The questions on a cyber insurance application look much as they always did. What sits behind them does not. Underwriters increasingly want to know whether a control was actually running, actually enforced, and actually tested, and they ask for something that shows it. Six questions, and you will know which of your answers would survive a follow-up.
A self-assessment, not insurance advice. Underwriting decisions belong to the carrier.·Checked July 2026
Five of these mirror the areas every SMB application concentrates on. The sixth is the one that has changed, and it is usually the one that decides how the rest are read.
Answer the six questions and your readiness readout appears here, including which answers are most likely to draw a follow-up.
Forms vary. What they are trying to establish does not. Some carriers ask for more than this. Almost none ask for less.
| Area | What is actually being asked | Where it usually falls down |
|---|---|---|
| Multi-factor authentication | Whether it is enforced on remote access, VPN and administrator accounts, not just on email. | Enforced on email, assumed everywhere else. |
| Endpoint protection | Whether real detection and response runs on every machine, including the laptop somebody takes home. | Bundled antivirus counted as endpoint detection. |
| Backups | Three things: they run, at least one copy is somewhere an attacker who owns the network cannot reach, and somebody has restored from them. | The third one. Backups nobody has ever tested. |
| Incident response plan | A document that names who gets called, in what order, with what authority. | A concept of a plan rather than a document. |
| Security awareness training | Whether staff are trained on a schedule, and whether there is a record of who completed it. | Training happened; nobody kept the record. |
This is a plain-language summary of the ground SMB cyber applications cover, not a reproduction of any carrier's form. Your carrier's questions are the ones that count, and your broker has them.
Almost never because the business is uninsurable. Nearly always because an answer cannot be supported.
MFA on email but not on the VPN. Backups running but never tested. A partial yes recorded as a full yes is the most common way an application becomes a coverage problem later, because it reads as a clean answer right up until somebody checks.
Often true, and still not an answer. Somebody has to know what is configured, and in a lot of small businesses nobody has asked the IT provider that question in writing.
Usually means a document exists. The follow-up question is whether anything attaches to it: a schedule, a record, a date. A policy with no evidence of operation behind it can be worse than none, because it establishes that the business knew what it should have been doing.
The person who signs the application is almost never the person who knows the answers. The owner or office manager fills it in, the IT provider holds the actual configuration, and the two never compare notes. The cheapest fix is to have whoever manages the systems initial each answer before it goes back.
Why this outlives the policy. An application is a document the business signs, and the answers can be read again if a claim is made. If a control was recorded as in place and was not, the exposure can move back to the business at precisely the moment the policy was meant to help. That is why an unsupported yes is a bigger problem than a no. A no is just a gap, and gaps have known fixes.
And usefully, it does not come from a vendor.
On November 19, 2025, the Center for Internet Security and CyberAcuView released Control Assist, which aligns the CIS Critical Security Controls Implementation Group 1, the 56 safeguards that make up basic cyber hygiene, with the questions that appear on cyber insurance applications. CIS described the problem it solves as SMBs struggling to translate their security efforts into language insurers understand. CyberAcuView described it as translating essential controls into the language of underwriting.
The reason it is worth knowing by name: AIG, AXIS, Beazley, Chubb, The Hartford, Liberty Mutual and Travelers are named as supporting insurers. If somebody asks why a small business should care about a security framework, seven carriers is a better answer than anything a consultant can tell them. It is free and public.
There is a great deal of material circulating with confident figures on how many applications get declined, how far premiums rise, and what proportion of carriers now mandate a given control. Almost all of it traces back to marketing rather than to a source you could check, and much of it cites other marketing.
We only put numbers in front of people when we can point at where they came from. So this page names a framework, the two organisations behind it, the date it was published, and the carriers supporting it, all of which you can verify in a minute. The statistics are left to whoever can source them.
Whatever the carrier and whatever the form, SMB applications concentrate on the same five areas: multi-factor authentication on remote access, VPN and administrator accounts rather than email alone; endpoint detection and response running on every device; backups that run, keep at least one copy an attacker on the network cannot reach, and have actually been restored from in a test; a written incident response plan that names who is called and in what order; and security awareness training delivered on a schedule with a record of who completed it. Some carriers ask for more. Almost none ask for less.
Most often because an answer cannot be supported rather than because the business is uninsurable. Three patterns account for the majority: a partial yes recorded as a full yes, such as multi-factor authentication on email but not on the VPN; deferring to an IT provider without anyone having confirmed in writing what is actually configured; and pointing at a written policy that has no schedule, record or date attached to show it operates. The underlying problem is that the person who signs the application is usually not the person who knows the answers.
Control Assist is a free framework released on November 19, 2025 by the Center for Internet Security and CyberAcuView. It aligns the CIS Critical Security Controls Implementation Group 1, the 56 safeguards that make up basic cyber hygiene, with the questions that appear on cyber insurance applications, so a business can describe its security in terms an underwriter recognises. AIG, AXIS, Beazley, Chubb, The Hartford, Liberty Mutual and Travelers are named as supporting insurers.
Yes. An application is a document the business signs, and the answers can be reviewed if a claim is made. If a control was recorded as in place and was not, the exposure can move back to the business at exactly the moment the policy was supposed to help. That is why an answer nobody can support is a larger problem than a no, which is simply a gap with a known fix.
No, and nothing can. Underwriting decisions belong to the carrier, appetite differs between carriers and changes over time, and every application is read alongside the industry, revenue, claims history and controls of the specific business. This check is a self-assessment of whether your answers would survive a follow-up question, which is a different and more useful thing to know before you submit.
A control that was optional on last year's application can be the reason this year's gets held up.
Security, Sized Right is a monthly issue on what actually changed: what underwriters started asking for, what the enforcement record shows, and what either one means for a practice too small to have a security team. It is written from real client work, not from vendor research.
You can read the current issue in full before deciding whether to subscribe.
The controls on a cyber application are the same ones a CIS Controls IG1 or HIPAA security risk analysis walks you through, and the output is the dated, documented record an underwriter is asking to see. Seqora runs both as guided assessments. See a finished sample, or run one on a demo business right now. No signup.