Skip to main content
MSP Business

Answering cyber insurance questionnaires

Why cyber insurance questionnaires have got tougher, what they always check, and how an MSP turns answering them into billable work.

L'équipe Vigicap13 min read

A client forwards you a forty-question cyber insurance questionnaire a week before their policy is due for renewal, and asks you to fill it in "quickly". A few years ago that same questionnaire fitted on one page. Here is why it has grown, what it checks every single time, and how to stop treating it as unpaid drudgery.

Why have cyber insurance questionnaires become longer and stricter?#

Because insurers have stopped taking self-declaration at face value. Faced with the frequency and cost of ransomware claims, underwriters have tightened their grids: they now ask for elements of proof on specific controls — a screenshot of the MFA console, a restore test report, an EDR certificate — rather than a ticked box. A questionnaire that used to stop at "do you have an antivirus?" has become a detailed list of verifiable technical controls — which shifts part of the answering burden onto the provider that actually runs the infrastructure: you.

Legislators have moved in the same direction. In France, article L12-10-1 of the Insurance Code, in force since 24 April 2023, makes payment under a clause covering losses caused by an attack on an automated data processing system conditional on the victim filing a complaint with the competent authorities no later than seventy-two hours after becoming aware of the attack. The provision applies only to legal persons and to natural persons acting in the course of their professional activity. Put plainly: in France, an SME's cyber cover now comes with a procedural condition to be met within three days of discovery — which belongs in the incident response plan the same questionnaire asks you to describe a few pages later.

What does an insurer's questionnaire actually look like, structurally?#

A mandatory common core, followed by conditional blocks triggered by the client's profile. Most insurers keep their own grid confidential, but there is one public model: the cyber risk questionnaire published in German by the GDV, the German insurance association, as a non-binding template for cyber policies aimed at SMEs. It is binding on nobody, but it is one of the few publicly available worked examples — and the mechanics it shows are the same everywhere.

The principle: the number of questions asked depends on two variables, turnover and the activities carried on. The GDV model distinguishes three risk categories — up to 2 million euros of turnover, up to 5, up to 10 — and its core asks only about a dozen questions covering the baseline obligations, plus five screening questions whose only purpose is to establish which additional blocks to open.

BlockWhat it asks forWhat it is really after
Activity screeningE-commerce run on your own infrastructure, processing of third-party data, use of external providers, personal devices, automated production systemsPlacing the client in a risk category and deciding which conditional blocks to open
Core: accessNamed accounts, separate administrative accounts, minimum password requirements, firewall and disk encryptionChecking that one compromised account does not immediately hand over administrative rights
Core: protection against malicious codeProtection present and kept up to dateScreening out estates with no maintained protection
Core: updatesSecurity patches installed regularly and promptlyMeasuring the exposure window between publication and deployment
Core: backupBackup at least weekly, physically separate media, protection against tampering, periodic restore testEstimating whether a ransomware attack ends in a restore or in a negotiation
IT provider blockOne set of questions per IT service provider the client usesAssessing the client's dependency, and the insurer's own routes of recourse
Sensitive data blockNature of the third-party data processed, professional secrets, trade secretsEstimating exposure to liability claims and to penalties
Higher-category blockSecurity officer, data protection officer, regular training, need-to-know access and its review, encrypted remote access, centralised patch management, network segregation, risk analyses, IT recovery planMoving from technical security to organisational security, which is what the insurer is actually pricing

Two lessons for an MSP. First, eight of the ten core questions are about access and backup — only one about malware protection, only one about security updates. Second, the blocks that really move the premium are the organisational ones: access reviews, network segregation, centralised patch management, recovery plan. Those are precisely the ones a client cannot fill in alone.

What does the block on IT service providers ask?#

Five questions per provider, and they are about you. In the GDV model, the client first has to list each provider and the scope entrusted to it — email, hosting, line-of-business applications — because the nature of the outsourced scope determines both the client's dependency and its potential loss. Then come four questions on the contractual relationship: is there a service contract governing availability, updates and the remediation of security flaws; is the provider certified or subject to independent quality control; has the client released its provider from liability, and in which cases; is the provider subject to European data protection law.

