The Coverage Memo
Cyber RiskLong read

Cyber Insurance Underwriting Questions for Startups

Underwriters now verify your actual security controls, not just your claims about them.

Features Editor · · 11 min read
Cover illustration for “Cyber Insurance Underwriting Questions for Startups”
Cyber Risk · September 30, 2026 · 11 min read · 2,523 words

Cyber Insurance Underwriting Questions for Startups

Why underwriters are scrutinizing startup applications more carefully even as rates soften

Cyber insurance questionnaires are a scoring mechanism. They are a scoring mechanism, and every question on the form maps to a control area an underwriter uses to price the risk sitting in front of them. Startups that treat the application as a formality tend to discover, at the worst possible moment, that a wrong answer can void the policy entirely.

The market backdrop makes this worth understanding right now. Cyber rates fell 4% globally in the second quarter of 2026, the twelfth straight quarterly decline, and primary pricing is roughly 42% below where it stood in 2022. By most measures, that should mean easier underwriting and looser scrutiny. It hasn't worked out that way. U.S. cyber premiums reached $7.5 billion in 2025, and the loss ratio climbed 4.3 points to 53.0%, the first time it has crossed the 50% mark since the ransomware surge a few years back. Carriers are collecting less per policy while paying out more per claim, which is exactly the condition that makes underwriters tighten their questions even as the sticker price on coverage drops.

That combination pushes competition away from price and onto proof. When a market can't win on premium alone, it wins by figuring out who actually has functioning controls and who is guessing. The discount goes to the applicant who can demonstrate posture.

The stakes justify the scrutiny. The average cost of a data breach in the U.S. has climbed to nearly $9.6 million in 2026 Top Cyber Liability Insurance Providers for Seed-Stage.... Most startups don't arrive at this realization on their own, either. They buy cyber coverage because an enterprise customer's procurement team stalled a contract pending proof of insurance, or a security questionnaire demanded a certificate, or an investor's due diligence checklist required it. The purchase decision starts as a box to check for somebody else. The underwriting process, though, doesn't care why the applicant showed up. It only cares whether the controls described on the form actually exist.

How the underwriting process itself has changed before you fill out a form

The old version of this process was simple enough: a company filled out a lengthy self-attested questionnaire, an underwriter read it, and a price came back. That model still exists in places, but it's no longer the whole story.

Some carriers now scan an applicant's external attack surface before anyone reads a single answer on the form. Corvus states directly in its application that it scans the applicant's primary corporate website and any affiliated sites, and folds high-level findings into the quote. Open ports, exposed services, and outdated software sitting on the perimeter can appear in the scan before the underwriter even opens the application document. A company can write "yes, patched" in a text box while the scan behind it says otherwise.

What happens to those answers afterward matters just as much as how they're checked. Beazley's form states that the application, along with everything submitted alongside it, becomes part of the policy itself if one is issued. That's a meaningful legal shift from how most people think about filling out a form. An answer here is a warranty. It's a warranty, and warranties get tested when a claim comes in.

Some carriers push the accountability even further up the org chart. AXIS requires its ransomware supplemental application to be signed by a named officer, someone holding a title like CEO, CTO, CSO, CFO, General Counsel, or an equivalent role. It's an executive attestation, with a named signature attached to specific claims about the company's security posture.

Underwriters have also stopped accepting vague affirmatives. A bare "yes" to a question about MFA or backup coverage doesn't satisfy anyone anymore Cyber Insurance for Startups: What You Need, When You Need It, and Ho…. Carriers want coverage percentages, the names of the vendors involved, and a documented list of exceptions where the control doesn't fully apply. Treat the application like a security audit that carries a signature, and gather the evidence before writing the first answer, not after submission.

What happens when an answer is wrong (the rescission risk every startup needs to understand)

A real case illustrates what's at stake better than any hypothetical could. In Travelers v. Ill.), Travelers sought to rescind a $1 million CyberRisk policy approximately thirteen weeks after inception Cyber Insurance for Startups: What You Need, When You Need It, and Ho…. The ransomware attack that triggered the claim had hit about eight weeks into the policy term Cyber Insurance for Startups: What You Need, When You Need It, and Ho…. The application had stated that multi-factor authentication protected administrative access across the network. The server that got hit in the May 2022 attack had none Cyber Insurance for Startups: What You Need, When You Need It, and Ho….

"Void from inception" is a specific and unforgiving phrase in insurance law. It means something more severe than the claim getting denied. It means the policy never existed at all, as though the premium was never paid and the coverage was never bound. Every dollar spent on that policy bought nothing.

