Services
Fractional CISOFractional CIOAI Readiness & Security AuditStrategic Implementation
Who we serve
NonprofitsChurches & ministriesSmall businessesMSP partners
Company
AboutCase studiesInsightsContactStart with a conversation →
Home/Insights/The insurer’s questionnaire

Insights

What to do the day your insurer sends a forty-question security form

Cyber-insurance renewals now hinge on a handful of controls. Here is how to answer the form honestly, fix what is missing, and never scramble for it again.

PublishedAug 25, 2026
AuthorMike McGee
Reading time4 min

The form arrives with the renewal notice, usually with two weeks on the clock. Forty questions, most of them yes-or-no, several of them about things nobody in the building is certain about. The temptation is to answer optimistically. Don’t — a claim denied for a misstatement on the application is far more expensive than a higher premium.

Start with the five questions that decide the outcome

Underwriters weight a small set of controls heavily: multi-factor authentication on email and remote access, tested backups that are separated from the production network, endpoint detection on every device, a written incident response plan, and staff security training in the last twelve months. If you can answer those five truthfully, the rest of the form is detail. If you cannot, those five are your project list.

Answer with evidence, not memory

For each “yes”, know where the proof lives: a screenshot of the MFA policy, the last backup restore test, the endpoint console, the dated plan, the training roster. Your MSP can produce most of this in an afternoon if you ask specifically. Keep it in one folder with the completed form. Next year’s renewal becomes a review, not a scramble.

Fix the gaps before you submit, where you can

Turning on MFA for email is usually a week of work and it is the single control brokers ask about first. A tabletop exercise with leadership produces a real incident plan in two hours. If a gap cannot be closed in time, say so on the form and give a date — underwriters respond well to a credible remediation plan and badly to surprises.

Make it someone’s job

Every organization that struggles with this form has the same root cause: nobody owns it. Assign an owner — an executive, not a vendor — and put the renewal date on the risk calendar. That is exactly the kind of ownership a fractional CISO provides, and it is often the first thing we take off a client’s plate.

MIKE McGEE · Founder, ForEffect · ABOUT

One call, no deck

Start with a conversation.

Tell us what keeps you up at night. We read and reply to every note — usually within one business day — and the first conversation is about your organization, not our services.

info@foreffectai.comMill Creek, WA · Remote-first

Book a 20-minute conversation

Pick a time that suits you. No slides, no pitch — twenty minutes on what your organization is dealing with and whether a fractional executive is the right shape of help.

Choose a time
or
Send a short note instead