The Death of the Questionnaire: Why Underwriters Now Demand EDR Telemetry Before Binding

Self-reported security questionnaires are dead. Coalition, At-Bay, and Corvus now require EDR telemetry, MFA logs, and backup restore proofs before binding. A practitioner guide to what evidence underwriters demand at renewal — and what happens to the premium when it is missing.

Self-reported security questionnaires are dead. Coalition, At-Bay, and Corvus now require EDR telemetry, MFA logs, and backup restore proofs before binding. A practitioner guide to what evidence underwriters demand at renewal — and what happens to the premium when it is missing.

For fifteen years I signed off on cyber risks the same way every underwriter did: I sent a 180-question security questionnaire, the insured’s IT manager answered “yes” to most of it, and I priced the risk on the strength of those answers. Then I spent a year embedded with a claims team adjusting losses. That year broke my faith in the questionnaire more thoroughly than any market cycle ever did.

Here is the uncomfortable truth the claims data keeps confirming: what insureds tell us they have, and what their systems actually enforce, are two different things. The gap between them is where the money goes.

This is why carriers like Coalition, At-Bay, and Corvus have stopped trusting self-reported controls — and why, at renewal, your underwriter is now asking for machine-generated evidence instead of ticked boxes. If you broker cyber business, you need to know what that evidence looks like before the binder is on the desk.

The Questionnaire Was Never an Underwriting Instrument

A security questionnaire is self-reported, point-in-time, and unverifiable. That is three failure modes stacked on top of each other, and each one costs claims.

Self-reported. The person filling it in has every incentive to answer favourably. A “yes” on MFA keeps the premium down and the deal moving; a “no” triggers a declination or a punitive sublimit. We have trained the market to give us the answers we want, and then we are surprised when the loss data reflects those answers rather than reality.

Point-in-time. A questionnaire signed in January describes the estate as it existed on the day someone read it. By the time the policy incepts, three cloud tenants have been added, a contractor has been onboarded, and the EDR agent on the finance director’s laptop has been silently uninstalled by an overenthusiastic cleaner application. The attestation expired the moment it was printed.

Unverifiable. “We have immutable backups.” Did you test a restore in the last quarter? “We run security awareness training.” What is the simulated phishing click rate? “MFA is enforced.” On which percentage of accounts — privileged ones, or all of them? A questionnaire cannot answer follow-up questions, and the answers it does give cannot be checked against the estate.

The claims data exposes the cost. Coalition’s claims analysis has repeatedly shown that in ransomware events where the insured reported “backups in place,” a substantial share could not recover cleanly because those backups were online, credentials-controlled, or simply never tested. At-Bay has published that organisations with exposed remote desktop protocol faced roughly three times the ransomware frequency of those without — a fact no questionnaire reliably captured, because insureds did not consider one exposed port worth disclosing.

When the same carriers began scoring risks off active scans rather than spreadsheets, the correlation between real exposure and loss became obvious. The questionnaire was screening out the wrong things. Coalition went further still: in several markets it made its security-control questions optional for smaller clients, preferring to read the insured’s posture from its own security telemetry and scanning rather than from the insured’s own answers. That decision is the whole thesis, enacted by a carrier.

What Underwriters Demand Before Binding

The shift is not subtle. The artefacts that move a file from “quoted” to “bound” have changed, and brokers who arrive at renewal with a refreshed PDF questionnaire are arriving unarmed. Here is what the desk now expects.

EDR telemetry, not “antivirus.” “We have endpoint protection” means nothing on its own. Underwriters want evidence that an EDR agent — CrowdStrike, SentinelOne, Microsoft Defender for Endpoint or Defender for Business — is deployed across the estate and, critically, that it is reporting. We look for agent coverage as a percentage of endpoints, detection telemetry over a trailing window, and whether the platform sits in prevention or detect-and-respond mode. A 100% deployment with 12% of agents silent for more than seven days is worse than a 90% deployment that is awake. Silent agents are unmanaged endpoints, and unmanaged endpoints are where the attacker lands.

MFA logs, not the word “yes.” The single most contested attestation in cyber insurance is “MFA enforced.” Underwriters now want the authentication log or the conditional-access policy export that proves it. The threshold that matters is coverage of all accounts — and the unprivileged ones count. A common finding, and the one that drives the most denials, is MFA on global administrators and a handful of executives, with the remaining 60% of accounts protected by a single password. We do not accept “MFA on critical accounts,” because the claims data shows the attacker does not target the critical account; they target the account that lets them become critical.

