Skip to main content
Category: Underwriting & Risk Selection

Underwriting Questionnaire

Also known as: Cyber Insurance Application, Proposal Form, Cyber Risk Questionnaire
Simply put

An underwriting questionnaire is a set of questions an insurer asks a business before deciding whether to offer cyber insurance and on what terms. It gathers information about the organization's security practices, technology, and past incidents so the insurer can assess the risk and set pricing. The answers a business gives can affect not only whether it gets coverage but also whether a later claim is honored, since inaccurate answers may give the insurer grounds to dispute the policy.

Formal definition

A structured information-gathering document used by insurers or their agents to evaluate a prospective or renewing insured's cyber risk profile and determine acceptability, terms, conditions, sublimits, retentions, and premium. It typically solicits details on security controls (for example, multi-factor authentication, endpoint detection and response, backup practices, and patch management), governance and compliance posture, network and data environment, prior claims and incident history, and revenue or exposure metrics. The questionnaire commonly functions as a representation or warranty forming part of the basis of the contract; depending on the specific policy wording and applicable jurisdiction, material misrepresentation or omission may expose the insured to rescission, coverage disputes, or the application of failure-to-maintain-standards exclusions. It should be distinguished from resilience assessment tools and security control frameworks (such as NIST CSF or ISO 22301): although a questionnaire may reference such controls, it is an insurance underwriting instrument rather than a resilience measurement standard, and completing it does not itself reduce the likelihood of an incident.

Why it matters

The underwriting questionnaire is often the single most consequential document a business completes in the cyber insurance process, because it shapes both the terms of coverage offered and the insurer's later willingness to pay a claim. In many policies the questionnaire functions as a representation or warranty that forms part of the basis of the contract, which means the answers are not merely informational, they are contractual assertions. Depending on the specific policy wording and the applicable jurisdiction, a material misrepresentation or omission may give the insurer grounds to dispute or rescind coverage, or to invoke failure-to-maintain-standards exclusions if the insured did not in fact operate the controls it attested to.

This creates a distinct and sometimes underappreciated exposure: an organization can hold a policy it believes covers a loss, only to face a coverage dispute at claim time over the accuracy of its application answers. Because insurers increasingly ask granular, verifiable questions about controls such as multi-factor authentication, endpoint detection and response, backup practices, and patch management, discrepancies between what was represented and what was actually in place can become central to whether a first-party loss (such as business interruption or data restoration) or a third-party liability claim is honored.

It is important to recognize the boundary of what the questionnaire does and does not do. Completing it accurately supports the risk-transfer function of insurance, but it does not reduce the likelihood of an incident and is not itself a resilience measure. Although a questionnaire may reference recognized control frameworks, it is an underwriting instrument, not a resilience measurement standard, and attesting to a control is not the same as maintaining it under real-world conditions.

Who it's relevant to

Risk managers and compliance professionals
They typically coordinate the accurate completion of the questionnaire, gathering input from IT, security, and legal functions. Because answers can operate as contractual representations, they should ensure attestations reflect controls that are actually in place and maintained, and retain records supporting each response to reduce the risk of a later coverage dispute.
Insurance brokers
Brokers guide clients through the application, help interpret how questions map to the client's environment, and advise on the downstream consequences of the answers for terms, pricing, and potential exclusions. They are positioned to flag where imprecise or optimistic answers could jeopardize a future claim.
Underwriters
Underwriters rely on the questionnaire to assess the risk and set acceptability, premium, sublimits, retentions, and conditions. The document is their primary structured basis for pricing and for establishing the representations that may later be tested if a claim arises.
Chief information security officers and security teams
CISOs and their teams supply the technical substance behind answers on controls such as MFA, EDR, backups, and patch management. They should be aware that an attestation may be treated as a warranty, so gaps between stated and actual control operation carry insurance as well as security implications, though the questionnaire measures insurability, not the organization's resilience.
Legal counsel
Legal advisors review how questionnaire responses function within the specific policy wording and jurisdiction, including exposure to rescission, coverage disputes, or failure-to-maintain-standards exclusions arising from material misrepresentation or omission.

Inside Underwriting Questionnaire

Organizational and Exposure Profile
Baseline information about the applicant, typically including industry sector, revenue, number of records held, and the nature of data processed. This helps the underwriter gauge the scale and category of exposure rather than establishing any coverage terms directly.
Security Controls Attestation
Questions about technical and administrative controls such as multi-factor authentication, endpoint detection and response, encryption, privileged access management, and patching cadence. These reference security concepts (controls) that are distinct from policy terms; answers may inform pricing, eligibility, and, in some cases, conditions precedent or exclusions in the resulting policy.
Governance and Framework Alignment
Questions about alignment with recognized frameworks or standards (for example NIST CSF or ISO-family standards). Alignment is a resilience or security governance indicator and is not itself a coverage term; it does not by itself determine what a policy pays.
Business Continuity and Recovery Posture
Questions addressing backup practices, disaster recovery arrangements, and continuity planning, which may touch on recovery objectives such as RTO and RPO. These are resilience metrics used to assess likelihood and potential severity of loss, and should not be confused with policy waiting periods or business interruption sublimits.
Incident History and Prior Claims
Disclosure of past incidents, breaches, regulatory actions, or prior claims. This section informs the risk assessment and, subject to the specific wording, may relate to conditions or exclusions concerning known circumstances or prior acts.
Third-Party and Supply Chain Dependencies
Questions about reliance on vendors, managed service providers, and critical software dependencies, used to evaluate aggregation and dependent-business-interruption exposure.
Declarations, Warranties, and Signatory Attestation
The applicant's affirmation, often by an authorized officer, that responses are accurate. Depending on policy wording and jurisdiction, material inaccuracies may affect the insurer's ability to rely on the application, though the precise legal effect varies by regime and form.

