Getting a cyber insurance quote, and the answers that decide the price

A cyber insurance quote turns on a dozen answers, and a business that has them written down gets a usable number the same day rather than a fortnight of email. The questions are broadly the same whichever insurer asks them, because the market converged on the same short list of controls, and the answers form part of the contract once the policy is issued. Preparing them properly is the cheapest thing a buyer can do, and it is also what stops a quote turning into a condition nobody can meet.

Write down the three numbers before anybody asks

Turnover for the last full year, the rough number of individuals whose personal data you hold, and the largest single payment the business could plausibly be tricked into making. Those three figures decide which sections need real limits and which can sit at the default, and they are the ones that will be asked for in the first minute of any conversation with an insurer or a broker.

Answer the controls questions honestly, and say where a control is partial

Multi factor authentication on email and remote access, backups held off the live network and tested, a patching routine, administrator rights limited, and a rule for verifying a change to a supplier's bank details. A partial answer described accurately is priced. A yes that turns out to have been a no is a condition precedent the insurer can rely on when the claim arrives, so the accurate answer is also the cheaper one in the end.

Ask for the section list, not just the premium

Two quotes at the same price can carry different sections. Ask each insurer to confirm whether the quote includes a crime or social engineering section, what the sub limit on it is, whether business interruption extends to an outsourced provider, and whether defence costs sit inside or outside the limit. Those four answers explain almost every price difference you will see.

Check what the incident response arrangement actually is

The value of a cyber policy arrives in the first day, in the form of people who have handled this before. Ask whether there is a dedicated incident line, who answers it, and whether the forensic and legal firms are pre appointed at agreed rates. A quote that cannot answer that is selling an indemnity rather than a response, and the difference shows up exactly once.

Questions people ask about cyber insurance quote

How long does a cyber insurance quote take?

For a small business with the answers ready, often the same day online and a day or two through a broker. What slows it down is missing information about controls, which is why writing the answers down first is worth the half hour it takes.

Will I be declined for weak controls?

Sometimes, particularly for remote access without multi factor authentication. More often you will be quoted with a condition, a larger excess or a lower limit, and fixing the control before applying is usually cheaper than accepting the loading.

Do I need to disclose a previous incident?

Yes, and it will be underwritten rather than automatically declined. Insurers care most about what changed afterwards, so describe the incident and the fix together.

Can I get a quote without a broker?

Yes, and for a simple risk it is quick. A broker earns their keep where the business has an outsourced data processor, a payments role, overseas clients or a claim in its history.

Sources

Related answers

See what insurers printCompare by trade