Cyber insurance questionnaire: what insurers ask and why

The form arrives before the quote. It runs to several pages, asks questions your IT manager might answer in a second and your operations director might not understand at all, and the way you complete it determines what you pay and whether the cover holds at claim time. Businesses treating the cyber insurance questionnaire as a box-ticking exercise often discover, at the worst possible moment, that the answers they gave created a coverage problem nobody anticipated.
What is a cyber insurance questionnaire?
A cyber insurance questionnaire is the underwriter's tool for measuring how well your business protects its systems, data, and people before a quote is offered. It maps your security controls, your incident response capability, and your exposure to third-party and regulatory risk. The answers set your risk profile and, by extension, your premium, your excess, and what the policy will and won't cover.
Key Takeaways
- The questionnaire is a legal document. Inaccurate answers can void the policy at claim time, regardless of whether the inaccuracy was deliberate.
- Insurers place multi-factor authentication, endpoint protection, and offline backups above almost every other control. Without them, cover may be declined or carry significant sub-limits.
- South African businesses face regulatory exposure under POPIA, and insurers are asking about compliance directly. A weak POPIA posture affects your risk rating.
- The questions have become more technical since 2021. Businesses without an IT provider or a documented security framework struggle to answer them accurately.
- Completing the questionnaire honestly, even where the answers reveal gaps, is the foundation the rest of the cover rests on.
Why underwriters treat the questionnaire as a risk map

Cyber underwriters can't inspect your server room the way a fire assessor walks a factory floor. The questionnaire is the substitute, and insurers use the answers to build a picture of how an attack would likely unfold and how contained the damage would be. The global cyber insurance market reached approximately fifteen billion US dollars in 2024, and that growth has made underwriters considerably more precise about what they will and won't accept at what price.
The academic literature on cyber risk assessment confirms the problem underwriters are solving: consistent points of reference are hard to establish, and even when the same risk assessment standard is applied, two insurers can reach materially different conclusions about the same business. The questionnaire is an attempt to make the assessment comparable across thousands of applicants. Your answers tell the underwriter how a ransomware attack would play out if it landed on your network today. Questions follow a recognisable pattern across most markets: authentication, access controls, backup integrity, patch management, staff training, and incident response.
South African insurers have been attentive to this risk class since the pandemic period, when digital adoption accelerated faster than security frameworks could follow. The SARB's own analysis of financial system resilience specifically identified cyber incidents, data breaches, identity theft, ransomware, and denial-of-service events, as material concerns for regulators. That regulatory attention has since flowed into underwriting practice.
Authentication and access controls: the questions carrying the most weight
The single question reshaping cyber cover more than any other is the one about multi-factor authentication. Multi-factor authentication, or MFA, means logging into a system requires two separate proofs of identity: the password you know and a code sent to a device you hold. Without it, a stolen password is a stolen key. With it, the stolen password is useless without the second factor.
Insurers ask about MFA for email, for remote access tools, for administrator accounts, and for any system touching financial data or personal information. If your answers show MFA is absent on administrator accounts or on your remote desktop access (the route attackers use most often), underwriters typically either decline the submission or apply sub-limits rendering the cover largely academic. The FSCA's own cybersecurity risk guidance names multi-factor authentication as a baseline mitigation measure, alongside cyber insurance and employee training. The regulator and the insurer are pointing at the same control.
Related questions cover privileged access management: how many people can make administrator-level changes to your systems, and whether those accounts are separated from everyday user accounts. A business where the same login used to check email can also reconfigure the firewall is one where a single phishing click creates a very large problem.
Backup and recovery: what insurers need to know before quoting ransomware cover
Ransomware cover is the section of a cyber policy paying for lost income and the cost of restoring systems after an attacker encrypts your files and demands payment. Insurers quote it cautiously, because the claim cost is high and the outcome depends almost entirely on whether you can recover without paying. Your backup answers decide how the underwriter treats that risk.
The questions are specific. Do you take backups? How often? Where are they stored? Are they tested? And the one catching businesses out most often: are the backups connected to the same network as the primary systems? A backup drive sitting on the same server it is backing up gets encrypted in the same attack. An offline backup, stored separately and tested quarterly, is the difference between a recovery taking days and one taking months.
Insurers also ask about your recovery time objective: how long your business can operate before a system outage becomes an existential problem. A professional services firm running on paper and phone calls for a week has a fundamentally different risk profile from a logistics business whose tracking, invoicing, and dispatch systems are all cloud-dependent. The indemnity period (the number of months the business interruption section of a cyber policy will pay) is set partly from your answer to that question.
Patch management and end-of-life software: the questions about what you haven't fixed
Patch management is the process of applying security updates to operating systems, applications, and firmware as vendors release them. The window between a vendor publishing a patch and an attacker weaponising the vulnerability it closes has shortened considerably. Insurers ask about your patching cycle because an unpatched system is a known open door.
The questionnaire typically asks how long after release you apply critical patches, who is responsible for the process, and whether patching is tracked and documented. Answers describing an informal or ad hoc process ("IT handles it when they get to it") read to an underwriter as a gap, not a process.
End-of-life software is a related and often more uncomfortable question. End-of-life software is any operating system or application the vendor no longer supports or patches. Windows 7, for example, stopped receiving security updates in January 2020. A business still running it has a system permanently without patches, because no further patches exist. Insurers ask directly whether end-of-life software is present in your environment, and an honest "yes" without a compensating control (network isolation, or an active migration plan) will affect your terms. Many South African SMEs are running end-of-life software on machines they haven't prioritised for replacement, and the questionnaire is designed to surface exactly that.
Cyber security control comparison by insurer risk weighting
| Control | Insurer weighting | Effect of absence |
|---|---|---|
| Multi-factor authentication | Critical | Likely decline or heavy sub-limit |
| Offline tested backups | Critical | Ransomware cover restricted |
| Patch management process | High | Premium loading |
| End-of-life software | High | Exclusion or sub-limit |
| Email security filtering | Medium | Loading applied |
| Incident response plan | Medium | Affects business interruption terms |
| Staff security training | Medium | Premium credit where present |
Data handling, POPIA compliance, and third-party exposure