Backup immutability proof. Saying you have backups and proving you can restore from them are different transactions. Carriers want an immutable or air-gapped copy, a restore test dated within the quarter, and evidence that the backup control plane is not reachable with the same credentials as the production estate — the exact failure mode that turned “we have backups” into a full ransomware payout at carriers across the market. The absence of secure, tested backups remains one of the strongest predictors of a paid ransom, and the carriers that scan for it price accordingly.

Incident-response readiness, demonstrated. More binders now carry a warranty or condition precedent requiring a documented and tested incident-response plan plus a named retainer. At-Bay has tied ransomware coverage to specific control requirements, and the market has followed: a tabletop within the last twelve months, a signed retainer with an incident-response firm, and a tested out-of-band communications channel. A plan that exists only as a Word document in a shared drive the attacker can reach fails this test by definition.

The pattern across all four is the same. Each asks for telemetry and demonstration, not assertion. The underwriter is no longer rating the insured’s stated posture; they are rating the evidence of it.

When the Evidence Is Missing — the Premium, the Sublimit, and the Denial

What happens when the broker cannot produce this evidence is where the renewal turns. Three outcomes, in increasing order of severity.

The premium load. A file that arrives without EDR coverage data or MFA logs does not get declined — it gets loaded. In the current market a missing-control adjustment commonly adds 15–25% to the indicative premium, with the ransomware sublimit cut to a quarter or a sixth of the primary limit. On a €2,000,000 cyber programme quoting around €48,000, that is the difference between €48,000 and roughly €58,000, with ransomware capped at €300,000 instead of €1,000,000. The broker who gathered the evidence pays €48,000; the broker who did not pays €58,000 for demonstrably worse coverage. The client rarely understands that the two submissions were the same risk, separated only by the paperwork.

The warranty and the coinsurance. The harder change is the control warranty now embedded in wordings across the market. The clause reads, in substance: if a ransomware or funds-transfer loss occurs and the named controls — MFA on all accounts, EDR on all endpoints, tested immutable backup — were not in force at the time of loss, the limit for that loss is reduced to the stated sublimit (often 25% or less of the primary) and a coinsurance of 30–50% applies to what remains. This is no longer a pricing lever. It is a coverage lever, and it survives renewal even when the premium looks competitive.

The denial. The case that settled the argument for me was a funds-transfer fraud loss at a mid-sized professional-services firm. The insured had attested, at bind and again at renewal, that “MFA is enforced across the organisation.” During the claim investigation the carrier pulled the tenant’s authentication logs. MFA was active on 40% of accounts — the executives and IT, exactly the accounts that never get phished. The finance controller who authorised the €410,000 wire sat on a password-only account. The attacker had taken that account eight weeks earlier and waited.

The wording contained a condition precedent requiring MFA on all human accounts. Coverage was declined. The insured’s own misrepresentation — a box they had ticked confidently for three years — was the reason the €410,000 stayed on their balance sheet. A controls gap that would have cost roughly €18,000 a year to close (licensing plus a conditional-access policy) produced a €410,000 uninsured loss. That ratio is the entire case for telemetry over attestation, in one number.

The Broker’s Renewal Action List

If you broker cyber, your job at renewal is no longer to collect answers; it is to assemble evidence. Six items, gathered before you approach the market:

  1. EDR coverage report. A console export showing agent count, percentage of endpoints covered, and any agent offline for more than seven days. Redact hostnames; keep counts and timestamps.
  2. MFA enforcement proof. The conditional-access policy or authentication summary demonstrating MFA on all human accounts, with coverage expressed as a percentage. This is the document that moves the sublimit back up.
  3. Backup restore evidence. Dated restore-test output from the last quarter, plus confirmation the backup control plane is credential-isolated from production. This is the single highest-value artefact for ransomware sublimits.
  4. Attack-surface scan. A current external scan — exposed RDP, open management interfaces, expired certificates, exposed cloud storage. At-Bay and Corvus run their own; arriving with yours means you frame the finding before they do. You can generate one in seconds with our domain exposure tool.
  5. IR readiness. A tabletop date within the last twelve months and a signed IR retainer. A one-page summary beats a fifty-page plan.
  6. A quantified exposure view. Carry a euro-denominated loss estimate calibrated to the insured’s sector and size, so the underwriter’s pricing decision is anchored to your number rather than theirs. The broker scorecard produces this in under a minute, and the FAIR-aligned risk report supplies the full loss exceedance curve the desk now expects.

