The Cyber Insurance Application Is the Real Test. Here Is What It Asks.
Key takeaways
- The cyber application is underwriting, not paperwork. Your answers shape the premium, the terms, and sometimes whether a carrier will offer a quote at all.
- Most of the questions come down to four things: who can log in, what is running on the laptops, whether your backups would survive an attack, and who has actually practiced responding to one.
- Answer from evidence rather than memory. Confirm each answer with whoever administers your systems before anyone signs.
- Business email compromise remains one of the costliest exposures for businesses. The FBI logged $3,046,598,558 in reported BEC losses across 24,768 complaints in 2025.
- Maryland, Virginia and the District each require notice to a regulator after a breach, and Virginia adds a separate duty for employers that hold payroll withholding data.
October is Cybersecurity Awareness Month, which has run every October since 2004. It is a reasonable prompt to do something most businesses put off: read the cyber insurance application before renewal instead of during it.
That document does more work than people expect. It is not a formality attached to a quote. It is the underwriting. The answers you give describe the risk a carrier is being asked to take, and they shape the price, the terms, the sublimits, and in some cases whether you get an offer at all.
The application is the underwriting
A cyber application asks a specific set of questions because carriers have watched which controls actually change outcomes. The questions look technical. They are really asking four plain things.
Who can log in. Whether multifactor authentication is turned on, and where. This is the question most often answered too generously. A lot of businesses enabled it on email years ago and have not looked since, while remote access, the VPN, cloud administration consoles and privileged accounts sit outside it. Those are the doors that matter.
What is running on the laptops. Whether endpoint detection and response, or a managed version of it, is deployed on every machine. The word that carries weight is every. One unmanaged laptop belonging to a contractor or a departing employee is the gap the question is designed to find.
Whether the backups would survive. Not whether backups exist. Whether a copy is kept offline or immutable, whether it can be reached with the same credentials as production, and when it was last restored as a test rather than assumed to work. A backup an attacker can encrypt is not a backup.
Who has practiced. Whether there is a written incident response plan, whether anyone has rehearsed it, and whether staff receive phishing training. These questions look soft next to the technical ones. They tend to separate the businesses that recover in days from the ones that recover in months.
Where DMV businesses get caught
The FBI’s Internet Crime Complaint Center logged 1,008,597 complaints and $20.877 billion in reported losses in 2025, a 26 percent increase in losses over the prior year. Two numbers inside that matter most to employers.
Business email compromise accounted for $3,046,598,558 in reported losses from 24,768 complaints. That is the invoice that looked real, the wire instructions that changed at the last minute, the payroll direct deposit quietly redirected. It rarely involves anything dramatic. It usually involves one mailbox and one person in a hurry.
Ransomware produced 3,611 complaints. More than 1,400 of those came from businesses and organizations outside the sixteen critical infrastructure sectors, and the reporting was led by legal services at 18 percent, contracting services at 17 percent, engineering and architectural services at 10 percent, and consulting at 7 percent. Those are ordinary professional and trade firms, and they look a great deal like the businesses across this region.
The District, Maryland and Virginia all sit high in the same report. Virginia recorded 25,314 complaints and $476,120,025 in reported losses. Maryland recorded 19,430 complaints and $390,242,821. The District recorded 3,113 complaints and $97,368,097, and on a per capita basis it ranked first in the country for both complaints and losses.
What a careless answer costs
Application answers are representations. Some carriers go further and write a control into the policy as a condition, so the coverage responds only if the control was actually in place when the loss happened. The phrasing varies by form, which is exactly why the form matters.
The practical risk is not usually dishonesty. It is distance. The person signing the application is often not the person who administers the systems, and the answer that gets written down is the answer from memory. Someone recalls that multifactor authentication was rolled out, without knowing it was never extended to the VPN. Someone confirms nightly backups, without knowing the backup server shares credentials with everything else on the network.
The fix is unglamorous. Before anyone signs, put the application in front of whoever actually runs your systems, whether that is an internal person or an outside IT provider, and have them answer from what they can see rather than what they believe. Where an answer is no, say no. A truthful no is a conversation about price and terms. An inaccurate yes is a conversation at claim time, which is a far worse moment to have it.
The clock after a breach is different in each jurisdiction
If a breach reaches personal information, the obligations are statutory and they are not the same across the region. This is worth knowing before an incident, not during one.
