The short answer for a software company approaching renewal: policy terms follow what you can prove in documentation, not what you write on the form. A company arriving with operational evidence is priced as a measured risk, and a company arriving with intentions is priced as uncertainty.

Key Takeaways

  • Two questions move pricing more than any others: where multi-factor authentication is enforced, and when recovery from backup was last tested. Underwriters look for enforcement across mailboxes, remote access, cloud management consoles and code repositories, and for a backup copy the attacker’s encryption tools could not reach.
  • Data from 2026 points to an average cost of around 5 million dollars per data breach, a record, an increase of 12%. Data from 2026 also shows that the average time to identify and contain an incident rose to roughly 247 days, so underwriters test detection capability with the same seriousness they apply to prevention.
  • An Israeli company is also measured against the Privacy Protection Regulations (Data Security), which require a managerial framework around the database: a database definitions document, a security procedure, periodic risk assessment, appointment of a data security officer in certain organisations, and reporting of a severe security incident to the Privacy Protection Authority. Amendment 13 to the Privacy Protection Law strengthened enforcement powers and raised the weight of internal documentation.
  • The underwriter also examines the commercial side: the volume of personal data records, where they are stored, how revenue is spread across clients, and dependency on a single cloud provider. A client generating more than a fifth of revenue changes the business interruption calculation, and the insurance confirmation required by that client’s contract sometimes sets the limit of liability.

What Actually Changed in Cyber Underwriting for Software Companies

Until a few years ago the cyber questionnaire held twenty broad questions about the nature of the business and the volume of data. Today it tests specific controls and asks for evidence of them, much like the vendor review a large enterprise client runs. The shift comes from claims experience: the underwriting market learned which controls actually reduce loss, and prices accordingly.

The underwriter builds two assessments in parallel, one for frequency and one for severity. Frequency follows from the external attack surface, from identity hygiene, and from how quickly the organisation detects an intrusion. Severity follows from the volume of personal data the company holds and from how fast an outage converts into lost revenue. Data from 2026 points to an average cost of around 5 million dollars per data breach, a record, an increase of 12%. According to 2026 data, the cost of a data breach in the United States runs at more than double the global average. For an Israeli software company whose clients are mostly American, that figure translates directly into the limit worth requesting. Some underwriters scan the applicant’s external attack surface before the first call, and arrive with a list of findings already in hand.

Underwriting questions look fairly similar across channels, partly because a large share of the technical capability in this line sits in the Lloyd’s market. A company that prepares one organised answer can use it with several markets and compare terms on identical ground.

The Technical Questions and What Sits Behind Them

Every question in the questionnaire tests a particular loss scenario rather than filling a box. Whoever recognises the scenario behind the question answers in a way that lowers perceived risk, and whoever simply ticks yes or no gets the conservative reading.

Multi-Factor Authentication: Which Assets It Is Enforced On

A yes on multi-factor authentication barely moves pricing. The underwriter wants to know whether enforcement covers mailboxes, remote access, cloud management consoles, code repositories and internal admin interfaces, and whether legacy accounts remain excluded from the policy. One old service account without authentication is the path attackers look for, and it is also the detail that surfaces in the investigation after an incident.

Backups: The Test Is the Date of the Last Restore

The question that separates organisations is when a full restore from backup was last performed and how long it took. Underwriters look for an immutable copy, offline or segregated from the operational network, one the attacker’s encryption tools could not reach. A recovery time objective written into a document and never tested is treated as a statement and nothing more.

Encryption and Key Management

The question covers data at rest and data in transit, but the real weight sits in key management. An underwriter will ask who holds the keys, whether a documented rotation process exists, and whether production keys are separated from development environments. An organisation managing keys in a dedicated cloud provider service with separation of duties stands in a better place than one keeping them in a configuration file.

Incident Response: A Plan That Has Been Exercised

An incident response plan is measured by the date of the last exercise and by the identity of the person in charge. The underwriter will ask who decides to take a system offline, who speaks to clients and to the Privacy Protection Authority, and who is authorised to approve spending in the first hour. Data from 2026 shows that the average time to identify and contain an incident rose to roughly 247 days, and every one of those days rolls into the cost of the claim.

Vulnerability Management, Patching and Access

These two families are examined together because they describe the same operational discipline. On vulnerabilities the underwriter will ask the target time to remediate a high severity finding, how often scanning runs, and whether it covers third-party libraries too. On access the question is how long it takes to revoke a departing employee’s access, and whether privileged access is managed in a separate system with an audit trail. An answer that rests on a manual process with no automated control reads as open risk.

What to Prepare in Advance for Each Underwriting Topic

The table brings together the nine topics that recur in almost every cyber questionnaire for a software company, what the underwriter is really trying to learn from each, the document worth bringing with you, and the red flag that pushes terms upward.

