The short answer
Your insurance application is a free security checklist. Check you can prove every Yes.
A cyber insurance application asks about specific security controls. The people who write it pay the claims when the answers turn out wrong. Most firms are about as secure as they think, but cannot prove it, and an insurer cannot price what it cannot see. So pull out your last renewal application and check you could show evidence for every Yes. Where a question assumes an office network you do not have, answer No and attach a short note on what you do instead.
We applied for our own cyber and technology errors-and-omissions insurance this month. The application had ninety questions, most of them about specific security controls. It also had a whole supplemental questionnaire about nothing but multi-factor authentication (MFA), the second sign-in check after a password.
It is the most useful security document we have read in a year, and it is free.
Every framework you have been handed comes from someone selling you something. A vendor's checklist leads to the vendor's product. A consultant's assessment leads to the consultant's paid engagement. An insurance application is different. The people who write it pay the claims when the answers turn out to be wrong. They have refined it over years of watching which controls actually correlate with losses. Nobody on the other end of that form is trying to sell you software.
If you have not filled one out, or you signed the last renewal without reading it, here is what it asks and what it means for your firm.
The eight questions that hold up an application
Most of the ninety questions are background. A smaller set decides whether your application goes forward. Here they are, roughly in order of how often they hold one up:
Multi-factor authentication on email. The usual gap: MFA is on for most staff, but older sign-in methods (legacy authentication) are still open somewhere. Those quietly get around MFA.
MFA on remote and administrative access. This is the one that matters most. Firms require MFA for ordinary staff but exempt the administrators and the service accounts (accounts that software, not a person, signs in with). That is exactly backwards. An attacker who breaks into an ordinary account is a problem. An attacker who reaches an administrator account without MFA controls your firm's entire cloud setup.
MFA on backup systems. It is almost never set up, and usually nobody has thought about it. Backups are your way back. Ransomware attackers destroy them before they encrypt anything. And those backups are often protected by a password alone.
Conditional access policies. These are sign-in rules the firm sets in one central place. Without them, MFA is a setting on each person's account, not a rule the firm enforces. Anyone who finds it inconvenient at the wrong moment can switch it off.
Endpoint detection with central visibility. This means security software on every computer, all reporting to one place. Antivirus installed on each machine is not the same as knowing how many machines you have. The common failure is not a missed threat. It is three laptops nobody knew were unmanaged.
Backups that have been restore-tested. Nearly every firm has backups. Very few have tested a restore. A backup that has never been restored is a belief, not a backup.
A written incident response plan. This is the plan for what the firm does when something goes wrong. It is missing, or it names a coordinator who left the firm two years ago.
Privileged access. This is about who holds administrator rights. At some point everyone senior was made a global administrator, the top admin role, and nobody ever took it away.
A brief note on where this is heading. Carriers (the insurers) are beginning to ask about three things: generative AI use, prompt logging (a record of what staff type into AI tools), and acceptable use policies. Consumer AI tools the firm does not manage are a strong candidate for the next auto-decline trigger, an answer that gets an application turned down on its own. Most firms cannot currently answer these questions at all.
The questions that make a good firm look bad
Here is the part nobody warns you about.
Insurance applications were written for a 2012 office. Servers in a closet. A firewall around the office network. A VPN, a private tunnel into that network, for the person working from home on a Tuesday. Most firms under twenty-five people are now entirely cloud-based. If yours is, several questions have no honest good answer.
Do you restrict remote access to a VPN? No. There is no office network to tunnel into. Every system is a cloud service reached over an encrypted connection.
Do you require dual authorization for all wire transfers? No. There are four people in the firm and two of them are the partners.
Do you require background checks on all employees? The question assumes an HR department.
Answer these honestly, and your application reads like a firm with no controls. Answer them dishonestly, and you have made a false statement on a document that carries fraud language. That can void the policy at the moment you need it.
There is a third option, and it has a name: compensating controls.
A compensating control is a different safeguard that gives the same protection the question was written to test for. You answer No, and you attach a short written explanation of what you do instead.
For the VPN question, the explanation says this. There is no on-premises network, meaning no network in an office. All systems are cloud services reached over TLS, the standard encrypted connection. Multi-factor authentication is enforced at the identity provider, the service your staff use to sign in. Conditional access policies limit where, and from which devices, staff can sign in. That is stronger than a VPN. An underwriter reading it sees right away that this is a modern setup, not an unprotected one.
For dual authorization, the explanation says this. Any change to payment instructions is checked by a separate telephone call to a number already on file. It is never checked by calling a number given in the request.
A No with that written explanation attached reads completely differently than a No alone. The explanation is called an addendum. It takes about an hour to write. It is the best-spent hour in the entire application process.
What we found in our own house
We are a security firm. We had every framework, every template, every checklist. We answered the ninety questions and found two gaps in our own setup.
There was no written offboarding procedure, the steps for shutting off a departing person's access. There is one person in the firm, so nobody had ever left. That is not a control. It only means the need had never come up.
There were backups, in the sense that the vendors whose platforms we use keep backups. Nobody had ever tried a restore.
