Most Rockland businesses that get denied cyber coverage are turned down over answers on the application, not findings from an audit, usually because somebody guessed at a technical question nobody in the office could actually verify.
It’s not what owners expect. They picture an underwriter poking around the network and finding something. Wrong picture, at this size.
The form is the audit. Read that twice. Whatever gets written on it becomes the record, and the record is what gets checked later, either at renewal or at the worst possible moment, which is after a claim.
If you’ve already had a renewal come back declined, the recovery path is a different piece of work and my colleague laid it out in the fix-it checklist for reapplying. This one is about the stage before that. What the questions actually mean, and how to answer them without guessing.

The Decision Gets Made at the Questionnaire
A small-business cyber application is short. Ten or twelve questions. That brevity is the trap.
Mostly yes or no, and every one of them is compressing a technical reality into a checkbox. An underwriter isn’t going to visit. They’re going to read your answers, price the policy against them, and rely on those answers being true if a claim ever lands.
So the failure mode isn’t dishonesty. Almost nobody lies on these. So what goes wrong? The failure mode is a confident yes from someone who has no way to confirm it, about a system they’ve never had visibility into, based on something their IT provider said in a meeting two years ago.
That answer gets you one of three outcomes. Declined now, which is annoying but survivable. Priced badly, which you’ll never know about. Or issued, and then contested later when it matters most.
Nobody in the Office Can Actually Answer These
Look at who typically fills out the form. An owner, an office manager, sometimes a bookkeeper. Three people. None of them technical. All capable people. None of them have a console that shows which endpoints are reporting, or whether multi-factor authentication is enforced as policy rather than switched on for whoever bothered.
They’re not being careless. Ask yourself who in the building could answer it. They’re being asked to certify something they genuinely cannot see.
The honest version of most of these answers is “I believe so.” Insurance forms don’t have a box for that. What that means practically is that whoever runs your IT needs to be in the room while the form gets completed, with evidence rather than recollection, and if that person can’t produce evidence on request, you’ve learned something important before the underwriter learns it.
Four Questions That Get Answered Wrong
These four come up on nearly every application I’ve seen a client bring me. The printed wording sounds simple. It isn’t. What sits underneath each one is a much bigger question than the checkbox suggests.
| The Question as Printed | What It’s Actually Asking | How to Check Before You Answer |
|---|---|---|
| “Do you use multi-factor authentication?” | Is MFA enforced by policy on every account touching email, remote access and admin, with no opt-out | Ask for the conditional access or policy list, and confirm the owner and any shared admin login are inside it |
| “Do you have endpoint protection?” | Is detection and response deployed and reporting on every device including servers, not antivirus on laptops | Ask for a device list from the console and compare the count against your actual hardware |
| “Do you back up your data?” | Has a restore been performed and documented, from an isolated copy, recently | Ask for the date of the last restore test and what came back with it |
| “Do you have an incident response plan?” | Does a written document exist naming current people and current vendors | Open it and check whether the phone numbers in it still belong to anyone you work with |
The first one causes the most trouble, because “we use MFA” feels true when it’s on for most people. Enforced is a different word, and CISA’s fact sheet on phishing-resistant MFA is a useful read on why the method matters too. We wrote up the enforced versus available distinction separately because it sinks so many applications on its own.
The backup question runs a close second. Jobs completing successfully is not a restore, and CISA’s StopRansomware guide is blunt about testing recovery rather than assuming it. If the endpoint question is where you’re unsure, the EDR versus antivirus breakdown covers what the form means by advanced protection.

Saying Yes When You Mean Probably
Now the part that deserves far more weight than it usually gets.
A declined application is a bad afternoon. A policy issued against an answer that turns out to be wrong is a much worse year, because the carrier can contest coverage at exactly the point you need it, and that’s a conversation happening while you’re already dealing with the incident that triggered it.
Which makes an accurate no more valuable than an optimistic yes. A no gets you a higher premium, a condition to fix within ninety days, or a narrower policy. All of those are recoverable. Being told after a loss that a control you attested to wasn’t actually in place is not.
None of that requires perfection at the time you apply. It requires the answers matching reality, and somebody keeping the evidence that shows it, which is its own discipline and one we covered in the piece on proof versus promises.
What We See Across Rockland
A few things show up repeatedly here. Less about the county than the kind of business in it.
Rockland runs heavy on professional practices, medical and dental offices, contractors, and small manufacturers along the Route 303 and 9W corridors. Most are under sixty people. Few have internal IT, which means the person who knows the answers to that application works for another company, and getting them on the phone before the form goes back to the broker is an actual scheduling problem rather than a formality.
The other pattern is timing. Renewal notices land, the form sits for a few weeks, and then it gets completed quickly on a deadline by whoever has time. That’s when guessing happens. Starting the conversation when the notice arrives rather than the week it’s due removes most of the risk on its own.
The NIST small-business quick-start guide is a reasonable plain-language baseline if you want to see how these controls fit together outside an insurance context, and our Rockland work is built around the same set.
What Rockland Owners Ask Before They Apply
Our broker fills out most of the form for us. Is that a problem?
We answered honestly and still got declined. What happened?
Can we just have our IT provider fill in the technical sections?
Is it better to answer no than to guess yes?
Does switching carriers reset any of this?
We’re renewing, not applying fresh. Does the same scrutiny apply?
A free security assessment checks each answer against what’s actually running, so the form goes back to your broker with evidence behind it. No obligation, and the findings are yours regardless.
