How do you prepare for a cyber-insurance questionnaire?
Glassbreak Team · Published 2026-07-19
Preparing for a cyber-insurance questionnaire means doing three things before the form arrives: knowing the short list of controls underwriters actually price on — MFA coverage, privileged and break-glass credential vaulting, a tested incident-response plan, isolated backups, and an incident communication capability — being able to answer each one truthfully with a qualifier where reality is partial, and attaching evidence (dated drill reports, audit exports) rather than bare checkboxes. The questionnaire is part of the application: answers that turn out to be materially wrong when a claim is investigated can reduce or void the payout, so the goal is not the most impressive answers — it's the most defensible ones.
The questions underwriters actually ask, and why
Application forms differ by market, but the control list has converged because it tracks claims data. Expect variants of these:
"Is MFA enforced on remote access, email, and all privileged accounts?" The single biggest gating question; many markets decline to quote without it. The trap is the word all: service accounts, legacy VPN paths, and — most commonly — the emergency admin account "temporarily" excluded from MFA. Answer the strict question, list the exceptions, and describe compensating controls for each.
"How are privileged and emergency (break-glass) credentials stored, and who can access them?" This question has sharpened noticeably in recent renewal cycles. Underwriters are probing for the unvaulted domain admin password, the cloud root credential in a shared document, the backup-console login one engineer knows. What scores well: credentials in an encrypted vault, no single person able to retrieve them unilaterally, alert-on-use, and an audit trail of every release. What scores badly: "in the password manager, IT team has access." If this is your weak area, break-glass account best practices covers the design that underwriters' questions are steering you toward.
"Has your incident-response plan been tested in the last 12 months?" Underwriters want a dated exercise — tabletop or live — with a report. This is the cheapest question on the form to turn from "no" to "yes": schedule a tabletop, run it, write down what broke, keep the report. The 2 a.m. test is a good scenario seed: can your responders actually reach what they need out of hours?
"Do you maintain offline, immutable, or otherwise isolated backups, and have you tested restoration?" The underwriter is pricing ransomware recovery. "Isolated" is the load-bearing word — backups reachable with the same credentials as production are, from a claims perspective, part of production. Note the quiet dependency: restoring isolated backups requires credentials that survive the incident too, which loops back to the vaulting question.
"Do you have an incident communication plan that works if primary systems are unavailable?" Increasingly asked directly, because claims handlers watch response costs balloon when a victim's coordination channels (email, chat, SSO) are inside the blast radius. A good answer names an independent, secured channel, a current contact tree, and evidence it's been exercised.
Copy-pasteable prep worksheet
Fill this in before the renewal form arrives; it becomes both your answer source and your evidence index.
# Cyber-Insurance Questionnaire Prep Worksheet
For each control: state (Yes / Partial / No), scope + exceptions,
evidence artifact + date, remediation date for gaps.
## 1. MFA coverage
- Remote access / VPN: [state] [exceptions] [evidence, date]
- Email: [state] [exceptions] [evidence, date]
- Privileged/admin accounts: [state] [exceptions] [evidence, date]
- Break-glass accounts: [state] [compensating controls if MFA
is infeasible, e.g. quorum release +
alert-on-use] [evidence, date]
## 2. Privileged & break-glass credential vaulting
- Inventory of privileged/emergency credentials current as of: [date]
- Storage: [vault name/type, encryption model]
- Can any single person retrieve unilaterally? [yes/no — name the
approval threshold, e.g. 2-of-4]
- Alert-on-use in place? [yes/no, who is notified]
- Last credential release + review: [date, evidence]
## 3. Incident-response plan & testing
- IR plan version/date: [x.y, date] Owner: [role]
- Last test: [date] [tabletop/live] [scenario]
- Report retained: [location] Findings closed: [n of m]
- Next scheduled test: [date]
## 4. Backups
- Isolation model: [offline / immutable / separate credentials]
- Are backup credentials separate from production SSO? [yes/no]
- Last successful restore test: [date, evidence]
## 5. Incident communications
- Out-of-band channel: [system], independent of [SSO/email/chat]?
