Skip to main content
Language Translation
  Close Menu

Cyber Insurance Underwriting

When it comes to underwriting for a cyber insurance policy, there are a wide range of reasonable controls, across 18 categories, that can be implemented -- ranging from hardware/software inventory and security monitoring to managing back-ups and encryption.

Within each category, there are sample questions that are typical for a cybersecurity insurance application along with applicable resources that will help you.

Does the Applicant track hardware assets deployed across your organization?

Does the Applicant track software assets deployed across your organization?

Does the Applicant have a listing of all personal, sensitive, and/or private information, and its location in your systems?

Does the Applicant document and understand the sensitivity of its data?

Does the Applicant continuously monitor its network, all endpoint devices and assets within our network to detect and respond to attempted unauthorized access or unusual activity?

Does the Applicant retain records (or logs) of that monitoring and any response measures undertaken and review those records often?

Does the Applicant use a SIEM monitored 24x7 by a SOC?

Does the Applicant use any software or hardware that has been officially retired (“end of life’) by the manufacturer? If end of life/support assets are in use, have they been segmented from the rest of the network and disconnected from the internet?

Does the Applicant require use of firewalls on workstations?

https://www.crowdstrike.com/en-us/cybersecurity-101/data-protection/data-loss-prevention-dlp/

Does the Applicant require use of AV on workstations?

https://www.sans.org/information-security-policy/ (Anti-Virus Guidelines)

Does the Applicant have third party software protecting its network (e.g., antivirus, encryption, firewalls, etc.)

Does the Applicant tag external emails to alert employees that the message originated outside the organization?

Does the Applicant use web filtering to block access to malicious websites?

Does the Applicant run a vulnerability management tool?

Does the Applicant use advanced endpoint detection and response (EDR) tool on all endpoints?

Does the Applicant continuously monitor its network, all endpoint devices and assets within our network to detect and respond to
attempted unauthorized access or unusual activity?

Does the Applicant verify all vendor and supplier bank accounts by a direct call to the receiving bank,
prior to accounts being established in the accounts payable system?

If the Applicant’s website, computer system, or telephone system requests or captures Payment Card information, has the Applicant self-attested to PCI-compliance in the last twelve months?

If the Applicant’s website, computer system, or telephone system requests or captures medical records or personal health insurance, is the Applicant compliance with HIPAA and HITECH Act?

Does the Applicant have a written Incident Response Plan?

Does the Applicant have a written Data Breach Response Plan?

Does the Applicant have a written Disaster Recovery and Business Continuity Plan?

Does the Applicant test your Disaster Recovery and Business Continuity Plan annually?

Does the Applicant limit access to those required to perform a job?

Does the Applicant regularly perform full and incremental backups?

Does the Applicant require Multi-Factor Authentication (MFA) for access to backup environment?

Does the Applicant test backups for restorability?

Does the Applicant encrypt personal data, sensitive and confidential information stored on your systems and networks?

Does the Applicant encrypt personal data, sensitive and confidential information in transit?