Neither of those is a technical failure. Both are failures of evidence. The tools were running the entire time. What did not exist was anything written down that proved they were. An underwriter cannot price a control they cannot see. Neither can an examiner.
That is the gap this exercise exposes, and it is almost always the real one. Firms are rarely as insecure as their applications make them look. They are usually about as secure as they think. They are just completely unable to prove it.
Both gaps are closed now. It took an afternoon. We only found them because someone with money at stake asked a specific question in writing.
Three numbers firms mix up
These three come up constantly. Mixing them up leads firms to the wrong conclusion about what they owe.
If you are wondering whether the Safeguards Rule applies to an accounting practice at all, 16 CFR 314.2 gives examples of a financial institution. Among them it names an accountant or other tax preparation service that is in the business of completing income tax returns.
500 consumers is the notification trigger. Under 16 CFR 314.4(j), if a notification event involves the information of at least 500 consumers, the firm must report it to the Federal Trade Commission. The deadline is as soon as possible, and no later than 30 days after discovery.
5,000 consumers is the exemption ceiling. Under 16 CFR 314.6, financial institutions that maintain customer information on fewer than five thousand consumers are exempt from four specific requirements. Two are the written risk assessment at 314.4(b)(1) and the continuous monitoring or penetration testing requirement at (d)(2). The other two are the written incident response plan at (h) and the annual written report to leadership at (i).
500,000 records is one of the size bands on the insurance application, where it asks how much data you hold. It has nothing to do with either of the above.
Two consequences worth sitting with. First, a firm can fall below the 5,000 exemption ceiling and still owe the FTC a notification, because the two numbers measure different things. Second, an insurer does not care about either one. Being exempt from a rule is not the same as being insurable. The underwriter will want the control regardless of what the rule lets you skip.
One more thing about the 5,000 figure. Most firms that assume they are under it have never actually counted. The count is consumers whose information you maintain, not clients you billed this year. Prior-year returns still on file count. Spouses and dependents on a joint return count.
What to do next
Do not buy a consultant's checklist. You already have a better one.
Pull out your last renewal application. Go through it one question at a time. For every Yes you gave, check whether you could produce evidence. Not whether the answer felt true when you signed it. Whether you could show someone.
That exercise costs nothing and takes an afternoon. It will tell you more about how secure your firm actually is than any assessment you could buy. Where you find a Yes you cannot back up with evidence, you have found real work. Where you find a No that deserves an explanation, you have found an hour that will change how your application reads.
Related questions
What does a cyber insurance application actually ask about?+
Specific security controls. The application we completed had ninety questions, most of them about controls. It also had a supplemental questionnaire about multi-factor authentication alone. The people who write the form pay claims when the answers turn out to be wrong. They have refined it over years of watching which controls correlate with losses. So it is not built around any vendor's product.
Which answers most often stall a submission?+
Eight. Multi-factor authentication on email, on remote and administrative access, and on backup systems. Conditional access policies. Endpoint detection with central visibility. Backups that have been restore-tested. A written incident response plan. And privileged access held only by people whose job is administration. Remote and administrative access is the one firms most often get backwards. They require MFA for ordinary staff but exempt the administrators and service accounts.
How does a cloud-only firm answer questions written for an office network?+
With a compensating control. Answer No, and attach a short written explanation of the different safeguard that gives the same protection. For the VPN question, the explanation says there is no on-premises network, and all systems are cloud services reached over TLS. Multi-factor authentication is enforced at the identity provider. Conditional access policies limit where, and from which devices, staff can sign in. A No with an addendum reads completely differently from a No alone. The addendum takes about an hour to write.
What is the difference between 500, 5,000 and 500,000?+
500 consumers is the notification trigger. Under 16 CFR 314.4(j), a notification event involving at least 500 consumers must be reported to the Federal Trade Commission. The deadline is as soon as possible and no later than 30 days after discovery. Under 16 CFR 314.6, 5,000 consumers is the exemption ceiling. Below it, a firm is relieved of four requirements. Two are the written risk assessment at 314.4(b)(1) and the continuous monitoring or penetration testing requirement at (d)(2). The other two are the written incident response plan at (h) and the annual written report to leadership at (i). 500,000 records is a size band on an insurance application, for how much data you hold. It relates to neither.
Who counts toward the 5,000 figure?+
Consumers whose information the firm maintains, not clients it billed this year. Prior-year returns still on file count. Spouses and dependents on a joint return count too. Most firms that assume they are under the ceiling have never actually counted.
Are carriers asking about AI yet?+
They are beginning to. Questions on generative AI use, prompt logging and acceptable use policies are starting to appear on applications. Consumer AI tools the firm does not manage are a strong candidate for the next auto-decline trigger, an answer that gets an application turned down on its own. Most firms cannot currently answer these questions at all.
Claremont Security works with accounting and tax firms on the FTC Safeguards Rule, IRS Publication 4557, and governed deployment of Microsoft Copilot. Our WISP readiness check is free and requires no account: claremontsecurity.com/wisp-check
claremontsecurity.com/insights/what-a-cyber-insurance-application-actually-asks