Common questions

Answers to the questions practitioners most commonly ask about Underwriting Questionnaire.

Does completing the underwriting questionnaire accurately guarantee my claim will be paid?
No. The questionnaire informs the underwriter's decision to offer terms and price the risk, but it does not by itself determine coverage. Whether a specific loss is covered depends on the policy wording, endorsements, exclusions, conditions precedent, and applicable jurisdiction. Accurate completion matters chiefly because material misrepresentations or omissions can give the insurer grounds to rescind the policy or deny a claim, subject to the specific wording and governing law.
Is the underwriting questionnaire a measure of my organization's resilience?
Not in the resilience-engineering sense. The questionnaire is a risk-assessment and risk-transfer instrument used to evaluate and price the risk being transferred to the insurer. It may ask about controls, frameworks, and recovery objectives such as RTO and RPO, but reporting those attributes does not reduce the likelihood or impact of an incident and is not a substitute for actual business continuity, disaster recovery, or incident response capability. Purchasing insurance is risk transfer, distinct from risk mitigation.
Who inside the organization should complete the underwriting questionnaire?
Because questionnaires span both security and insurance concepts, responses typically require input from multiple functions rather than a single owner. Technical questions about controls, frameworks, backups, and recovery objectives generally need the CISO or security team, while questions about revenue, prior claims, and legal or regulatory posture often involve risk management, finance, and legal or compliance. A coordinating owner, frequently the risk manager working with the broker, helps ensure answers are consistent and accurate across sections.
How should I answer a control question when a control is only partially deployed?
Answer factually and avoid overstating deployment. If a control such as multi-factor authentication or endpoint detection covers only part of the environment, describe the actual scope rather than answering as though coverage were complete, since a discrepancy discovered after a loss can create grounds for the insurer to challenge the policy under the specific wording and applicable law. Where a questionnaire offers limited response options, it is common to add a clarifying note or supporting narrative through the broker.
What should I do if my controls change after I submit the questionnaire but before the policy binds or renews?
Material changes to the information provided may need to be disclosed, because underwriting relies on the accuracy of representations at the point terms are offered and bound. The relevant duty and its consequences vary with the policy conditions and the applicable jurisdiction. As a practical matter, communicate significant changes to your broker promptly so any updated information can be reflected in the underwriting record and the terms offered.
How can I keep questionnaire responses consistent from year to year?
Retaining a dated copy of each submission, together with the supporting evidence and the internal contributors for each section, helps maintain consistency and lets you explain any changes at renewal. Where answers reference recovery objectives such as RTO and RPO or specific controls, keeping those definitions aligned with how your continuity and security teams actually use them reduces the risk of internally contradictory responses. This is administrative discipline, not a coverage determination, which remains subject to the policy wording.

Common misconceptions

Completing the questionnaire and obtaining a policy makes the organization resilient or reduces the likelihood of an incident.
The questionnaire supports risk transfer through insurance, which is distinct from risk mitigation. Insurance does not reduce the probability of an incident and does not by itself constitute resilience; the controls described in the questionnaire, not the policy, are what affect likelihood.
Attesting to a control or framework in the questionnaire guarantees that related losses will be covered.
Whether a given loss is covered depends on the full policy wording, endorsements, exclusions, and conditions precedent, and on jurisdiction. In some policies, an attested control may function as a condition or relate to a failure-to-maintain-standards exclusion, so an attestation can affect coverage in either direction subject to the specific wording.
The questionnaire covers both the organization's own losses and its liability to others in the same way, so distinctions do not matter at application.
First-party exposures (such as business interruption, data restoration, and cyber extortion) and third-party exposures (such as privacy liability and regulatory defense) are assessed differently, and the questions relevant to each differ. Conflating them can lead to gaps between what the applicant expects and what the resulting coverage addresses.

Best practices

Answer every question against verifiable evidence rather than aspiration, because inaccurate attestations may, depending on wording and jurisdiction, affect the insurer's ability to rely on the application.
Involve both security or resilience staff and risk or insurance staff when completing the form, so that controls, framework alignment, and recovery objectives are described accurately and their relationship to potential policy conditions is understood.
Confirm which attested controls the insurer may treat as conditions precedent or link to exclusions, and review the corresponding policy wording rather than assuming attestation alone secures coverage.
Distinguish resilience metrics such as RTO and RPO in continuity answers from any policy waiting periods, retentions, or sublimits, and do not treat one as a substitute for the other.
Document the state of controls as of the application date and note material changes before renewal, since the questionnaire reflects a point-in-time representation.
Have an authorized signatory review and retain a dated copy of the completed questionnaire and supporting evidence to support future placement, renewal, and any claim process.
Promotional banner for the Pentest Readiness checklist download