The third of those deserves a careful read. The model explains without any circumlocution why the insurer asks it: a liability waiver granted to the provider prevents the insurer from pursuing that provider after a claim, which changes the insurer's own risk. The contract you negotiated with your client is therefore also read by their insurer — and it weighs on the premium the client pays.

The model adds a remark every MSP should know about: on these questions, it does not expect the client to be able to answer without going and finding out, and it suggests the insurer collect the information directly. In practice, "directly" means through you. Better to have the answer prepared than to discover the question over the phone on a Friday afternoon.

Which categories of control do questionnaires check every time?#

Six families come up in almost every questionnaire, whichever the insurer:

  • Multi-factor authentication (MFA) — on email, on remote access and, increasingly, on privileged accounts.
  • Backups and tested restores — the question is no longer only whether a backup exists, but the last date on which a restore was actually attempted.
  • EDR (Endpoint Detection and Response) — a signature-based antivirus on its own no longer answers the question.
  • Patch management — the delay between the publication of a critical vulnerability and the deployment of its fix.
  • User awareness training — how often campaigns run, particularly on phishing, the leading entry vector in claims.
  • The incident response plan — that it exists, when it was last updated, and sometimes evidence of an exercise.

These are not arbitrary controls: they are, almost term for term, the same families as those in ReCyF, the cyber framework published by ANSSI, France's national cybersecurity agency, which French MSPs already assess for clients in scope of NIS2 — identity and access management, business continuity and recovery, protection against malicious code, incident response. A client that has already done that exercise for NIS2 or ISO 27001 answers the insurance questionnaire with evidence that already exists, rather than with improvised assertions.

One point of wording is worth flagging, because it trips people up regularly. The most common questions are not binary, despite looking that way. "Do you regularly test restoring your backups?" is not asking whether a restore is technically possible: it is asking whether there is a defined frequency, and tests actually carried out at that frequency. "Are security updates installed automatically or promptly?" is not asking whether the update service is switched on: it is asking for a delay. Answering "yes" to those questions without the corresponding dated report is declaring more than you can show.

Which answers hold for a whole portfolio, and which stay client by client?#

That distinction is the key to making the exercise pay. Some of the questions are about you, the provider — and that part does not change from one client to the next. Others are about the client's estate, and have to be measured again for each of them, at every renewal.

QuestionOnce for the whole portfolioPer client, at every renewal
Your own security practices as a provider (passwords, MFA on your administration tools, subcontractors you use)Yes — a single file, reusable—
Your certifications or your quality processYes—
The service contract template: availability, updates, remediation of flawsYes — one standard clause per offerCheck which one applies to this client
The liability waivers you have negotiatedYes, if your contracts are standardisedTo be confirmed if the contract was negotiated
The standard architecture you deploy (backup, EDR, MDM, conditional access policy)Yes — describe the standard once—
Actual MFA coverage across the client's estate—Yes — a dated figure, with its denominator
Last successful restore test—Yes — a date, a scope, a report
Observed deployment delay for critical patches—Yes — measured, not estimated
Privileged accounts and their last review—Yes
Personal devices and systems outside the managed scope—Yes — the question whose answer ages fastest

The left-hand column is written once and reread every year. The right-hand column cannot be written in advance: it has to be measured. It is also the one that exposes you if you fill it in from memory — because you are the only party in a position to check it.

Why can an inaccurate declaration void the cover at the worst possible moment?#

Because the policy rests on what the insured declared when the cover was underwritten, and an insurer treats a good-faith error and a misrepresentation very differently. An inaccurate answer discovered after a claim — "MFA enabled on all accounts", when half the privileged accounts were exempt — is never examined in the middle of the storm: it resurfaces when the insurer is assessing the claim, that is, at precisely the moment the client most needs the cover to respond.