The application had claimed MFA protected administrative access, but the server hit in a May 2022 ransomware attack had none Cyber Insurance for Startups: What You Need, When You Need It, and Ho…. The Travelers form states that the listed controls "are the minimum controls that must be in place in order to be eligible for a Cyber policy". That sentence draws a hard line. These are eligibility gates. They're eligibility gates. Fail to meet them, misstate that you meet them, and the policy was never valid to begin with.

The fix here isn't complicated, even if it takes discipline to execute. Answer control questions with actual coverage percentages and a documented exception register, rather than a flat yes or no Cyber Insurance Readiness: What Underwriters Require in 2026 - Integr…. And the obligation doesn't end once the policy binds. Most applications require notification of material changes to the security environment. The controls attested to at signing need continuous monitoring, not a once-a-year check-in before renewal.

The three gate controls (MFA, EDR, and backups) that determine eligibility before anything else

Diagram: The Three Eligibility Gates Every Startup Must Clear. Visualizes: Visualize three sequential eligibility gates that function as pass/fail thresholds before any other scoring begins: (1) MFA — required by roughly 96% of cyber insurers…

Three controls sit ahead of everything else on almost every cyber application, and they function as eligibility gates rather than scoring inputs. Aon has noted that insurers may simply refuse coverage outright when these basics aren't in place. There's a clear reason these three specifically carry that weight. Ransomware showed up in 44% of breaches in that same report. Backups and endpoint detection are treated as non-negotiable rather than optional line items.

MFA gets the most granular treatment of the three. Roughly 96% of cyber insurers now require multi-factor authentication across remote access, email, and privileged accounts as a flat condition of coverage. Beazley's form asks about this in three separate questions covering remote network access, webmail, and domain administrator accounts. Corvus splits the same territory four ways, asking separately about remote access, privileged accounts, email on every device, and all critical applications. Beazley also treats service accounts as their own category, asking how many hold domain admin rights and whether interactive logins onto those accounts are blocked. Not every authentication method counts equally in the eyes of security guidance, either. SMS codes and push notifications are generally accepted by carriers, but CISA's phishing-resistant MFA guidance recommends FIDO or PKI-based methods specifically for privileged and remote access, since weaker methods can be phished or worn down through push-bombing. An undisclosed gap is a far worse position to be in than a disclosed one.

Endpoint detection follows a similar pattern. About 88% of underwriters now mandate endpoint detection and response tooling across all managed devices, and basic antivirus no longer clears that bar on its own. Corvus asks applicants to specify which category of tool they run, whether that's EPP, NGAV, EDR, MDR, or XDR, and to name the vendor; Beazley asks applicants to specify the same thing. The vendor name matters less than the honest answer to what percentage of endpoints and servers actually carry that coverage, and who is watching the alerts it generates.

Backups round out the trio, and the questions here go well past "do backups exist." Applications ask whether backups are offline or air-gapped, whether they're immutable, whether they're encrypted, whether MFA protects access to them, and when the last full restore test happened. Underwriters increasingly want documented Recovery Time Objectives and Recovery Point Objectives on file, proof that the backup system works within defined performance parameters rather than just sitting there. Isolated or immutable backup infrastructure, tested on a quarterly cadence, is the standard most 2026 checklists now expect. Beazley extends this same logic to remote access tools, asking directly whether software like RDP sits exposed to the open internet, treating that exposure as another extension of the same access-control gate.

The remaining control areas every application covers, and the criteria for "passing" each one

Beyond the three gates, carrier questionnaires converge on roughly a dozen control areas in total, a structure Marsh publishes as twelve key cyber hygiene controls tied directly to insurability Cyber Insurance Readiness: What Underwriters Require in 2026 - Integr…. The remaining areas don't carry the same all-or-nothing weight as MFA, EDR, and backups, but they still shape both eligibility and price Cyber Insurance for Startups: What You Need, When You Need It, and Ho….

Email security shows up early on most forms, covering filtering, sandboxing of attachments and links, and enforcement of SPF, DKIM, and DMARC authentication standards, along with whether legacy mail protocols have been disabled. Passing here means those protections are actively enforced, not simply monitored in the background, external-sender banners are turned on, and legacy protocols are blocked outright. Email remains the leading delivery channel for both ransomware and funds-transfer fraud, and that is why it earns its own dedicated section on the form.

