The cyber underwriting questionnaire that landed in your inbox last week is forty-six questions. Some of them are obvious — "do you have MFA on all privileged accounts?" Some are technical — "what's your mean time to patch critical CVEs?" One of them is "describe your incident response capability," and the answer field is a single text box, no character limit, no rubric, and somehow the most consequential question on the form.
None of the answers you give will be independently verified before binding. The carrier will read them, run an external scan of your internet-facing posture, possibly request a short follow-up call, and produce a price. Then they'll bind. The verification, if it happens at all, happens after a claim is filed — at which point the gap between what you attested and what the forensic firm finds becomes either a partial denial or a full one.
This is what underwriters actually score, how they translate it into premium and coverage, and what they wish they could see but currently can't.
The five categories every cyber underwriter scores
The questionnaire varies by carrier, but every one of them is asking the same five underlying questions. The category labels are mine; the language on the form will be different. The structure is universal.
Score well on these five and the premium converges to the lower end of the band, the coverage is broad, and the exclusions are narrow. Score poorly on any single one and the carrier either declines, prices the gap (premium up 25–60%), or adds a scenario-specific exclusion that voids the corresponding coverage.
What the external scan actually sees
Beyond the questionnaire, almost every carrier runs an external attack-surface scan during underwriting and at renewal. This is the part most policyholders underestimate. The scan isn't deep — it can't see inside the network — but it doesn't need to be deep to fire a denial trigger later.
Internet-exposed services
Open ports, exposed RDP/SSH/SMB on internet-facing interfaces, admin consoles reachable from the public internet. Every exposed service becomes a known posture risk; if the eventual incident traces to it, the known-vulnerability exclusion fires.
Expired or weak TLS certificates
Signal of operational maturity. Expired certs say the operations function isn't watching basic hygiene; carriers extrapolate to other controls and price accordingly.
DNS hygiene
DMARC published and enforced ("reject" not "none"), SPF and DKIM aligned, no dangling subdomains pointing at deprovisioned cloud resources. Dangling subdomains in particular are a takeover vector with high signal-to-noise.
Email security configuration
Public-facing MX records, gateway configuration if detectable from outside, presence of SPF/DMARC. Carriers cross-reference what the scan finds against what the questionnaire claims.
Leaked credentials in public dumps
Carrier tooling checks public credential dumps for any email matching the policyholder's domain. Material credential exposure (especially for admin or executive accounts) drives premium up or triggers a posture-improvement requirement before binding.
The single most common underwriting gotcha: the questionnaire claims MFA is enforced on every admin account, and the scan finds an exposed admin console with no MFA challenge. The carrier doesn't argue; they price the gap or carve out the credential-compromise scenario. The fix isn't to argue the scan; the fix is to either close the exposed surface or to walk into the renewal with continuous attestation evidence that the scan's outside view doesn't reflect the inside reality.
How "score" translates into premium and coverage
Carriers don't publish their scoring rubrics, but the translation function is consistent enough across the market that it can be approximated. For a 100-person SaaS company in the $5M–$15M revenue band, the rough mapping looks like this:
The premium range matters less than the coverage profile difference. The strong-posture policy at $25K covers roughly twice the loss the average-posture policy at $45K covers, on the same incident. Buying the cheap policy with a weaker score isn't buying less insurance for less money — it's buying meaningfully less protection per premium dollar, in a way the aggregate limit doesn't reveal.
What underwriters actually want but can't currently see
Talk to a cyber underwriter long enough and the wish list is consistent. None of these are unreasonable; all of them are currently unavailable.
What underwriters see today
A self-attested questionnaire snapshot from the time of binding. An external scan that captures the outer perimeter and ignores everything behind the firewall. A renewal-time refresh that catches what changed in twelve months. Plus whatever the policyholder volunteers about controls.
What they actually want
Continuous attestation: that MFA is enforced today, that EDR is deployed on every endpoint today, that backups ran clean within the past 30 days. Real evidence the questionnaire claims still hold. A standardized risk score they can compare across the book. Telemetry-grounded claims when incidents happen, so the post-incident reconstruction isn't entirely policyholder-narrated.
The gap between what underwriters have and what they want is the gap that visibility-based insurance closes. Policyholders who can provide continuous attestation evidence — produced by their own security stack, shared under a defined access pattern — change the conversation. The carrier prices the actual posture, not the worst-case posture they have to assume in the absence of evidence.
How to walk into the renewal in a better posture than last year
Three things move the score more than anything else, and all three are doable inside the four-to-six week renewal window most policyholders have.
Close exposed services the scan will find
Run your own external scan against the same surface the carrier will scan. Close exposed admin consoles, expired TLS certificates, dangling subdomains, public-facing dev environments. The list of things to close is usually under twenty items and takes one engineer-week.
Enforce MFA on every privileged account with documented evidence
Not "we have MFA" — "MFA is enforced on every account with elevated privileges, with no exceptions, verified weekly." The documented evidence is what shifts the questionnaire answer from a 3 to a 5, and the underwriter notices.
Test the backup recovery and capture the evidence
Run a recovery exercise within the 90-day window the carrier asks about. Document the recovery time, the data integrity check, the offline/immutable verification. Send the test artifact with the questionnaire. The single most useful piece of "evidence beyond the questionnaire" you can produce.
The bottom line
Cyber underwriters are scoring the same five categories every carrier scores, using a combination of self-attested questionnaire answers and an external scan that sees the outer perimeter. The score translates into premium and — more consequentially — into coverage profile and exclusion language. The policyholders who walk into renewal with closed external surface, documented controls, and recent recovery-test evidence end up in the strong-posture band, paying less for materially better coverage. The math compounds: every year of investment in attested posture produces a renewal advantage that the rest of the market doesn't get.
Walk into the renewal with attestation evidence the questionnaire alone can't produce
vCISO Lite generates the continuous-attestation evidence — MFA enforcement status, EDR coverage, backup recovery tests, IR plan currency — that turns the underwriting questionnaire from a self-reported snapshot into a verified posture record. The same five-scenario annualized loss expectancy methodology that drives the CFO budget defense, exposed in the format underwriters actually need. Built for the 33 million US small and mid-sized businesses that don't have a CISO yet, but need to walk into the cyber renewal with evidence underneath every attestation.
If your renewal is on the calendar, or you want to score above the band you scored last year, visit vcisolite.com to learn more and get started.
Where this matters next
Cyber insurance is broken because carriers can't see inside the policyholder — the structural reason the questionnaire-plus-scan model isn't producing accurate pricing.
What cyber insurance actually covers in 2026 — the coverage carve-outs and sub-limits the underwriting score directly drives.
The five controls that most move cyber insurance premiums — the specific control investments that move the underwriting score most reliably.
Why cyber insurance premiums keep going up — the market-level dynamics that determine the band your premium falls into, regardless of individual score.
Where this matters next
Cyber Insurance Is Broken Because Carriers Can't See Inside the Policyholder — Property insurance works because adjusters can see the roof. Auto works because police reports document the crash
The Five Controls That Most Move Cyber Insurance Premiums — The renewal came in at $48K, up from $32K. The broker said \
Why Cyber Insurance Premiums Keep Going Up (And the Math Behind 2026's Increase) — The 28% increase on your renewal isn't your posture failing. It's the loss-ratio math catching up to the entire market
Cyber Risk Quantification for Mid-Market: FAIR Without an Enterprise Risk Team — FAIR was built for risk teams of 20+. Mid-market companies have one person doing security part-time