What the questionnaire is really asking
Behind the wording sit a handful of controls that decide whether a claim ever happens. Does a stolen password get somebody in, or does a second step stop them? If files are encrypted, is there a backup the attacker could not reach, and has anybody restored from it? Are the computers patched, and is something watching them? Who has administrator rights, and how many of those accounts are there? Is there a written plan naming who does what on the bad day, and would you know within hours rather than weeks?
The insurer is pricing the odds that they pay out. Every question maps to a way businesses of your size actually lose money.
Answer from evidence
For every yes, know where the proof is before you tick it. A report showing the second login step is on for every account, including the owner’s and any account a program uses. The date and result of the last restore test, with the file that came back. A written list of who holds administrator rights. A patch report showing what is current and what is behind. A one-page incident plan with names and phone numbers on it.
Keep the evidence with the completed form. If a claim ever happens, the questions get asked again by somebody who is far less relaxed about the answers.
The gaps that show up most
The second login step is on for the staff and off for the owner, or off for the shared mailbox, or off for the account that runs a program at night. Backups live in the same account as the data, so one stolen password reaches both. Nobody can say who has administrator rights. The plan exists in one person’s head. Remote access is open to the whole internet because it was quicker that way during a busy month.
Every one of those has a fix that costs a morning. Finding them because the insurer asked is the cheap version of finding them.
Write “no” where the answer is no
A yes you cannot evidence is a misrepresentation, and it is the sentence a claim gets refused on. Insurers see honest forms constantly, and “not yet, in place by the end of next month” is an answer they know how to price.
Treat the questionnaire as a work list as well. Somebody who prices risk for a living has just handed you a ranked set of priorities for your own business, at no charge.
What we do here
We go through the form with you and answer it from evidence, gathering the proof as we go. Where the honest answer is no, we say no and put a date beside it. We hold no security certifications and the form says exactly that, because a claim is a poor place to discover that a supplier was optimistic on your behalf.
You keep a written list of the protections actually in place, in plain words and with our name on it, which is also what your regulator or your privacy officer will ask for.