The Protection of Personal Information Act (POPIA) is South Africa's data privacy legislation. It sets obligations for how businesses collect, store, process, and protect personal information, and it creates regulatory liability when a breach occurs. The Information Regulator can impose administrative fines, and affected individuals have the right to bring civil claims. Insurers ask about POPIA compliance because it determines the size of the regulatory and third-party liability exposure they're agreeing to cover.
The questions in this section ask what categories of personal information you hold, how many records, where they are stored, who has access, and whether you've completed a POPIA compliance assessment. They also ask about third-party processors: suppliers, cloud providers, or payroll bureaus handling personal data on your behalf. Your liability for a breach at a third party processing your data on your instructions doesn't disappear because the breach happened on their systems.
The Prudential Authority's cyber resilience findings underline effective collaboration and information sharing between businesses and their service providers as a key factor in improving overall cybersecurity outcomes. The questionnaire is, in part, asking whether your third-party relationships have been assessed with the same rigour as your internal controls.
Incident response: what your plan on paper means to an underwriter
An incident response plan is a documented procedure your business follows when a cyber incident is detected. It names who is responsible for each step, who authorises the decision to notify the Information Regulator or affected individuals, who communicates with clients, and who engages the insurer. In a well-run business it reads like a plan nobody ever wants to use.
Insurers ask whether the plan exists, when it was last tested, and whether staff have been trained against it. The question is consequential because the cost of a cyber incident escalates with every hour of unco-ordinated response. A business discovering a breach on a Friday and spending the weekend deciding who is in charge pays more in business interruption costs than one activating a practised procedure within the hour.
One of the largest players in the global cyber insurance market has acknowledged directly questionnaires often ask the wrong questions, receive incomplete answers, and are sometimes out of date before they're even finalised. The more useful signal, underwriters now say, is the incident response section: a business with a tested plan and trained staff demonstrates a culture of preparedness the technical controls alone can't show. If your plan exists only as a document nobody has read, the questionnaire is a good moment to change that.
The EDUCAUSE research on cyber insurance market cycles notes insurer appetite shifts as loss experience accumulates. In a hardening market, businesses with documented and tested response plans hold a meaningful advantage in coverage availability and premium.
Staff training and the human factor
The last major section of most questionnaires asks about security awareness training: whether staff receive it, how often, and whether phishing simulation exercises are run. The reason is straightforward: most successful cyberattacks begin with a human action, not a technical failure. A staff member clicking a convincing phishing link and entering their credentials has opened the door to a network attack no firewall prevented, because the firewall was never in the way.
Insurers regard training not as a nice-to-have but as a compensating control. A business with weaker technical controls but strong, documented training is in a better position than one with good tools and no culture of awareness. The questions ask about frequency, format, and whether training is tracked. "We remind staff occasionally" is not an answer improving your position. Annual documented training with a record of completion is. The Heimdal Security data on the global cyber insurance market reflects businesses with demonstrable security cultures finding better terms than those relying on technology alone.
The questionnaire is an audit you can prepare for

