Blog / Compliance

Compliance
July 21, 2026 · 6 min read · Nexus Team

Cyber Insurance Questionnaires Decoded: What the Underwriter Is Actually Trying to Find Out

Cyber insurance applications read like a compliance framework wrote itself in a hurry — dozens of yes/no questions about MFA, backups, EDR, and patching cadence, with no visible connection between any single answer and the premium quoted back. That's because the questionnaire isn't really forty independent questions. It's a small number of underlying risk signals, asked from several angles each, to catch inconsistent answers.

The signals underneath the questions

Underwriters care most about a handful of controls that correlate strongly with claim frequency and severity in their loss data: whether MFA is enforced on remote access and privileged accounts specifically (not just 'we have MFA' somewhere), whether backups are both immutable and tested via actual restore, whether EDR or equivalent runs on endpoints versus legacy signature-based antivirus, and whether privileged access is limited and logged. Every other question on the form is usually a variant angle on one of these four, asked in a different phrasing to catch an applicant who answered generously on the direct question but contradicts themselves on the follow-up.

Where MSPs and their clients get caught

  • Answering 'yes, MFA is enabled' when it's enabled but not enforced — a policy that can be bypassed or disabled per-user reads very differently to a claims adjuster after an incident than to an applicant filling out a form
  • Answering 'yes, we have backups' without distinguishing whether they're immutable, whether they're tested, and whether they'd survive an attacker who had domain admin for two weeks before detection
  • Treating the questionnaire as a one-time form rather than a snapshot that needs to still be true at claim time — insurers have denied claims based on a gap between the application's answers and the environment's actual state during the incident

The attestation problem

A cyber insurance questionnaire is a legal document, not a marketing survey — a materially false answer can void coverage after a breach, at exactly the moment the client needs the policy to pay out. That makes the honest answer to a hard question ('partially implemented, rolling out across remaining endpoints this quarter') more valuable to the client than an optimistic yes, even though it might narrow available coverage or raise the quote, because the alternative is a coverage denial dressed up as a lower premium.

The underwriter isn't grading effort. They're pricing the gap between what the application says and what a forensic investigator will find eighteen months from now.

This is one of the clearer cases for evidence-backed posture tracking rather than a memory-based yes/no answer sheet — being able to show, with attached evidence, exactly which controls are implemented versus partial versus planned makes the questionnaire answers defensible after the fact, not just plausible when filled out. Nexus's compliance module tracks that kind of control-level posture across frameworks already; using the same evidence trail to answer an insurance questionnaire accurately is a natural extension of it, though the underwriting decision itself, like the premium, stays entirely the insurer's call.

Follow the build as it ships.

Nexus is live in our own MSP operations and opening to a limited design-partner cohort. Join the private-preview list.