Insights/Business-Educational
How to Prepare for a Cyber Insurance Audit: A Checklist for Enterprises
Published
Reading time2 minutes
FromTriad ICS Research

Underwriters now ask detailed control questions. Answer them accurately, or risk a claim being contested.
Cyber insurance proposal forms used to be a couple of pages. Today, underwriters send detailed questionnaires and sometimes run their own external scans before quoting. The answers you give shape your premium and cover, and inaccurate answers can become a problem at claim time. Treat the process as an audit.
Controls underwriters commonly ask about
- Multi-factor authentication: for email, remote access, cloud consoles and privileged accounts. This is often the first question, and a “no” can end the conversation.
- Endpoint detection and response on servers and laptops, not only traditional antivirus.
- Backups: frequency, whether a copy is offline or immutable, and when you last tested a full restore.
- Patching: how quickly critical vulnerabilities on internet-facing systems are fixed.
- Privileged access: separate admin accounts, and how many people hold domain or cloud administrator rights.
- Email security: SPF, DKIM and DMARC, plus filtering for malicious attachments and links.
- Incident response: a written plan, named roles, and whether it has been exercised.
- Awareness training and phishing simulations for staff.
- Vendor risk: how you assess third parties that hold your data or connect to your network.
Preparing the evidence
- Collect screenshots or exports that prove each control: MFA enrolment reports, EDR coverage, backup logs.
- Run your own external scan first; fix exposed services before the insurer finds them.
- Check that answers are true for the whole organisation, not just head office.
- Keep a record of what you submitted; it effectively becomes part of your policy.
Understand the policy, not just the premium
- What is covered: first-party costs (forensics, restoration, business interruption) and third-party liability.
- What is excluded, and what conditions apply (for example, requirements to maintain MFA).
- Who you must call first, and whether you must use the insurer’s panel of responders.
- How the policy interacts with regulatory obligations such as CERT-In’s six-hour reporting requirement.
A useful side effect
Organisations that prepare seriously for underwriting often find their largest gaps in the process. Insurance transfers part of the financial risk; the controls behind the questionnaire are what actually reduce it.
This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.