- Contact tree last verified: [date]
- Acknowledgment/escalation mechanism: [description]
- Last communications drill: [date, evidence]
## 6. Evidence pack (attach or index)
- [ ] MFA policy + coverage report dated: [date]
- [ ] Vault access policy + audit-log export dated: [date]
- [ ] IR plan + last tabletop/drill report dated: [date]
- [ ] Restore test record dated: [date]
- [ ] Comms drill record + contact tree dated: [date]
## Honesty check (before signing)
- [ ] Every "Yes" has a named evidence artifact
- [ ] Every exception is disclosed with a remediation date
- [ ] The person signing has seen the evidence, not just this sheet
Mapping the worksheet to Glassbreak
Glassbreak, an end-to-end-encrypted break-glass platform, is built to make the hardest sections of that worksheet true and provable:
- Section 2 (vaulting) — credentials are encrypted client-side and released only by M-of-N quorum approval (Shamir secret sharing over an RSA-OAEP-4096 + ML-KEM-1024 hybrid), so "can any single person retrieve unilaterally?" is answerably no — including for Glassbreak itself, which cannot read your secrets. Every request, approval, and release lands in the audit log. The cryptography is documented on the security page.
- Section 5 (communications) — the platform runs on two independent cloud providers with continuous replication, outside your SSO and email blast radius; emergency messages go out over voice, SMS, and email with per-recipient acknowledgment tracking and escalation tiers, so the "acknowledgment/escalation mechanism" line has a concrete, evidenced answer.
- Sections 3 and 6 (testing and evidence) — drill scheduling runs your access and notification drills on a cadence, and the audit log plus exportable evidence packs produce the dated artifacts the worksheet indexes — the difference between asserting a control and attaching it.
- Playbooks — your IR plan and contact tree live alongside the credentials they reference, reachable when production isn't.
The same controls, evidenced once, also serve your auditors and regulators: see the ISO 27001 break-glass procedure guide (with a full procedure template), the DORA incident reporting checklist, and the NIS2 readiness guide. Glassbreak plans are priced per responder — recipients are free — with a 30-day trial; see pricing.
This page is general preparation guidance, not insurance, legal, or brokerage advice; your policy wording and your broker's guidance govern what any specific insurer requires.
Frequently asked questions
- What happens if I answer "yes" to a control we only partly have?
- The questionnaire is part of the application for insurance, and insurers investigate the state of controls when a large claim lands. If the answer was materially wrong — MFA "everywhere" except the domain admin account the attacker used — the insurer may dispute or reduce the payout, and in some cases seek to rescind the policy. The safe pattern is to answer the strict question truthfully, add a qualifier describing scope and exceptions, and attach the remediation date for the gap. Underwriters see qualified answers constantly; discovered misstatements are what damage you.
- Why do insurers care so much about break-glass and privileged credentials specifically?
- Because claims data says privileged credentials are how incidents become catastrophes: ransomware operators specifically hunt for domain admin, cloud root, and backup-console credentials, and an unvaulted emergency credential is both an entry path and an escalation path. A vaulted credential that requires multiple people to release, alerts on use, and appears in an audit log turns the worst-case scenario the underwriter is pricing into a contained one — which is why the question keeps appearing in more specific forms each renewal.
- What counts as a "tested" incident-response plan?
- Underwriters generally want a dated exercise within the last 12 months — a tabletop walkthrough of a realistic scenario or a live drill — with a record of who participated, what scenario was run, and what was fixed afterward. A plan that has only ever been written doesn't count for much, and an honest "documented but not yet tested" answer scores worse than a modest but dated tabletop report. Scheduled drills with retained reports are the cheapest control on the whole questionnaire to make true.
- Will good answers actually reduce my premium?
- Controls move premiums, deductibles, sub-limits, and insurability itself — several markets won't quote at all without MFA on remote access and tested backups, and ransomware sub-limits or coinsurance are commonly tied to privileged-access and backup answers. Exact pricing impact varies by market, sector, and revenue, so treat controls as buying access to better markets and terms rather than a fixed discount; your broker can tell you which answers are currently gating which markets.