment across providers or for all insureds" (GAO-22-104256, June 2022). The same report notes that insurers collect information such as a business's size, security controls and incident history, and that smaller businesses may answer a short questionnaire of as few as four questions.
The topics, though, repeat. New York's insurance regulator says an insurer's assessment of a business commonly starts with surveys and interviews on topics including "vulnerability management, access controls, encryption, endpoint monitoring, boundary defenses, incident response planning and third-party security policies" (NY DFS Circular Letter No. 2, 2021). The Cyber Readiness Institute, linked from NIST's Small Business Cybersecurity Corner, lists the minimum controls carriers want to see: awareness training, multi-factor authentication, documented and tested backups, access management, secure email and regular patching.
Most of these match the cybersecurity basics NIST recommends for every small business. Our free Security Basics Check walks through eight of them in about two minutes.
Check your own answers
Fill this in for your business as it runs today, before you open the application. Answer "Not sure" when you are not sure; that is the answer to follow up on.
| Control | What to confirm | Your answer |
|---|---|---|
| Multi-factor sign-in | Every person uses a second sign-in step for email, remote access and admin accounts, with no exceptions for the owner. | Yes / No / Not sure |
| Tested backups | Business data is backed up, a copy is kept apart from the main network, and someone has restored from it recently. | Yes / No / Not sure |
| Endpoint protection | Every work computer runs antivirus or threat detection that updates itself, and someone reads its alerts. | Yes / No / Not sure |
| Patching | Operating systems and software are updated promptly on every device, including laptops that leave the office. | Yes / No / Not sure |
| Email security | Incoming email is filtered for phishing and malicious attachments. | Yes / No / Not sure |
| Staff training | Staff have had security training, including spotting phishing, in the last year. | Yes / No / Not sure |
| Access control | Each person has their own account, admin rights are limited, and former employees' access is removed on their last day. | Yes / No / Not sure |
| Incident response plan | A written plan says who to call first, including your insurer, and staff know where it is. | Yes / No / Not sure |
The first six rows line up with NIST's basics, so the Security Basics Check can help you answer them. Access control and incident response go beyond that check. NIST's quick-start guide has an incident response section with a line for your insurer's contact details, a simple place to start the plan.
Answer the application honestly
An application answer is a statement about your business, not a goal. Under Florida's insurance code, statements in an application are representations, and a misrepresentation "may prevent recovery under the contract or policy" when it is fraudulent or material to the risk, among other conditions (section 627.409, Florida Statutes). How that applies to your policy is a question for your broker or attorney, but the practical lesson is simple:
- Answer for the business as it is today, not as it will be after a project you have planned.
- Ask what each question means. "MFA on all accounts" may include shared mailboxes, admin accounts and remote access tools you rarely think about.
- Keep evidence. A screenshot of your sign-in settings or a note of the last backup restore takes minutes and answers the question later.
- If the answer is no, say so and ask your broker how to handle it. Fixing the gap is better than describing it differently.
Before your renewal: a checklist
GAO reported in 2022 that policyholders face "fewer coverage options, stricter standards, and more exclusions" (GAO WatchBlog). Give yourself time before the renewal date:
- Ask your broker for the renewal application early, so you see the questions before the deadline.
- Complete the self-check above and mark every "No" and "Not sure."
- Run the Security Basics Check with whoever manages your IT.
- Test a restore from backup, and write down the date and what you restored.
- Confirm multi-factor sign-in on email, remote access and admin accounts, including the owner's.
- List every device and confirm it is receiving updates.
- Update your incident response plan with your insurer's claims contact and your broker's number.
- Read the policy's exclusions and conditions with your broker, and ask about anything you do not understand.
What a policy usually does not fix
Insurance pays for some of the damage after an incident. It does not stop the incident, restore your systems by itself, or make up for a control you said was in place.
Coverage also has limits. The Cyber Readiness Institute notes that "some policies may not cover losses resulting from social engineering attacks, intentional acts by employees, or attacks launched by a foreign nation." Social engineering includes the fake invoice or changed bank details that arrive by email, so ask your broker directly whether that is covered.
The controls in the self-check are what reduce the chance of an incident. Fitch Ratings told GAO that because insurers may include a security assessment in underwriting, companies generally work to reduce their cyber risks before they buy coverage, to get more favorable pricing. Your broker can tell you whether that applies to you.
Cyber insurance questions
Is cyber insurance mandatory for small businesses?
The FTC calls cyber insurance one option for protecting your business, and NIST's small business guide asks you to assess whether it is appropriate for you. Neither describes it as a general legal requirement. A client contract, lease, lender or industry rule can still ask you to carry it, so check your agreements and ask your broker or attorney.
Who needs cyber insurance?
It is worth a conversation with your broker if you hold customer, patient or payment data, or if your business would struggle to operate while its computers or email were down. The FTC suggests discussing whether you need first-party coverage, third-party coverage or both.
What are the typical requirements for cyber insurance?
There is no single standard. Common topics on applications include multi-factor authentication, tested backups, software patching, endpoint protection, email security, staff training, access control and an incident response plan. Your insurer's application is the only list that applies to you.
How much does cyber insurance cost for a small business?
It depends on the insurer, the coverage and your business, so ask your broker for quotes. Fitch Ratings told GAO that because insurers may assess your security during underwriting, companies generally work to reduce their cyber risks before buying coverage to get more favorable pricing.
Does my general liability policy cover a cyber attack?
Often not. The NAIC says most commercial property and general liability policies do not cover cyber risks. Ask your broker what your current policies say.
What does cyber insurance not cover?
Policies differ. The Cyber Readiness Institute notes that some policies may not cover losses from social engineering attacks, intentional acts by employees, or attacks launched by a foreign nation. Read the exclusions with your broker before you buy.
Get help closing the gaps
If your self-check has a few "Not sure" answers, the free IT assessment is a practical next step. It looks at your devices, backups and security basics, then puts the fixes in writing, so you can answer your application from evidence rather than memory. Onward's security services and patch management help close the gaps insurers ask about. Whether a policy is offered, and on what terms, is always the insurer's decision.
Onward is based in North Fort Myers and works with businesses across Southwest Florida, including Fort Myers, Naples and Cape Coral.