Our insurance company is asking about our computer security. What do we tell them?

The short answer

Insurers ask a short list: does every person use a second step to log in, are backups kept out of reach and tested, is there a written plan for the day something is locked, and who holds administrator access. Answer from evidence, and write “no” where the answer is no. A hopeful yes is the answer that costs you the claim.

A support desk: a telephone headset resting on a paper notepad beside a pen and a mug

What the questionnaire is really asking

Behind the wording sit a handful of controls that decide whether a claim ever happens. Does a stolen password get somebody in, or does a second step stop them? If files are encrypted, is there a backup the attacker could not reach, and has anybody restored from it? Are the computers patched, and is something watching them? Who has administrator rights, and how many of those accounts are there? Is there a written plan naming who does what on the bad day, and would you know within hours rather than weeks?

The insurer is pricing the odds that they pay out. Every question maps to a way businesses of your size actually lose money.

Answer from evidence

For every yes, know where the proof is before you tick it. A report showing the second login step is on for every account, including the owner’s and any account a program uses. The date and result of the last restore test, with the file that came back. A written list of who holds administrator rights. A patch report showing what is current and what is behind. A one-page incident plan with names and phone numbers on it.

Keep the evidence with the completed form. If a claim ever happens, the questions get asked again by somebody who is far less relaxed about the answers.

The gaps that show up most

The second login step is on for the staff and off for the owner, or off for the shared mailbox, or off for the account that runs a program at night. Backups live in the same account as the data, so one stolen password reaches both. Nobody can say who has administrator rights. The plan exists in one person’s head. Remote access is open to the whole internet because it was quicker that way during a busy month.

Every one of those has a fix that costs a morning. Finding them because the insurer asked is the cheap version of finding them.

Write “no” where the answer is no

A yes you cannot evidence is a misrepresentation, and it is the sentence a claim gets refused on. Insurers see honest forms constantly, and “not yet, in place by the end of next month” is an answer they know how to price.

Treat the questionnaire as a work list as well. Somebody who prices risk for a living has just handed you a ranked set of priorities for your own business, at no charge.

What we do here

We go through the form with you and answer it from evidence, gathering the proof as we go. Where the honest answer is no, we say no and put a date beside it. We hold no security certifications and the form says exactly that, because a claim is a poor place to discover that a supplier was optimistic on your behalf.

You keep a written list of the protections actually in place, in plain words and with our name on it, which is also what your regulator or your privacy officer will ask for.

What we would do

When an owner forwards us an insurer’s questionnaire, this is the sequence.

  • Read the form with you on the callback and separate the questions we can answer from the ones only you can.
  • Check each control against what is actually running, rather than against what was set up two years ago.
  • Collect the evidence for every yes and keep it with the completed form.
  • List the gaps in the order the insurer cares about, with what each would cost to close.
  • Close the quick ones, usually the second login step and the backup that sits too close to the data.
  • Give you a plain-words summary of the protections in place, signed by us.

This is part of the free infrastructure audit, and the written result is yours whether you go on to hire us or not.

Two more questions people ask next

All the answers

Send us the questionnaire.

Leave your name and your number. A person calls you back the same business day, usually within an hour, and goes through the insurer’s questions with you one at a time.

Ask us to call you back

Leave your name and number. A real person calls you back the same business day, usually within an hour.

We use your number to call you back about your request. Nothing else.

Call me back