Guide

What a cyber-insurance renewal questionnaire actually asks

The renewal form arrives with a deadline attached, and it does not ask for opinions. It asks whether specific controls exist, whether they are written down, and when each one was last reviewed. The underwriter reads the answers as a picture of how the business is run; a control that is real but undocumented reads the same as a control that does not exist.

The blocks below are the recurring ones — the questions that show up in some wording on nearly every small-business cyber policy questionnaire. None of them is exotic. Most firms already do the work; what they lack is the written record the form wants.

Identity and access

Whether multi-factor authentication is enforced on email, remote access and admin accounts, whether admin rights are separate from day-to-day accounts, and how a leaver's access is removed.

Backups

What is backed up, whether a copy lives offline or immutable, how often restores are actually tested, and who performs the test.

Endpoint protection and patching

Whether managed antivirus or EDR covers every machine, how quickly critical patches are applied, and what happens to machines that fall out of compliance.

Written policies

An incident response plan, acceptable use, password, backup, vendor management and BYOD policies — the questions ask whether the document exists and when it was last reviewed, not just whether the practice happens.

Incident history and continuity

Past breaches and near misses, whether you have a disaster recovery plan, how long you could tolerate being down, and who is called at 2am.

Why the written set, not the practice, is the bottleneck

A yes/no answer is accepted grudgingly. The forms increasingly single out documents by name — an incident response plan, an acceptable use policy, a backup policy — because a written policy is the one thing an underwriter can file, review and hold you to. Writing them from scratch is a week of unbillable work, which is why the answers get rushed a few days before the deadline and the premium reflects it.

The cheaper path is to keep the document set current between renewals: a network document, the six standard policies, a recovery plan and an onboarding record for the client company, held as editable files. Then the questionnaire becomes an afternoon of copying answers you already stand behind, and the same set serves the next audit, the next enterprise client’s vendor form and the next new hire.

Ready Net exists for exactly this afternoon

Answer a short intake about the client company and a complete, client-branded document set comes back the same day — the network documentation, the policy set, a disaster recovery plan and the rest, as editable files. The free intake delivers the first document in full, with the price on the page before you decide on the rest. Start an intake

Ready Net is built and run end to end by AI agents on NanoCorp, which is how this guide stays current with what the renewal forms ask.