10 Essential Tips for Completing Cyber Insurance Applications
Filling out an application comes with risks of denied coverage and missed opportunities for discounts. Follow these tips to avoid critical mistakes:
- Start Early and Designate One Primary Owner
Begin the application process 2-4 months before renewal. Assign one person (IT manager, CISO, CFO, or other relevant employee) to complete the entire application using available information, then have your MSP review only the technical sections for accuracy.
- Be Accurate with Revenue Information
Premium calculations are based on your revenue figures. Use exact numbers from audited financial statements and include all entities covered under the policy. This directly impacts your cost, so precision matters.
- Check “Yes” for Planned Implementations
If you’re planning to implement a security control, check “Yes” and specify the planned date. For example: “MFA implementation scheduled for Q2 2025” or “Endpoint encryption rollout planned for March 2025.”
- Provide Data Record Estimates When Exact Numbers Aren’t Available
For PII, PHI, PCI, and biometric data counts, use reasonable ranges:
- Small business: “1,000-5,000 records”
- Medium business: “5,000-25,000 records”
- Large operations: “25,000-100,000+ records”
- Create an MFA Implementation Appendix
List all systems and their multi-factor authentication status:
- Systems WITH MFA: Email, cloud applications, VPN, backup systems
- Systems WITHOUT MFA: Legacy applications, local servers
- Planned MFA rollouts with target implementation dates
- Specify Security Vendors Not in Dropdown Menus
When your security provider isn’t listed, write in the specific vendor:
- EDR/NGAV: CrowdStrike, SentinelOne, Microsoft Defender
- Email Security: Proofpoint, Mimecast
- Backup Solutions: Veeam, Acronis, Carbonite
- Choose the Right Cybersecurity Contact
This is who would be the go-to liaison between the insurance company and your company if there is a security incident
Designate your cybersecurity contact (list more than one in an appendix if needed):
- Internal CISO or Chief Security Officer
- Head of IT or CTO
- External MSP security lead
- Risk manager or equivalent
- Be Completely Honest About Prior Incidents
Transparency about past incidents within the 3-year lookback period is crucial. Report all unauthorized network activity, data breaches, system outages over 6 hours, and social engineering attacks. Hiding incidents is the #1 cause of claim denials.
- Document Backup and Recovery Capabilities
Clearly specify your backup arrangements:
- Frequency: Daily, weekly schedules
- Type: Cloud-based, on-premises, or hybrid
- Segmentation: Note if backups are air-gapped or offline
- Testing: Include annual restoration testing
- Have Authorized Signatory Complete and Review
The application must be signed by CEO, President, CIO, CTO, CSO, COO, CFO, General Counsel, or Risk Manager. Ensure this person reviews the completed application and understands they’re certifying its accuracy under penalty of insurance fraud laws.
Remember: Accuracy over perfection – insurers prefer honest organizations with clear security roadmaps over those claiming perfect implementation without evidence.
BONUS: Communicate with your cyber insurance agent if you have any questions. The agent is there to help you through the cyber insurance buying experience.
Now you have the roadmap to filling out the application. All you need is the right broker to help you place coverage and determine the correct coverage for your type and size of company.
Contact Joe Erle at C3 Insurance: [email protected] or call/text 760-688-9131 for a free evaluation of your cyber insurance program.
Joe Erle, Cyber Group Practice Leader