The artefacts that carry third-party weight — the IR retainer, the penetration test, the external scan — should be supplemented rather than self-attested wherever the wording carries a warranty. Where a control genuinely cannot be evidenced, say so and price the sublimit honestly. Underwriters decline submissions that misrepresent; they quote the ones that are candid about a gap.

The Questionnaire Is Not Coming Back

The carriers that priced off self-reported controls learned, painfully, that the questionnaire measured the insured’s optimism, not the insured’s exposure. The ones still standing measure the exposure directly — through telemetry, through scans, through logs that do not know how to be optimistic.

For brokers the implication is mechanical. The asset at renewal is no longer the completed form; it is the evidence packet behind it. Build that packet once, keep it current, and the renewal becomes a pricing conversation. Arrive without it, and the renewal becomes a coverage conversation — which is always the more expensive of the two.

If you are not yet scoring your clients against the controls the underwriter will actually check, the risk register maps each named control to its coverage consequence, so you can see — before the market does — which box your client can honestly tick, and which one is about to cost them.

This article reflects practitioner experience and is not underwriting, legal, or coverage advice. Coverage terms, sublimits, and control warranties vary by carrier and jurisdiction; always review the specific policy wording.

Interactive: The Attack Chain

Click any stage to see the control gap, coverage impact, and financial exposure. Drag to pan, scroll to zoom.

Michael Guiao Michael Guiao founded Resiliently AI and writes Resiliently. He has CISM, CCSP, CISA, and DPO certifications — but let them lapse, because in the age of AI, knowledge is cheap. What matters is judgment, and that comes from eight years of hands-on work at Zurich, Sompo, AXA, and PwC.

Get the full picture with premium access

In-depth reports, assessment tools, and weekly risk intelligence for cyber professionals.

Starter

€199 /month

Unlimited scans, submission packets, PDF downloads, NIS2/DORA

View Plans →
Best Value

Professional

€490 /month

Full platform — continuous monitoring, API access, white-label reports

Everything in Starter plus professional tools

Upgrade Now →
30-day money-back
Secure via Stripe
Cancel anytime

Free NIS2 Compliance Checklist

Get the free 15-point PDF checklist + NIS2 compliance tips in your inbox.

No spam. Unsubscribe anytime. Privacy Policy

blog.featured

The Death of the Questionnaire: Why Underwriters Now Demand EDR Telemetry Before Binding

Underwriting ·

10 min read

WordPress Plugin Flaw CVE-2023-4213 Exposes 10K+ Sites to Cyber Claims

Cyber Risk ·

6 min read

WordPress Plugin XSS Vulnerability Exposes Cyber Insurance Portfolios to Persistent Web Risks

Cyber Risk ·

5 min read

WordPress Security Plugin Flaw Exposes Organizations to Cyber Claims

Cyber Risk ·

6 min read

Premium Report

2026 Cyber Risk Landscape Report

24 pages of threat analysis, claims data, and underwriting implications for European cyber insurance.

View Reports →

Related posts

The Five Toxic Powers of Agentic AI — What Underwriters Need to Know
Agentic AI · · 11 min read

The Five Toxic Powers of Agentic AI — What Underwriters Need to Know

Agentic AI introduces five double-edged powers that create toxic risk combinations. Here's how underwriters, brokers, and CISOs should assess the threat.

Agentic Security: What Underwriters Need to Know in 2026
Agentic AI · · 9 min read

Agentic Security: What Underwriters Need to Know in 2026

Autonomous AI agents are entering production at scale — and they bring a completely new attack surface that traditional cyber insurance questionnaires weren't designed to capture.

An AI Agent Deleted a Startup's Production Database — Can You Insure Against That?
AI Agents · · 7 min read

An AI Agent Deleted a Startup's Production Database — Can You Insure Against That?

PocketOS lost its production database to a Cursor AI agent in 9 seconds. The incident exposes a gap in cyber insurance that most policies don't cover: AI-caused operational destruction with no external attacker.