By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity | Serving organizations across Canada, the US, and beyond | Last updated August 17, 2026
Quick answer: The cyber insurance underwriting questionnaire is a legal document, not a form to be completed quickly and submitted. Every response is a representation that the carrier relies on to decide whether to provide coverage and on what terms. Inaccurate answers, even unintentionally inaccurate ones, can provide grounds for claim denial when the organization most needs coverage. Completing the questionnaire accurately requires understanding what each question is technically asking, gathering evidence that supports the response, and identifying where gaps exist that should be disclosed rather than obscured.
Key Takeaways
- Cyber insurance underwriting questionnaires have grown dramatically in length and technical specificity. A questionnaire that once asked six high-level questions now routinely spans forty or more pages with detailed questions about specific control configurations, deployment percentages, and testing cadences.
- Many questionnaire questions are technically ambiguous and interpreted differently by different teams. A question asking whether MFA is deployed on all remote access systems means something different to an IT administrator, a CISO, and a business owner. Getting the interpretation right requires understanding what the underwriter is trying to assess, not just reading the question literally.
- The evidence behind the answer matters as much as the answer itself. Carriers are increasingly conducting technical validation of key control claims. At claim time, the forensic investigation will establish whether the controls represented in the questionnaire were actually deployed as described.
- Over-answering, providing more favorable responses than the actual control state warrants, is a post-claim risk. Under-answering, responding conservatively to avoid misrepresentation, can result in worse terms than the actual security posture warrants. Accurate, evidence-supported answers are the only approach that protects both the organization at claim time and the quality of coverage secured.
- Questionnaire responses can and should be reused across carriers when shopping the market. A well-documented set of responses with supporting evidence is an asset that reduces the burden of future renewals and supports accurate answers across multiple carrier submissions.
Why the Questionnaire Is More Consequential Than It Looks
A cyber insurance underwriting questionnaire looks like an application form. It functions as a legal document. The responses to the questionnaire form the basis of the representations on which the carrier agrees to provide coverage. The policy contains provisions, typically in the conditions or representations section, that tie the accuracy of the questionnaire responses to the validity of coverage. A material misrepresentation gives the carrier grounds to void the policy from the date of binding, deny a specific claim, or both, depending on the jurisdiction and the specific policy language. This is why the questionnaire is where the value of what a cyber policy actually covers is either protected or quietly undermined.
Most organizations completing underwriting questionnaires do not have legal or cybersecurity advisory support. The questionnaire is forwarded from the broker to IT, who fills in what they know, passes it to a business leader who signs off without reviewing the technical responses, and returns it to the broker by the deadline. This process is common and creates meaningful post-claim risk. The responses IT provides may be technically accurate from an IT perspective but not reflect what the underwriter’s question was actually asking for. The business leader who signs off typically cannot evaluate whether the technical responses are accurate or complete.
The Questions That Are Most Often Answered Incorrectly
MFA coverage percentage
The MFA question is the most consequential question on most questionnaires and the one most often answered inaccurately. The question typically asks something like: Is multi-factor authentication enforced for all remote access, all privileged access, and all cloud services? The technically accurate answer requires knowing whether MFA is enforced at the policy level (so that users cannot bypass it) or merely available for users who choose to enable it, whether there are any accounts or access paths that are excluded from the MFA policy, whether service accounts and break-glass accounts are covered or are exceptions, and whether the MFA requirement applies to all cloud consoles including those managed by the IT or security team directly. Answering yes to a broad MFA question when MFA is enabled in Microsoft 365 but not enforced on the VPN or not covering privileged access to cloud infrastructure is a common inaccuracy with material claim consequences, and it is why enforcement is best handled through identity and privileged access management rather than left to individual users.
Backup architecture
The backup question has evolved from a simple yes or no about whether backups exist to a multi-part question about backup architecture. Underwriters now commonly ask whether backups are maintained offline or in an air-gapped environment, whether backups use immutable storage that prevents modification or deletion, whether backup access requires separate credentials from the primary environment credentials, and whether restoration from backup has been tested within the past twelve months. Answering yes to the backup question based on the existence of a backup solution without verifying whether the backup architecture meets these specific requirements is a frequent source of inaccuracy. Many organizations that back up to a connected network share or a cloud storage account accessible with the same credentials as the primary environment do not meet current underwriting expectations for backup security.
EDR deployment scope
Endpoint detection and response questions ask about coverage across the entire endpoint fleet, not just the primary managed endpoints. The question is typically phrased to ask what percentage of endpoints have EDR deployed and whether there are any systems excluded from EDR coverage. Organizations that have deployed EDR on their standard workstation and server fleet but have not extended it to legacy systems, operational technology, or endpoints acquired through a recent merger or acquisition may answer the coverage percentage question inaccurately. The follow-up question about excluded systems is the one that catches partial deployments: answering 100% coverage on the percentage question and then disclosing excluded systems on the follow-up creates an inconsistency that underwriters notice.
Incident response plan testing
The incident response plan question asks not only whether a plan exists but whether it has been tested. The distinction between having a plan and having a tested plan matters to underwriters because an untested plan provides no operational assurance that the organization can actually execute its response when an incident occurs. Answering yes to a question about incident response plan testing based on an internal review of the plan document, rather than an actual tabletop exercise or simulation with the response team, is technically inaccurate in the way underwriters interpret the question. If the plan has never been exercised through a structured tabletop, the accurate answer to the testing question is no, and the submission should include context about when testing is planned.
