A decade ago, cyber insurance applications were two pages. Today they're questionnaires with teeth, and a growing block of questions is about your people: training cadence, phishing simulations, wire-transfer verification, offboarding speed. That's not bureaucratic drift — it's carriers reading their own claims data. The human element drives the large majority of incidents they pay out on, especially business email compromise, which consistently tops loss reports for small and mid-size businesses.
The questions you should expect
Wording varies by carrier, but nearly every current application probes these areas:
- Training cadence. "Do all employees receive security awareness training?" — with a frequency answer. "Annually at onboarding" is now the floor, not a good answer.
- Phishing simulations. Whether you test employees with simulated phishing, and what happens when someone fails.
- MFA enforcement. Technically separate from training, but it's the first checkbox and some carriers treat it as pass/fail for coverage.
- Out-of-band verification. Whether payment or banking-change requests get verified by phone to a known number before execution. This question exists because unverified change requests are how most BEC losses happen.
- Access management. How fast departing employees lose access, and whether privileged accounts get extra controls.
How answers move money
Insurability. Some carriers simply won't quote an organization with no training program, or will exclude social engineering losses from the policy.
Premium and sub-limits. Social-engineering and cybercrime coverage often carries a sub-limit far below the headline policy limit. Strong human-risk controls are one of the levers that raise it — or keep the premium from climbing at renewal.
Claims. This is the one that should worry you. An application is a legal representation. Attesting to quarterly training and simulations you don't run gives the carrier a misrepresentation argument exactly when you need them to pay. If your program is aspirational, say so on the form — or better, make it real before renewal.
What "documented program" actually means
Underwriters and forensic teams don't accept vibes. Keep four artifacts current:
- Completion records — per employee, with dates, for every training cycle.
- Simulation results over time — click rates, report rates, and the trend line. The trend matters more than any single number.
- Your reporting workflow — written down: how an employee reports a suspicious message and who triages it, how fast.
- A risk metric that moves — the strongest artifact is a per-employee score that demonstrably improves. This is exactly what our Defense Score was designed to be: a number you can hand your broker, not a completion percentage.
The renewal checklist
| Before your renewal | Why it matters |
|---|---|
| Pull last year's application and reread your training answers | Whatever you attested to is your baseline. Gaps between answers and reality are claim-time risk. |
| Enforce MFA on email and remote access | Often treated as pass/fail. Cheapest fix on this list. |
| Stand up a real training + simulation cadence | Converts the worst application answers into good ones inside one quarter. |
| Write the out-of-band verification rule for payment changes | One paragraph of policy that removes the most common BEC loss. |
| Export completion + simulation reports into one folder | When the broker asks, you answer in minutes, not weeks. |
Where do you stand today?
Our free Defense Score assessment asks roughly the same questions your insurer will — MFA, training cadence, verification habits, offboarding. Two minutes now beats discovering the gaps on a renewal form. And if you need the program itself, our Professional tier includes the compliance pack (HIPAA / SOC 2 / PCI / GDPR) with insurer-ready reporting — pricing is published here.
FAQ
Is training legally required for cyber insurance?
Rarely as an absolute bar — but applications ask, answers move price and coverage, and some carriers decline organizations with no program or exclude social-engineering losses.
Can a claim really be denied over this?
Misrepresentation on an application is a standard basis for rescission or dispute. Don't attest to a program you don't run.
What's the minimum credible program?
Recurring training (quarterly beats annual), regular phishing simulations with tracked results, a written reporting workflow, and records for all of it. That's also, not coincidentally, our Essentials tier plus a written policy.