Your Cyber Insurance Questionnaire Is Not a Formality

Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider serving Seattle-area businesses, founded in 2005. This is about completing an insurer’s control questionnaire truthfully when you are not certain of the answers.

Most cyber insurance applications come with a multi-page questionnaire asking detailed questions about controls a business may not fully understand, let alone have verified. It is worth treating that questionnaire as more than paperwork, because what is attested to there can determine whether a claim gets paid at all.

Why it matters more than it looks

Insurers can and do treat inaccuracies in a questionnaire as grounds to deny or close a claim without payment, on the reasoning that the policy was underwritten against a set of controls that turned out not to be accurate. That makes the honest answer to each question worth more than the flattering one – a control attested to but not actually in place is a liability at claim time, not before.

What the regulator’s own data shows

The National Association of Insurance Commissioners’ 2024 Cybersecurity Insurance Report, drawn from insurers’ own annual statement data, found that the number of claims closed without payment in 2024, 28,555, was nearly three times the number closed with a payment, 9,941.

That figure needs a caveat to be used honestly: “closed without payment” is not the same thing as “denied.” It includes claims that fell below the policy’s deductible, claims that were withdrawn, and claims resolved through non-monetary incident response rather than a cash payout. NAIC does not publish a separate denial count, and a widely circulated figure claiming that around 40% of cyber insurance claims are denied traces only to marketing blogs with no underlying source. The honest reading of the NAIC data is that a large share of claims close without a payment for a range of reasons, not that insurers are denying claims at that rate.

What to check before you answer

Before a questionnaire goes back to the carrier, verify that every control it claims actually exists and actually works the way the answer implies: multi-factor authentication where it is claimed as universal, backups that have actually been tested with a real restore rather than assumed to be working, and endpoint protection deployed where the questionnaire says it is deployed. The point of the exercise is not to answer conservatively – it is to make sure the answers are true, so that if a claim is ever filed, the policy behind it actually pays.

Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.