A cyber insurance application is the first time most small firms are asked precise questions about their own computers by somebody with a financial interest in the answers. The questions look simple. Several of them are not, and a surprising number of firms answer them from memory, from optimism, or from what they believe their IT provider is doing.
That matters more than it used to. Applications are signed. The answers form part of the basis on which cover is offered, and an answer that turns out to have been wrong is a bad thing to discover during a claim.
Corelink is not an insurance broker and this is not insurance advice. We license security software. The endpoint questions on these forms turn on how software is licensed and managed, which is the part we can speak to usefully. Your broker is the right person to ask about cover.
What the endpoint questions are really testing
Underwriters are not curious about which brand you run. Behind the endpoint questions sit three things they care about, and reading the questions with those in mind makes them much easier to answer.
Coverage. Not whether you have protection, but whether it is on everything. The gap between “we have antivirus” and “every device that touches company data is protected” is where incidents actually start.
Control. Whether somebody can see the state of the estate and change it. Central management is the difference between a policy you have and a policy you can enforce.
Evidence. Whether you can show it. An underwriter cannot verify your answers, but they can tell the difference between a firm that knows and a firm that is guessing, and that impression affects both the questions that follow and the terms offered.
The questions, and what they mean
“Is antivirus or endpoint protection deployed on all endpoints?”
The word doing the work is all. Nearly every firm can say yes about the office desktops. The honest answer depends on the machines at the edges: laptops that go home, personal computers used for work, a server, seasonal machines, the computer attached to a piece of equipment that nobody counts as a computer.
Answer this one from a list, not from memory. If you cannot produce a list, that is itself the finding.
“Is it centrally managed?”
This is asking whether there is a console: one place showing every enrolled device and its current status. Retail subscriptions bought machine by machine are not centrally managed, however good the underlying product is, and answering yes because each machine has protection installed is the most common mistake on these forms.
“Do you use endpoint detection and response (EDR)?”
Increasingly asked, and not the same question as the first. Traditional endpoint protection aims to prevent known threats. Detection-and-response products add recording of what happened on a machine and the ability to investigate and respond after the fact.
Some publishers include response features in their small-business tiers and some sell them separately, so the honest answer for a small firm is often “not currently” or “included in our product but not separately monitored”. Say which. A precise no is safer than an imprecise yes.
“Is it monitored, and by whom?”
Software that raises an alert nobody reads is not monitoring. In an office of twenty people the truthful answer is frequently that nobody watches the console between incidents. That is a normal answer for a firm this size and it is better given plainly than dressed up.
“Are automatic updates enabled?”
Two separate things sit inside this question: whether the protection product updates itself, and whether the operating system and applications are patched. Underwriters usually want both, and the second is where small firms are weakest.
“Do you still run unsupported operating systems?”
A yes will not necessarily prevent cover, but concealing one is serious. This is also worth knowing for your own sake: current versions of several endpoint products will not install on operating systems the publisher no longer supports, so an unsupported machine is often an unprotected one.
“Multi-factor authentication on email and remote access?”
Not an endpoint question, but it sits beside them and it is frequently the single most heavily weighted answer on the form. If you answer no here, expect it to affect the terms more than anything on this page.
How to answer from evidence
Give yourself an afternoon before the form is due.
- Build the device list. Every machine used for company work, including home and personal machines. Note the operating system and version for each.
- Check what is actually installed. On each machine, confirm protection is present, running, and updated within the last few days. Expired is common.
- Find the console, if there is one. Sign in. Compare its device list against yours. The difference between the two lists is the most valuable thing you will learn all afternoon.
- Write down the licensing. Product, seat count, term, expiry date, and who the licence is registered to.
- Answer the form from those four artefacts. Where the honest answer is no, write no, and note what it would take to change it.
That last step matters at renewal. An application that says no this year and yes next year, with a date attached, reads very differently from one that says yes both times.
What a firm can reasonably fix before renewal
Not everything on the form is fixable in a fortnight. Some of it is.
Moving from scattered retail subscriptions to a licensed business product with a console changes the answer to the first two questions, and it is a purchasing decision rather than a project. Correcting the seat count so that the licence actually covers every machine is the same conversation. Getting the console login into the hands of somebody who still works at the firm costs nothing.
Multi-factor authentication on email is usually a configuration change in a service you already pay for, and it is the highest-value item on most of these forms.
Detection-and-response, continuous monitoring and a written incident response plan are larger undertakings. They are worth planning, and they are not worth pretending to have.
The habit worth forming
Keep the four artefacts from the list above — device list, installed status, console export, licence record — in one place, and update them when you renew. Next year’s application takes twenty minutes instead of an afternoon, and the same four documents answer client security questionnaires and, for firms in regulated work, a good deal of what a compliance programme asks for. Our guide to the FTC Safeguards Rule covers that overlap for accounting and tax practices.
Where we fit
Corelink licenses business endpoint protection and handles renewals, which covers the coverage, central management and licensing parts of the list above. We will help you get to an accurate device count before quoting, and we will tell you when your existing arrangement already answers the questions and only needs renewing.
Our endpoint security page describes how the licensing works, and the renewals page covers the case where your current product is fine and the renewal is the only decision.
We do not sell insurance, complete applications, or attest to anything on your behalf. The answers have to be yours.