Resources · Insurance Guide

Cyber insurance now expects awareness training. Here's what underwriters look for.

The training questions on your renewal application aren't decoration — they move your premium, your sub-limits, and whether a claim gets paid.

A decade ago, cyber insurance applications were two pages. Today they're questionnaires with teeth, and a growing block of questions is about your people: training cadence, phishing simulations, wire-transfer verification, offboarding speed. That's not bureaucratic drift — it's carriers reading their own claims data. The human element drives the large majority of incidents they pay out on, especially business email compromise, which consistently tops loss reports for small and mid-size businesses.

The questions you should expect

Wording varies by carrier, but nearly every current application probes these areas:

  • Training cadence. "Do all employees receive security awareness training?" — with a frequency answer. "Annually at onboarding" is now the floor, not a good answer.
  • Phishing simulations. Whether you test employees with simulated phishing, and what happens when someone fails.
  • MFA enforcement. Technically separate from training, but it's the first checkbox and some carriers treat it as pass/fail for coverage.
  • Out-of-band verification. Whether payment or banking-change requests get verified by phone to a known number before execution. This question exists because unverified change requests are how most BEC losses happen.
  • Access management. How fast departing employees lose access, and whether privileged accounts get extra controls.

How answers move money

Insurability. Some carriers simply won't quote an organization with no training program, or will exclude social engineering losses from the policy.

Premium and sub-limits. Social-engineering and cybercrime coverage often carries a sub-limit far below the headline policy limit. Strong human-risk controls are one of the levers that raise it — or keep the premium from climbing at renewal.

Claims. This is the one that should worry you. An application is a legal representation. Attesting to quarterly training and simulations you don't run gives the carrier a misrepresentation argument exactly when you need them to pay. If your program is aspirational, say so on the form — or better, make it real before renewal.

What "documented program" actually means

Underwriters and forensic teams don't accept vibes. Keep four artifacts current:

  • Completion records — per employee, with dates, for every training cycle.
  • Simulation results over time — click rates, report rates, and the trend line. The trend matters more than any single number.
  • Your reporting workflow — written down: how an employee reports a suspicious message and who triages it, how fast.
  • A risk metric that moves — the strongest artifact is a per-employee score that demonstrably improves. This is exactly what our Defense Score was designed to be: a number you can hand your broker, not a completion percentage.

The renewal checklist

Before your renewalWhy it matters
Pull last year's application and reread your training answersWhatever you attested to is your baseline. Gaps between answers and reality are claim-time risk.
Enforce MFA on email and remote accessOften treated as pass/fail. Cheapest fix on this list.
Stand up a real training + simulation cadenceConverts the worst application answers into good ones inside one quarter.
Write the out-of-band verification rule for payment changesOne paragraph of policy that removes the most common BEC loss.
Export completion + simulation reports into one folderWhen the broker asks, you answer in minutes, not weeks.

Where do you stand today?

Our free Defense Score assessment asks roughly the same questions your insurer will — MFA, training cadence, verification habits, offboarding. Two minutes now beats discovering the gaps on a renewal form. And if you need the program itself, our Professional tier includes the compliance pack (HIPAA / SOC 2 / PCI / GDPR) with insurer-ready reporting — pricing is published here.

FAQ

Is training legally required for cyber insurance?

Rarely as an absolute bar — but applications ask, answers move price and coverage, and some carriers decline organizations with no program or exclude social-engineering losses.

Can a claim really be denied over this?

Misrepresentation on an application is a standard basis for rescission or dispute. Don't attest to a program you don't run.

What's the minimum credible program?

Recurring training (quarterly beats annual), regular phishing simulations with tracked results, a written reporting workflow, and records for all of it. That's also, not coincidentally, our Essentials tier plus a written policy.

Make your renewal answers true.

Take the Free Assessment See Pricing