shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
Refinery Report / Cybersecurity / post · cklist
CybersecurityCyber InsuranceSecurity EvidenceRisk Assessment

Cyber Insurance Evidence Readiness Checklist

Underwriting questionnaires ask for attestations you have to be able to evidence. The artifacts to assemble before renewal, and how to answer what you cannot prove.

D
By the DSE practice team
Operator-led practice · how we research & review
July 19, 2026
11 min · 2,436 words

By the DSE practice team · published July 19, 2026 · reviewed July 19, 2026

A cyber insurance application is an evidence exercise wearing a questionnaire’s clothing. The questions look like a survey — do you enforce MFA, do you have offline backups, do you have a written incident response plan — but each answer is an attestation, and the gap between “yes, mostly” and “yes, and here is the artifact” is what a renewal conversation, and later a claim review, tends to turn on.

This checklist is the artifact set we assemble in a readiness engagement, organized by the control areas that recur across underwriting questionnaires. Two constraints up front, because they shape everything below. We cannot tell you what any specific carrier will ask, accept, or cover — that is between you, your broker, and the underwriter. And nothing here makes any claim payable. What it does is put you in a position to answer accurately, quickly, and with something behind the answer.

Why accuracy matters more than a good score

The temptation on a questionnaire is to answer to the aspiration. Resist it. An application answer is a representation you are making to an insurer, and the safest posture is a precise “yes, for this population, with these exclusions” rather than an unqualified yes that a later review can contradict. In our experience, underwriters respond better to a qualified yes with a documented remediation date than to an unqualified yes with an obvious hole behind it — and a qualified yes cannot be characterized later as a misrepresentation.

If a question cannot be answered accurately in the affirmative, the useful move is to answer it accurately in the negative, attach the compensating control, and attach the remediation date. That is a fundable position. An unsupported yes is not.

The eight evidence bundles

A print-ready version of the eight bundles below — one line per artifact, with space to record who owns it and whether you can evidence it yet — is in our cyber insurance evidence checklist.

1. Identity and access

Identity questions carry the most weight on most questionnaires, and they are the ones where “we’re rolling it out” is most often recorded as a yes. Pull the actual numbers. The method is in the Microsoft 365 security assessment checklist.

2. Backup and recovery

The restore-test record is the highest-value single artifact in the whole pack, because it converts a claim about resilience into a measurement. If you have none, run one before renewal; the method is in how to prove your backups will actually restore.

3. Endpoint and email controls

4. Payment and social-engineering controls

These are process controls, not technology, and they are increasingly asked about because they are what actually interrupts a funds-transfer loss.

5. Governance and program

Where a regulatory regime applies, this bundle may already be mandatory rather than optional. The FTC Safeguards Rule at 16 CFR 314.4 requires a designated Qualified Individual, a written risk assessment, encryption of customer information in transit and at rest, multi-factor authentication, a written incident response plan, service-provider oversight, and a written report to the board or a senior officer at least annually. If you are covered by it, the pack you owe your regulator overlaps almost entirely with the pack the underwriter wants.

6. Testing and vulnerability management

The Safeguards Rule sets a useful benchmark even for organizations it does not cover: 16 CFR 314.4(d)(2) requires continuous monitoring or, absent it, annual penetration testing plus vulnerability assessments at least every six months, and additionally whenever there are material changes to operations or business arrangements. That is a defensible cadence to be measured against whether or not the rule applies to you.

7. Incident response

If none of this exists yet, incident response planning without a security team covers building it with the staff you have.

8. Third parties

Use a control baseline, not a wish list

If you need a defensible baseline to organize the pack against — and to answer “what should we be doing” without inventing a standard — two public references do the job.

CIS Critical Security Controls v8.1 defines Implementation Group 1 as a foundational set of 56 Safeguards that CIS calls essential cyber hygiene and describes as an emerging minimum standard of information security for all enterprises, selected to be implementable with limited cybersecurity expertise and aimed at thwarting general, non-targeted attacks. For a mid-market firm, IG1 is a realistic target set and maps readably onto most questionnaire sections.

CISA’s Cross-Sector Cybersecurity Performance Goals 2.0 are a voluntary, prioritized set aligned to the NIST CSF 2.0 Functions, published with cost, impact, and ease-of-implementation ratings for each goal — which makes them unusually useful for arguing a budget case rather than only for measuring posture.