The cyber insurance questionnaire sits at the intersection of your IT posture and your legal exposure. Fill it in accurately, because a material non-disclosure (an answer misrepresenting your actual controls) is grounds for repudiation at claim time. The policy is a contract, and the questionnaire is part of the basis on which it was offered. Fill it in strategically, because knowing what underwriters weight most heavily tells you where to invest before you apply: MFA on administrator accounts, offline tested backups, a documented patching process, and a written incident response plan are the four controls shifting the outcome most.
You shouldn't have to navigate a cyber insurance questionnaire alone, hoping the answers hold up when a claim comes in. With Mont Blanc Financial Services you won't.
Contact Mont Blanc Financial Services to review your current cyber security posture, complete the questionnaire accurately, and place cover reflecting your actual risk rather than your best guess at it.
South African businesses carry more cyber exposure than most of their insurance programmes reflect, and the questionnaire is the clearest view into that gap. A few of the questions coming up most often deserve a direct answer.
Frequently Asked Questions
What is the experience of the cyber insurer with cyber insurance questionnaires, and what is their track record for paying claims?
Track record is consequential because cyber insurance is a relatively young product line, and not all insurers writing it have the claims history or the technical expertise to assess complex losses fairly. When evaluating an insurer, look for evidence of paid claims in your size category, the insurer's Lloyd's syndicate or underwriting capacity, and whether they have in-house incident response support or rely entirely on panel providers. In South Africa, an FSP-licensed insurer underwriting cyber cover must meet Prudential Authority capital adequacy requirements, providing a baseline of financial soundness. The practical test is whether the insurer has a dedicated cyber claims team and a track record of settling ransomware and data breach claims without extended disputes. Your broker should be able to provide loss ratio data and claims examples for the specific policy and insurer being recommended. A policy from an insurer without genuine cyber claims experience is a cheaper document than it is a meaningful transfer of risk, and the questionnaire you complete for that insurer may have less technical rigour than the cover ultimately requires.
Do you have a firewall, and what does that question actually mean on the cyber insurance questionnaire?
A firewall is a system monitoring and filtering the traffic entering and leaving your network, blocking connections not meeting defined rules. When an insurer asks whether you have a firewall, they're asking whether there is a barrier between your internal systems and the internet, and whether it's actively managed rather than running on factory settings. The question often goes further: is the firewall a dedicated network appliance or a software firewall on individual machines, is it monitored, and is it updated? A domestic-grade router with its default settings is technically a firewall but not the answer an underwriter wants to see for a business handling payment data or personal records. The honest answer should reflect what you have: the make and model of your network firewall, whether a managed IT provider monitors it, and when it last received a firmware update. Where the answer reveals a gap, a documented remediation plan is a more useful response than an optimistic approximation.
What is your patching process, and why does the cyber insurance questionnaire ask for so much detail?
Insurers ask about your patching process because unpatched software is the mechanism behind a significant share of successful attacks. The questionnaire wants to know who owns the process, how quickly critical patches are applied after release, whether the process is documented, and whether exceptions are tracked. The detail is consequential because "we patch regularly" without specifics tells an underwriter nothing about whether critical vulnerabilities sat open for weeks while the person responsible was on leave. A credible answer names the person or provider responsible, describes the cycle (for example, critical patches within seventy-two hours, routine patches within thirty days), and confirms patches are tested before deployment in environments where untested updates could disrupt operations. If your patching is managed by an external IT provider, their service-level agreement on patch timing is the document answering the question. If you don't have one, the questionnaire is a good reason to establish one before the next renewal.
Do you have any end-of-life software in your environment, and what should I do if the answer is yes?
End-of-life software is any system the vendor no longer supports, which in practice means it no longer receives security patches. Running it creates a permanent vulnerability growing more exposed over time as new attacks are built around the known weaknesses. If your environment includes end-of-life software, the honest answer is yes, with a description of what it is, why it's still in use, and what compensating controls are in place. Network isolation (placing the affected machine on a segment of the network unable to reach the internet or sensitive internal systems) is the most common compensating control, and one underwriters recognise. An active migration plan with a target completion date is also a meaningful signal. Underwriters respond poorly to an undisclosed yes: if end-of-life software is present and not disclosed, and an attack exploits the known vulnerability, the insurer has grounds to argue the risk was misrepresented. The questionnaire is not the place to guess or to omit.

Nicola Iozzo
Founder & CEO, Mont Blanc Financial Services
Nicola has spent his career reading the policy wording most people skip, and writes here so you don't discover at claim stage what page 14 meant.
Everything on this blog is written to inform and educate. It is for information only. Nothing here is professional legal, financial, or technical advice. If you are making a significant business decision, speak to a qualified professional first. Mont Blanc Financial Services works hard to keep this content accurate and current, but is not liable for decisions made based on what you read here.
Mont Blanc Financial Services (PTY) Ltd. is an authorised financial services provider. FSP 8271