Maryland. The Personal Information Protection Act, Md. Code Ann. Com. Law section 14-3504, requires notice to affected consumers within 45 days. Before notifying consumers, a business must notify the Maryland Office of the Attorney General. Maryland also defines personal information broadly enough to include health information and health insurance policy or subscriber numbers, which matters for any employer holding benefits enrollment data. A violation is treated as an unfair or deceptive trade practice under the Maryland Consumer Protection Act.
Virginia. Section 18.2-186.6 requires notice to the Office of the Attorney General and to affected residents without unreasonable delay. The Attorney General may seek a civil penalty of up to $150,000 per breach, or per series of similar breaches found in a single investigation. Virginia also carries a provision that employers often miss: an employer or payroll service provider whose data on taxpayer identification numbers combined with income tax withheld is compromised must notify the Attorney General separately, and that duty covers the employer’s own employees rather than its customers.
District of Columbia. Section 28-3852 requires notice in the most expedient time possible and without unreasonable delay. If the breach affects 50 or more District residents, written notice must also go to the DC Office of the Attorney General, and that notice cannot be delayed simply because the final count is not known yet. It has to include the cause of the breach, the remedial steps taken and a sample of the consumer notice.
Most businesses in this region touch more than one of these. A Bethesda employer with staff in Arlington and a client in the District can trigger all three sets of duties from a single incident. Breach response coverage exists in large part to fund the legal and forensic work that sorting this out requires.
Four things worth doing this month
CISA publishes four steps that hold up regardless of the size of the business: use strong, unique passwords with a password manager, turn on multifactor authentication, learn to recognize and report phishing, and keep software updated. None of those are expensive. All four show up somewhere on a cyber application.
If you want a fifth, make it this: pull your current cyber policy and read the insuring agreements alongside the application you signed. That is the pairing that tells you what you actually bought.
How we work on this
We are an independent agency, so we are not steering you toward one carrier’s appetite. What we do is go through the application with you before it goes in, flag the answers that will drive the terms, and tell you plainly where a gap is going to be a problem so you can decide whether to close it or price it. If a control is missing and you would rather not fix it this year, that is a legitimate choice. It should just be a choice you make knowingly.
We work with businesses across Maryland, DC and Northern Virginia, and we are happy to look at what you have.
Frequently Asked Questions
What does a cyber insurance application actually ask about?
Four areas, mostly. Access control, meaning where multifactor authentication is turned on. Endpoint protection, meaning whether detection and response software is on every machine. Backups, meaning whether a copy is isolated from the network and has been restored as a test. And people, meaning whether you have a written incident response plan and run phishing training. Carriers also ask about revenue, records held, and prior incidents.
Does multifactor authentication have to be on everything?
Carriers care most about remote access, email, cloud administration consoles and privileged or administrator accounts. Email alone is the most common answer and the most common gap, because remote access and admin accounts are usually where an attacker would rather be. If you are not certain where it is enabled, that is worth confirming before the application goes in rather than after.
What happens if we answer a question wrong?
It depends on the form and on the facts. Application answers are representations, and some carriers also write specific controls into the policy as conditions, so the coverage responds only if the control was genuinely in place. An honest mistake is not the same as a misstatement, but it can still create a dispute at the worst possible time. Answering from evidence rather than memory avoids nearly all of this.
Do we still need cyber coverage if everything is in the cloud?
Yes. Moving systems to a cloud provider moves some of the technical work, not the legal duty. If your employees or clients have personal information exposed, the notification obligations in Maryland, Virginia and the District fall on your business. Business email compromise also happens almost entirely inside cloud email, and it remains one of the largest reported loss categories in the FBI data.
How soon do we have to report a breach in Maryland, Virginia or the District?
Maryland sets 45 days for consumer notice and requires notice to the Attorney General before consumers are notified. Virginia requires notice to the Attorney General and affected residents without unreasonable delay, with civil penalties up to $150,000 per breach. The District requires notice without unreasonable delay, plus written notice to its Attorney General when 50 or more District residents are affected. If you operate across the region, assume the strictest clock applies.
Related reading from Capitol Benefits
Ready when you are
Let's take a look at what you've got.
A real review of your current coverage. No deck, no pressure, and usually some money saved along the way.
