Underwriting Questionnaire
An underwriting questionnaire is a set of questions an insurer asks a business before deciding whether to offer cyber insurance and on what terms. It gathers information about the organization's security practices, technology, and past incidents so the insurer can assess the risk and set pricing. The answers a business gives can affect not only whether it gets coverage but also whether a later claim is honored, since inaccurate answers may give the insurer grounds to dispute the policy.
A structured information-gathering document used by insurers or their agents to evaluate a prospective or renewing insured's cyber risk profile and determine acceptability, terms, conditions, sublimits, retentions, and premium. It typically solicits details on security controls (for example, multi-factor authentication, endpoint detection and response, backup practices, and patch management), governance and compliance posture, network and data environment, prior claims and incident history, and revenue or exposure metrics. The questionnaire commonly functions as a representation or warranty forming part of the basis of the contract; depending on the specific policy wording and applicable jurisdiction, material misrepresentation or omission may expose the insured to rescission, coverage disputes, or the application of failure-to-maintain-standards exclusions. It should be distinguished from resilience assessment tools and security control frameworks (such as NIST CSF or ISO 22301): although a questionnaire may reference such controls, it is an insurance underwriting instrument rather than a resilience measurement standard, and completing it does not itself reduce the likelihood of an incident.
Why it matters
The underwriting questionnaire is often the single most consequential document a business completes in the cyber insurance process, because it shapes both the terms of coverage offered and the insurer's later willingness to pay a claim. In many policies the questionnaire functions as a representation or warranty that forms part of the basis of the contract, which means the answers are not merely informational, they are contractual assertions. Depending on the specific policy wording and the applicable jurisdiction, a material misrepresentation or omission may give the insurer grounds to dispute or rescind coverage, or to invoke failure-to-maintain-standards exclusions if the insured did not in fact operate the controls it attested to.
This creates a distinct and sometimes underappreciated exposure: an organization can hold a policy it believes covers a loss, only to face a coverage dispute at claim time over the accuracy of its application answers. Because insurers increasingly ask granular, verifiable questions about controls such as multi-factor authentication, endpoint detection and response, backup practices, and patch management, discrepancies between what was represented and what was actually in place can become central to whether a first-party loss (such as business interruption or data restoration) or a third-party liability claim is honored.
It is important to recognize the boundary of what the questionnaire does and does not do. Completing it accurately supports the risk-transfer function of insurance, but it does not reduce the likelihood of an incident and is not itself a resilience measure. Although a questionnaire may reference recognized control frameworks, it is an underwriting instrument, not a resilience measurement standard, and attesting to a control is not the same as maintaining it under real-world conditions.
Who it's relevant to
Inside Underwriting Questionnaire
Common questions
Answers to the questions practitioners most commonly ask about Underwriting Questionnaire.
