Cyber questionnaire
Answer a cyber insurance questionnaire with evidence you can stand behind.
We work through the questions and sort them into answers supported by material, gaps and points that need clarification, before you sit down with a broker or insurer.
01 Fit
When this service fits
When you have a cyber insurance questionnaire to complete and want to answer with evidence you can stand behind rather than optimistic declarations, before you talk to a broker or insurer. If you place your own products on the market, we add a product security angle: CRA, product vulnerabilities, SBOM, PSIRT and updates, because it comes up in questionnaires and conversations with industrial customers.
02 Scope
What we review
- The technical questions in the cyber questionnaire and what they mean.
- Risky answers that could weigh on the insurer's assessment.
- Evidence of controls: MFA, backups with a restore test, EDR and antivirus, remote access, privileged accounts, logs.
- The incident response procedure and IT supplier management.
- Ransomware exposure.
- Collecting the supporting material and a plan of first fixes before the conversation.
03 Result
What decision the result supports
You receive a clear split between answers supported by material, gaps and questions that require clarification.
04 Inputs
What to prepare
- The cyber questionnaire you received, or a working draft of it.
- The available evidence of controls: MFA configuration, a description of backups, EDR, logs, if they exist.
- The incident response procedure and a list of key IT suppliers, if you have them.
05 Terms
How scope and quotation are set
Scope and quotation depend on the number of questionnaires and the systems they cover, the material available and the conversations required. We establish both after a short scoping call.
06 Limits
What this service does not replace
We do not broker insurance and cannot guarantee an insurer's decision. We do not advise on policy choice or compare insurance terms; that is the broker's job. Evidence requirements vary by insurer and by questionnaire, so there is no universal acceptance checklist. We prepare the technical part: answers, evidence of controls and a plan of first fixes.
07 Process
Signal → review → evidence → decision
What does the cyber questionnaire ask for?
What is a declaration and what does material confirm?
What can you demonstrate before the conversation?
Which gaps to fix first?
08 Questions
Questions before starting
- Do you sell or choose the policy? No. That is the broker's job; we prepare the technical part.
- Is there a universal acceptance checklist? No. Requirements vary by insurer and by questionnaire.
- What if we cannot demonstrate a control? We mark it as a gap and point to what to fix first.
09 Contact
Discuss the questionnaire review scope
The starting point is the questionnaire and a few sentences about the situation; on that basis we will refine the scope of the work on answers and evidence.
Discuss your questionnaireEditorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.