How to Approach the Questionnaire Correctly
Treat each question as a technical assessment, not a form
Each question on the questionnaire is asking about a specific control or practice in a way that has a technically precise correct answer. Reading the question literally may not surface the correct interpretation. Working through the questionnaire with someone who understands both the technical substance of the questions and what underwriters are trying to assess with each one produces more accurate responses than forwarding the form to IT for completion. This is also where knowing the common cyber insurance denial reasons helps: the questions most often answered wrong are the same controls that most often trigger rejection or repricing.
Gather evidence before answering
The discipline of gathering evidence to support each response before answering has two benefits. It forces verification that the control claimed is actually in place as described, catching inaccuracies before they become claim risks. And it produces the evidence pack that underwriters are increasingly requesting alongside questionnaire submissions and that will be essential at claim time if coverage is disputed. Evidence for an MFA claim might include a screenshot of the conditional access policy configuration showing enforcement scope. Evidence for the backup claim might include the backup solution configuration and a test restoration record. Evidence for the incident response plan claim might include the plan document and the tabletop exercise attendance record and findings report.
Disclose gaps rather than obscuring them
When the honest answer to a questionnaire question reveals a control gap, the instinct is to answer in a way that minimizes the apparent gap to avoid adverse terms. This instinct creates post-claim risk that outweighs any benefit from the underwriting outcome. Carriers that discover at claim time that a material gap was not disclosed in the questionnaire have grounds to deny the claim. Accurate disclosure of a gap, accompanied by a documented remediation plan and timeline, is the approach that protects coverage at claim time. Some carriers will bind coverage with conditions requiring remediation of disclosed gaps; others will price the gap into the premium. Neither outcome is as bad as claim denial based on a misrepresentation discovered during forensic investigation.
Armour Cybersecurity’s Cyber Insurance Advisory team works through the questionnaire collaboratively with internal IT and security teams, drafting responses that are technically accurate, supported by evidence, and framed in the way that best reflects the organization’s actual posture. The pre-underwriting evidence pack produced by the engagement supports every response and is available for carrier review.
Frequently Asked Questions
How long does it take to complete a cyber insurance underwriting questionnaire properly?
A thorough, evidence-supported questionnaire completion for a mid-market organization typically takes two to four weeks when done properly. This includes the initial review of the questionnaire to understand the scope of questions, structured interviews with IT and security teams to gather accurate responses, evidence collection to support key claims, drafting of responses with internal team review and approval, and preparation of the supporting evidence pack. Organizations that attempt to complete a forty-page underwriting questionnaire in a weekend by forwarding it to IT for rapid completion are not completing it properly, even if the responses feel accurate. The advisory engagement runs the questionnaire process within its standard two to four week engagement timeline.
Can we use the same questionnaire responses for multiple carriers?
Yes, and this is one of the efficiency benefits of completing the questionnaire thoroughly with evidence support. A well-documented set of responses with supporting evidence can be adapted for submission to multiple carriers when shopping the market, with adjustments for carrier-specific formatting or additional questions. The core responses and evidence pack remain consistent across submissions. This reusability also extends to annual renewal: responses from the current year form the baseline for the renewal questionnaire, requiring only updates to reflect changes in the security environment rather than starting from scratch each year.
What is a supplemental questionnaire and when does it appear?
A supplemental questionnaire is an additional set of questions that a carrier sends after reviewing the initial application. Supplemental questions typically target specific areas where the initial responses were ambiguous, indicated potential gaps, or require additional information before the carrier can make an underwriting decision. Receiving a supplemental questionnaire is not a rejection; it is a request for clarification that is a standard part of the underwriting process for many applications. Responding to supplemental questions accurately and promptly, with supporting evidence for any claims being clarified, is the fastest path through the underwriting process. The advisory team supports supplemental questionnaire responses as part of the engagement.
Does our broker fill out the questionnaire for us?
Brokers vary in how much support they provide with questionnaire completion. Most brokers are insurance professionals rather than cybersecurity practitioners, and the technical questions on current underwriting questionnaires require cybersecurity expertise to answer accurately. Some brokers provide guidance on question interpretation and facilitate the process; few have the technical capability to assess the organization’s security controls and draft accurate, evidence-supported responses. The gap between what brokers can support and what accurate questionnaire completion requires is the primary driver of organizations seeking independent cybersecurity advisory support for the underwriting process.
What happens if our security environment changes after we submit the questionnaire?
Most cyber insurance policies require the policyholder to notify the carrier of material changes in the security environment during the policy period. What constitutes a material change varies by policy, but typically includes significant changes to the technology infrastructure, discovery of a previously unknown security incident, changes in business scope that significantly alter the risk profile, and failure of a control that was represented as being in place during underwriting. Reviewing the notification obligations in the policy conditions and following them when material changes occur is an important ongoing obligation that reduces post-claim dispute risk.
The Bottom Line
The cyber insurance underwriting questionnaire is a legal document, and every answer is a representation the carrier can hold you to at claim time. The questions most often answered wrong are the high-stakes ones: whether MFA is truly enforced everywhere, whether backups are immutable and separated, what percentage of endpoints actually run EDR, and whether the incident response plan has been tested rather than just written. Answer each as a technical assessment, gather the evidence before you answer, and disclose gaps with a remediation plan rather than obscuring them. A cyber insurance advisory engagement runs the questionnaire with your team and builds the evidence pack that stands up both to underwriting and to a future claim.
About the author
David Chernitzky is Co-Founder and CEO of Armour Cybersecurity, a Toronto-based cybersecurity firm founded by military intelligence veterans and advised by senior leaders from PwC, KPMG, Deloitte, EY, and Mandiant. Armour serves more than 260 organizations across 52-plus industries, including finance, healthcare, technology, energy, legal, and government, with a 97 percent client retention rate.