Insurance law draws that line explicitly, and the gap between the two outcomes is wide. The German Insurance Contract Act 2008 (Versicherungsvertragsgesetz – VVG) is a useful illustration because it exists in an official English translation. Its section 19 governs the policyholder's pre-contractual duty of disclosure, and it is built on two ideas that travel well. First, the duty attaches to the circumstances the insurer has asked about in text form — which is exactly what a questionnaire is, and which is why the wording of each question matters more than the general impression the file gives. Second, the insurer's remedy escalates with the policyholder's fault: rescission of the contract where the breach was intentional or grossly negligent, and, for simple negligence, termination or an adjustment of the premium or of the terms rather than the loss of the cover outright.

The remedy ladder differs country by country — the French Insurance Code and the Italian Civil Code draw the same line between an intentional misstatement and a good-faith one, but attach different sanctions to each side of it. What does not differ is the line itself, nor where it is drawn: on what was written in the questionnaire, and on whether an intention can be shown behind it.

That risk does not fall on the client alone: it is often the MSP who filled in the technical boxes on the questionnaire, with the information available to it. An approximate answer on a point only you are in a position to verify — the real state of the estate, the effective coverage of MFA — puts your credibility on the line as much as your client's policy.

Does an answer to the questionnaire bind you for the whole life of the policy?#

Usually yes, and this is the point most providers discover too late. The core questions are not simply pricing inputs: they cover obligations the insured undertakes to keep to for the life of the contract. The GDV model is explicit about it — the questions in its base category correspond to the obligations set out in its standard cyber policy conditions.

The practical consequence is the one that prompted a whole separate article: an answer that is true on the day the cover is underwritten and false six months later is not an administrative detail. MFA turned off on a Friday evening to unblock a user and never turned back on, a new device that entered the estate before the compliance policy applied to it, a backup that fails with a warning rather than an error — each of those unremarkable incidents turns an honest declaration into an inaccurate one, without anybody having lied to anybody.

It is also why the right unit of evidence is not the screenshot but the series of dated readings. It documents what you declared, when, and on the basis of which measurement.

How do you turn answering the questionnaire into a billable service?#

By ceasing to treat it as an administrative side-formality and structuring it as a recurring deliverable. Three concrete elements:

  1. Build a permanent evidence file, rather than an ad hoc answer at each renewal — the same screenshots (MFA, EDR, last tested restore) serve the insurance questionnaire, the NIS2 assessment and the same client's ISO 27001 file. Collection work done once serves several times over.
  2. Bill the annual questionnaire review as a service in its own right, scheduled ahead of the renewal date rather than in the rush of the week before — a client understands paying for security expertise, not for filling in a form.
  3. Document the gaps as much as the compliant points: a missing control, flagged clearly to the client before they answer "yes" out of overconfidence, protects you as much as it protects them.

A fourth point, less obvious, separates the MSPs who make money on this exercise from the ones who merely endure it: never hand back a completed questionnaire without a gap note. Two or three lines are enough — the questions whose answer is "no" today, what it would take for it to become "yes", and the order of magnitude of the work. That note does two things at once: it records that you did not let the client declare more than they could hold to, and it is your commercial proposal for next year. The same lines that protect you legally are the ones that fill your order book.

There are, finally, public tools for preparing the conversation in advance. The GDV publishes an interactive version of its questionnaire, the Cybersicherheits-Check, which returns an interim assessment and prioritised recommendations. It is German, non-binding and calibrated for German SMEs — but it gives an honest sense of the level of detail expected, which is already more than most clients imagine before they open their own insurer's form.


Vigicap offers drafting assistance for security questionnaires — insurer or large-account: you paste in the questions, and the tool produces proposed answers for you to validate, drawn from the client's compliance register, their maturity score and the latest connector readings. These are drafts to review and correct, not a form submitted on your behalf: the signature stays yours, and that is exactly why it is worth something.

Topicscyber insurancequestionnaireMSPrisk management