Cyber questionnaire

Answer a cyber insurance questionnaire with evidence you can stand behind.

We work through the questions and sort them into answers supported by material, gaps and points that need clarification, before you sit down with a broker or insurer.

01 Fit

When this service fits

When you have a cyber insurance questionnaire to complete and want to answer with evidence you can stand behind rather than optimistic declarations, before you talk to a broker or insurer. If you place your own products on the market, we add a product security angle: CRA, product vulnerabilities, SBOM, PSIRT and updates, because it comes up in questionnaires and conversations with industrial customers.

02 Scope

What we review

  • The technical questions in the cyber questionnaire and what they mean.
  • Risky answers that could weigh on the insurer's assessment.
  • Evidence of controls: MFA, backups with a restore test, EDR and antivirus, remote access, privileged accounts, logs.
  • The incident response procedure and IT supplier management.
  • Ransomware exposure.
  • Collecting the supporting material and a plan of first fixes before the conversation.

03 Result

What decision the result supports

You receive a clear split between answers supported by material, gaps and questions that require clarification.

04 Inputs

What to prepare

  • The cyber questionnaire you received, or a working draft of it.
  • The available evidence of controls: MFA configuration, a description of backups, EDR, logs, if they exist.
  • The incident response procedure and a list of key IT suppliers, if you have them.

05 Terms

How scope and quotation are set

Scope and quotation depend on the number of questionnaires and the systems they cover, the material available and the conversations required. We establish both after a short scoping call.

06 Limits

What this service does not replace

We do not broker insurance and cannot guarantee an insurer's decision. We do not advise on policy choice or compare insurance terms; that is the broker's job. Evidence requirements vary by insurer and by questionnaire, so there is no universal acceptance checklist. We prepare the technical part: answers, evidence of controls and a plan of first fixes.

07 Process

Signal → review → evidence → decision

Signal

What does the cyber questionnaire ask for?

Review

What is a declaration and what does material confirm?

Evidence

What can you demonstrate before the conversation?

Decision

Which gaps to fix first?

08 Questions

Questions before starting

  • Do you sell or choose the policy? No. That is the broker's job; we prepare the technical part.
  • Is there a universal acceptance checklist? No. Requirements vary by insurer and by questionnaire.
  • What if we cannot demonstrate a control? We mark it as a gap and point to what to fix first.

09 Contact

Discuss the questionnaire review scope

The starting point is the questionnaire and a few sentences about the situation; on that basis we will refine the scope of the work on answers and evidence.

Discuss your questionnaire

Editorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.