Privileged access management is its own category, covering whether admin accounts are kept separate from daily-use accounts, whether dedicated PAM tooling is in place, and whether service accounts carry domain admin rights they don't need Cyber Insurance Readiness: What Underwriters Require in 2026 - Integr…. Passing means those accounts are vaulted, rotated on a schedule, and reviewed quarterly for who actually holds administrative access. Privilege escalation is the step between an attacker gaining a foothold and that foothold turning into an enterprise-wide event. Underwriters treat this as more than a formality.

Vulnerability and patch management questions cover scan coverage, how often scans run, time to remediate critical CVEs, and whether end-of-life software is still running anywhere in the environment. Passing looks like a written patching cadence, critical vulnerabilities closed within days rather than quarters, and a documented compliance rate to back it up.

Network segmentation questions ask whether critical systems, backup networks, and cloud environments are walled off from general user traffic. This tends to appear alongside questions about centralized log collection, since forensic costs balloon quickly when a company can't reconstruct what happened across its systems after an incident.

Incident response planning gets direct attention too. Beazley asks outright whether the applicant has a written incident response plan covering intrusions and malware, while Corvus asks about continuity and disaster recovery plans, employee security training, and funds-transfer verification procedures. Passing means a documented plan that gets tested through actual tabletop exercises on a regular schedule.

Penetration testing occupies a slightly different place in this structure. Corvus asks a single yes-or-no question about whether the applicant runs a network penetration test at least annually. Beazley asks how often, with answer options of never, annually, two to three times a year, or quarterly or more often, meaning frequency itself carries weight in the underwriting decision. No law forces a startup to run a pentest before buying coverage, and whether skipping one changes eligibility, terms, or a ransomware sublimit depends heavily on the specific carrier and the limit requested; a broker can answer that directly. What a third-party pentest offers that a self-attested checklist can't is evidence that the controls described on the form actually hold up against a real, simulated attack, which is the underlying question the carrier is trying to price in the first place.

Social engineering defenses round out the list, covering phishing simulation programs, staff training, and the procedures in place for verifying payment or banking instructions before money moves. Coverage for funds-transfer fraud or business email compromise often requires its own specific grant on the policy, and isn't automatically bundled into a standard cyber form. Applications also ask how much personally identifiable information, protected health information, payment card data, or other sensitive data the company stores, processes, or can access. That figure isn't administrative curiosity. It feeds directly into how limits and pricing get set.

The startup-specific dimensions underwriters layer on top of the standard control questions

Startups face a layer of questions beyond the standard control checklist, and the pricing logic behind them starts with revenue. Cyber policies get priced off projected next-12-month revenue, and that figure is the primary underwriting variable, ahead of headcount or funding stage. A well-funded, well-staffed company with modest revenue can end up paying less than a leaner one generating more top line, because the underwriter is pricing against what the company earns, not how it's capitalized. Vouch's own client data, drawn from a base of 2,034 clients, puts the median annual premium at $2,755, with the actual number scaling against revenue, data exposure, and demonstrated security posture.

Business model questions come next, and they get specific fast. For B2B software companies, underwriters want to know what the product does, who uses it, and what happens downstream if it fails or gets compromised. A startup whose product has privileged access into customer environments, reading email, touching code repositories, or taking automated actions on a customer's behalf, is in a materially different risk category than one that doesn't reach that deep into a customer's systems. If a startup stores customer data, handles payments, runs a SaaS product, or integrates with third-party systems as part of its core offering, underwriters treat cyber risk as something baked into the business model itself.

Industry sector shifts the calculation further. Healthcare technology, fintech, and companies serving other regulated industries carry heavier data sensitivity and regulatory exposure, which raises both the price and the depth of questioning. Tech startups building SaaS or AI products, by contrast, typically are at the lower end of the market's rate range relative to their overall risk profile. Remote and distributed teams add their own wrinkle, since more endpoints and more access paths translate to more exposure, and underwriters ask about this directly rather than inferring it from the rest of the form.

Vendor and supply chain exposure closes out the list, and it's become one of the more common questions on recent applications. If key vendors hold access to a startup's data or systems, the risk extends past whatever controls the startup itself has built, and underwriters increasingly want to know exactly which third-party cloud infrastructure and vendors sit inside that trust boundary.

Sources

  1. Vouch: What Is Cyber Insurance? Coverage, Costs & How It Works (2026)
  2. Cyber Insurance Readiness: What Underwriters Require in 2026 - Integrated GRC Platform for Compliance, Risk & Security Governance
  3. Top Cyber Liability Insurance Providers for Seed-Stage ...
  4. Cyber Insurance for Startups: What You Need, When You Need It, and How to Get It Right
Filed underCyber Risk

More in Cyber Risk