cybee

Menu

Start freeDeutsch

What evidence should you prepare for cyber insurance?

Prepare clear answers about devices, accounts, backups and training before a cyber insurance application or renewal lands.

A business owner reviews insurance paperwork beside a laptop in a quiet office.
Illustrative scene.

What security evidence does a small business need for cyber insurance?

Start with the insurer’s actual questions and the systems they cover. Gather dated records for devices, account protections, backups, training and incident responsibilities where requested. Separate verified facts from gaps and planned changes. Requirements vary by policy. A security report alone does not guarantee acceptance, coverage or a successful claim.

Read the questions before collecting screenshots

An application asks whether all work devices are protected. You know yours is, but what about the freelancer who joined last week? Another question asks about multi-factor authentication. It might refer to email, remote access or administrative accounts. The word “all” can turn a familiar setting into a much wider business question.

Ask the insurer or broker to clarify unclear wording and which systems are in scope. Keep that clarification with the application. Start an answer sheet with the question, responsible person, evidence date and any exception. Do not choose “yes” because you intend to fix a gap later. Describe the current position and agree how an improvement should be handled.

Group evidence by the thing it actually proves

For devices, gather the list of work computers and relevant protection, encryption and update records. For accounts, check the services the question names and their actual sign-in settings. For backups, identify what is saved, where it is stored and whether recovery has been tested. Each group answers a different part of the business picture.

Training records show participation in particular lessons. An incident plan names who handles a problem and how to reach them. Neither is established by a healthy laptop. Keep the records separate but easy to find, and use a consistent date format. That saves the next person from having to work out which screenshot belonged to which answer.

From a question to a supported answer

  1. Question

    What exactly is being asked?

  2. Record

    Which dated evidence supports it?

  3. Gap

    What remains unknown or unresolved?

Example workflow.

Write down the awkward exceptions

Imagine six company Macs are checked, but a contractor uses an unassessed device for client work. The evidence covers six Macs. It does not cover every person in the project. Record that difference, assign someone to resolve it and ask how the insurer wants the exception reflected. Concealing the gap makes the answer less reliable.

Another example is a successful backup that nobody has tried restoring. Say what you know: the job ran, the recovery test remains outstanding. A planned control, an enabled control and a tested control are different states. This distinction helps the business choose its next action, rather than turning the application into a search for reassuring wording.

Make renewal a review, not a fresh investigation

Keep the submitted application, the evidence used and the answers to any follow-up questions together. Revisit the relevant records when people, devices or important services change. Before renewal, check the current questionnaire against your current setup. Both may have changed since the last application. Ask the broker how material changes should be reported.

Also understand the policy’s incident contact route, exclusions and conditions with the appropriate adviser. Insurance can help a business recover financially and operationally, but it is not a preventive control. Keep day-to-day protection and recovery work running after the application is complete. The useful outcome is a maintainable routine, not a folder that nobody opens until renewal.

Use device proof for the device questions

Cybee’s Trust Passport provides a dated record of technical controls on the assessed Macs. It can support the device-related answers within that scope. Review the separate Google Workspace and training records for the relevant account or training question. Do not treat a Mac record as proof about every account or business process.

You still need to check policy wording and provide information about areas such as backups, suppliers and incident responsibilities. Cybee does not certify eligibility or decide what an insurer accepts. It helps replace guesses about your devices with a record you can inspect, while leaving the remaining questions visible for the right person to answer.

What to remember

  • Work from the actual policy questions and their scope.
  • Date the evidence and state exceptions honestly.
  • A device report supports specific answers. It does not establish insurance coverage.
Sources and further reading

Product scope and provider guidance can change. Check the linked source for your own setup.

Put it to work.

Continue with a practical guide or see how cybee helps with the work.