Cyber insurance used to be easy to buy. You filled out a short form, checked a few boxes, and got a policy that paid out when something went wrong. Those days are over. After years of ransomware losses, insurers tightened up. The questionnaires got longer, the required controls got stricter, and claims started getting denied when the answers didn't match reality.

If you're renewing a policy or buying your first one, the underwriting process now looks a lot like a security audit. Underwriters want proof that you run real controls, not just that you own the right tools. This guide walks through how cyber insurance works today, what underwriters ask for, and how a mature compliance program helps you answer honestly and pay less.

How cyber insurance actually works

A cyber insurance policy covers the cost of a security incident: things like ransomware payments, business interruption, breach notification, legal fees, and regulatory fines where they're insurable. In exchange, you pay a premium, and the insurer prices that premium based on how likely you are to file a claim.

That pricing is the whole game. Underwriters assess your risk before they quote, and the way they assess it is a questionnaire. Every question maps to a control they expect you to run. The stronger and more provable your controls, the lower your risk profile, and the better your terms. Weak or missing controls either raise your premium, shrink your coverage, or get you declined outright.

The controls underwriters now require

A few years ago, a firewall and antivirus were enough to tick the box. Today the baseline is much higher, because insurers know which controls actually stop losses. These are the ones that show up on almost every questionnaire.

Multi-factor authentication everywhere

MFA is the single most requested control, and for good reason. It stops the credential theft that starts most breaches. Underwriters don't just ask whether you have MFA. They ask where: on email, on remote access, on admin accounts, on your critical systems. "Some of our apps" is not a good answer. You need to show MFA is enforced across the board.

Backups you've actually tested

Ransomware only works if you can't recover. Insurers want backups that are regular, encrypted, and stored offline or otherwise isolated from your production network so attackers can't encrypt them too. And they want proof you've tested a restore. An untested backup is a hope, not a control.

Endpoint detection and response

EDR replaced traditional antivirus on most questionnaires. It watches endpoints for suspicious behavior and lets you respond fast when something looks wrong. Underwriters ask whether it's deployed on every device, not just servers, because one unmonitored laptop is all an attacker needs.

Security awareness training

Most incidents start with a person clicking something. Regular training, including phishing simulations, lowers that risk, and underwriters know it. They ask how often you train staff and whether you can show who completed it.

A tested incident response plan

When an incident hits, the difference between a contained event and a catastrophe is often whether you had a plan. Underwriters ask if you have a documented incident response plan, whether roles are assigned, and whether you've rehearsed it. A plan nobody has practiced won't hold up when the clock is running.

Why a mature program lowers your premium

Here's the connection teams miss. Every control on that questionnaire is also a control in a compliance framework. MFA, backups, EDR, training, incident response: they all map to SOC 2, ISO 27001, and the requirements behind NIS2 and DORA. If you already run a compliance program, you already run most of what underwriters want.

That does two things for you. It lowers your risk profile, which lowers your premium. And it speeds up underwriting, because you can answer with evidence instead of promises. A company that hands over a current SOC 2 report and clean control evidence gets better terms than one that fills in a form from memory. Insurers reward provable maturity, and a program is how you prove it.

The honesty problem: how claims get denied

The questionnaire isn't just paperwork. It's part of your contract. When you attest that MFA is enforced everywhere or that backups are tested quarterly, the insurer relies on that. If a claim comes in and the investigation shows the control wasn't actually in place, the insurer can deny the claim or void the policy for misrepresentation.

This has happened. Companies have been denied payouts because MFA wasn't enabled on the account that got breached, even though the questionnaire said it was. The gap wasn't always deliberate. Someone answered based on what they thought was true, not what they could prove. That's the real danger: not lying, but not knowing.

The only safe way to answer an underwriting questionnaire is from evidence. If you can point to the control, its owner, and proof it was operating on the date in question, your answers hold up when a claim depends on them.

Answer the questionnaire from evidence, not memory

This is where OptiTech comes in. Your program in the OptiTech Console holds your controls, their owners, and the evidence that each one is actually operating. When an underwriting questionnaire asks about MFA, backups, EDR, training, or incident response, you're not guessing. You're reading the current state straight from your program.

Because the same controls map across your frameworks, one well-run program answers the questionnaire, the auditor, and the enterprise buyer at once. And when a control drifts, for example a backup test that didn't run, the program shows it before you sign an attestation that isn't true. You answer honestly because you can see the truth.

You can even point your broker or underwriter to your trust center, where your certifications and security posture are already published. It signals maturity before the questionnaire even starts.

Answer as of a date

Underwriting questions are about a point in time. Before you attest, check that each control was operating on the date you're certifying, not just that it exists today. Evidence tied to a date is what protects a claim later.

Getting started

You don't need a perfect program to benefit. A practical first pass looks like this:

  1. Map the questionnaire to your controls. Take last year's underwriting form and match each question to a control in your program.
  2. Fill the obvious gaps first. MFA coverage, tested backups, and EDR deployment are the usual weak spots.
  3. Attach evidence to each control so every answer traces back to proof, not memory.
  4. Publish what you can to a trust center so brokers and buyers see your posture up front.

Cyber insurance rewards the same discipline your customers and auditors already ask for. Run the controls once, keep the evidence current, and the underwriting questionnaire stops being a scramble. You answer honestly, you pay less, and your coverage actually holds when you need it.

Ready to answer underwriting questions from evidence instead of memory? Book a demo and see how OptiTech connects your controls and evidence into one program.