Both are free, both are citable, and using either lets you describe your position in language an underwriter, a customer, and a board can all read.

Assembling it once, using it three times

The pack above is the same pack that answers an enterprise customer’s security questionnaire and a diligence request in a funding or acquisition process. Build it once, keep it current on a defined cadence, and store it somewhere that is not the file share it is supposed to protect. A cybersecurity risk assessment produces most of it as a by-product — the evidence register, the assessed profile, the severity-ranked findings, and the remediation roadmap are exactly the artifacts these three audiences ask for — which is generally a better sequence than assembling the pack in the four weeks before a renewal date.

FAQ

What evidence do cyber insurance applications typically ask for?

Underwriting questionnaires recur across eight areas: identity and access (MFA coverage and privileged access), backup and recovery (protection of backups and restore-test evidence), endpoint and email controls, payment and social-engineering process controls, governance (policy set, named owner, risk assessment, training, board reporting), testing and vulnerability management, incident response (written plan, tabletop evidence, contact sheet), and third-party oversight. Specific questions vary by carrier and are a matter for your broker and underwriter.

What should we do if we cannot answer yes to a control question?

Answer accurately in the negative, describe the compensating control, and attach a remediation date. An application answer is a representation to an insurer, and a qualified yes or a documented no with a plan is a stronger position than an unqualified yes that a later review can contradict.

Does having this evidence guarantee coverage or a paid claim?

No. Coverage terms, underwriting decisions, and claim outcomes are determined by the carrier under the policy and applicable law. Assembling evidence lets you answer accurately and quickly; it is not a coverage guarantee, an insurance recommendation, or legal advice.

What baseline should we measure ourselves against?

CIS Critical Security Controls v8.1 Implementation Group 1 is a foundational set of 56 Safeguards that CIS defines as essential cyber hygiene and an emerging minimum standard for all enterprises, designed to be implementable with limited security expertise. CISA’s Cross-Sector Cybersecurity Performance Goals 2.0 are a voluntary prioritized set aligned to NIST CSF 2.0 and published with cost, impact, and ease-of-implementation ratings. Both are free and citable.

How often should the evidence pack be refreshed?

Quarterly for the metrics that move — MFA coverage, patch compliance, training completion, privileged role membership — and on an event basis for the artifacts: after each restore test, each tabletop exercise, each penetration test, and each material change to the environment. Refreshing only before renewal produces a pack that is accurate for one week a year.

What this guide is / What it is not

What it is: A practitioner evidence checklist organized around control areas that recur in cyber insurance underwriting, anchored to CIS Critical Security Controls v8.1 Implementation Group 1, CISA’s Cross-Sector Cybersecurity Performance Goals 2.0, and the FTC Safeguards Rule at 16 CFR Part 314. What it is not: Legal advice, insurance advice, a broker service, an audit, a certification, or an attestation. DSE does not speak for any carrier, does not determine coverage, and does not guarantee that any policy will be issued, that any premium will change, or that any claim will be paid. Nothing here reduces your duty to answer an application accurately; representations to an insurer are your own and should be reviewed with your broker and counsel. Readiness work is point-in-time and does not prevent incidents.

The Bottom Line

Answer accurately, and hold an artifact behind each answer. The eight bundles above — identity, backup and restore evidence, endpoint and email, payment process controls, governance, testing, incident response, and third parties — are the same pack an enterprise customer’s questionnaire and an acquirer’s diligence request will ask for, so assemble it once and keep it current on a cadence rather than in the four weeks before renewal. Where you cannot answer yes, say so, attach the compensating control, and attach the date. That is a position you can defend later.

Next step · before the renewal date

Thirty minutes on the answers you cannot evidence yet.

Bring last year's questionnaire and your MFA, backup, and training numbers. We will tell you which answers need an artifact behind them and which gap to close first.

Key facts

Read next · AI Security & Governance

P
Founder · Principal Engineer
Data & AI engineer · 10+ yrs hands-on

Writes most of the long-form here. Lives in the codebase. Active on GitHub and LinkedIn.

§ Next step

Not sure which of these is you?

Tell us what's broken in a paragraph and a principal reads it directly — or walk the ladder from a low-commitment first engagement up to retained work.

One long-form a week. No marketing.

Subscribe to the Refinery Report. Practitioner deep-dives on AI engineering, security, and the realities of running production systems. Unsubscribe in one click.

~12 issues / quarter