What the underwriter asks on each topic, what to prepare, and what counts as a red flag:

Underwriting topic What the underwriter really asks What to prepare in advance Red flag
Multi-factor authentication Which systems enforcement covers, and which accounts were excluded A screenshot of the enforcement policy from the identity provider and an approved exception list Authentication available to users but not enforced by policy, alongside open legacy accounts
Backups and recovery When a full restore was last performed, how long it took, and whether the copy is segregated The last restore test report with date and duration, and a description of the immutable copy A backup held in the same environment and under the same permissions as production systems
Encryption and key management Who holds the keys and how rotation is performed A key management procedure and documented separation between production and development Keys sitting in configuration files or in repository history
Incident response When the last exercise was run and who leads the incident A plan with a named owner and an escalation tree, alongside the record of the last exercise A plan written for a previous questionnaire and never updated since
Vulnerability management and patching The target time to remediate a high severity finding and the scanning cadence A remediation policy by severity and a periodic scan report Patching driven only by customer complaints
Access management How long it takes to revoke a departing employee’s access A joiner and leaver procedure and a current list of privileged accounts Blanket administrator rights for the whole development team in production
Personal data volume How many records, in which jurisdictions, and which sensitive categories A database map by data type, storage location and record volume A verbal estimate with no written map and no owner for the figure
Cloud and third-party dependency Who the essential suppliers are and what happens in an extended outage A list of essential suppliers, contractual recovery times and a continuity plan Single provider dependency with no written fallback scenario
Revenue and client concentration What annual revenue is and whether any single client exceeds a fifth of it A revenue report by client and an estimate of lost revenue per day of downtime A revenue per day figure that was never calculated

Personal Data, Cloud Dependency and Client Concentration

These three topics set severity, and therefore they set the limit of liability and the price of business interruption cover. A software company holding millions of records for enterprise clients in the United States and Europe is priced differently from one holding hundreds of thousands in Israel alone.

A single client generating more than a fifth of revenue turns business interruption from a statistical scenario into a concrete one.

Cloud dependency is examined in two layers: what happens when the primary infrastructure provider goes down, and what happens when a SaaS provider sitting at the core of the service goes down. An underwriter will ask whether a multi-region architecture exists and what recovery time the provider committed to in contract. Many companies discover at this point that they never calculated revenue per day of downtime, and without that number it is hard to justify a request for a higher limit.

What Israeli Regulation Adds to the Questionnaire

An Israeli company is also measured against the Privacy Protection Regulations (Data Security), which require a complete managerial framework around the database. The regulations call for a database definitions document, a data security procedure, periodic risk assessment matched to the security level, access control, appointment of a data security officer in certain organisations, and reporting of a severe security incident to the Privacy Protection Authority. Amendment 13 to the Privacy Protection Law strengthened the Authority’s enforcement powers, which turned internal documentation into an asset in front of the regulator and in front of the underwriter alike.

The table below maps the sources of obligation that actually appear in underwriting questionnaires for Israeli software companies.

Regulatory and contractual anchors and how they translate into an underwriting question:

Source of obligation What it actually requires How it appears in the questionnaire
Privacy Protection Regulations (Data Security) A database definitions document, a security procedure, periodic risk assessment and access control A question about a documented managerial framework and a named owner for data security
Reporting duty to the Privacy Protection Authority Reporting a severe security incident and running an orderly notification procedure A question about the regulatory reporting path inside the incident response plan
Amendment 13 to the Privacy Protection Law Broader enforcement powers and greater weight on internal documentation A question about audit readiness and the allocation of managerial responsibility
GDPR A lawful basis for processing, data processing agreements and breach notification A question about European clients and the volume of European records
NIS2 and DORA ICT supplier risk management and operational resilience at supervised European entities A question about selling to banks, insurers and supervised infrastructure in Europe
SOC 2 and ISO 27001 An attestation report from an independent CPA firm, or a certified management system standard A question about the scope of controls and the period the report covers
NIST and OWASP Frameworks for security controls and secure development A question about the standard the company built its security programme around
Insurance confirmation Matching limits, lines and clauses to the requirement in the client contract A question about contractual insurance requirements that set the limit of liability

Where the Questionnaire Meets the Client Contract

The insurance requirements in an enterprise client contract often set the limit of liability more decisively than any internal risk assessment. A clause requiring cyber and professional liability cover at a stated limit, together with an insurance confirmation in the client’s own format, turns the policy into a commercial condition for closing the deal. The broker (LAMDA Broking) and legal counsel compare the policy wording against the contract clauses, in order to find gaps between what the contract demands and what the wording delivers.

A common gap sits between the definition of a covered event and the definition of a security breach in the contract, and in the waiting period on business interruption cover. A contract promising 99.9% availability against a policy carrying a twelve hour waiting period creates a shortfall the company absorbs. Reviewing both documents together in advance saves renegotiation in the middle of an incident.

Common Mistakes

  • Ticking yes on multi-factor authentication when it is available to users but not enforced by policy.
  • Presenting a daily backup as proof of recovery, with no documented restore test carrying a date and a duration, and then discovering during a ransomware event that the copy was reachable by the same permissions that encrypted production.
  • Treating SOC 2 as a certification. It is an attestation report issued by an independent CPA firm against AICPA criteria, covering a defined period and controls the organisation itself defined.
  • Completing the questionnaire in the finance team without the head of information security, and sending answers the technical team would have phrased differently.
  • Reporting the number of personal data records from memory, with no written database map.
  • Arriving at renewal a week before expiry, when there is no time left to fix a finding the underwriter flags.
  • Skipping the calculation of revenue per day of downtime, then requesting a limit with no numerical basis.
  • Signing a contract carrying an insurance requirement that was never checked against the existing policy wording.

Professional Checklist

  1. Enforce multi-factor authentication on mailboxes, remote access, cloud management consoles and code repositories, and produce an exception report.
  2. Close legacy and service accounts without authentication, and document every remaining exception with a justification and a review date.
  3. Run a full restore test every quarter, and record the duration and the percentage of data recovered.
  4. Keep an immutable backup copy, separated from production environment permissions.
  5. Write a key management procedure with rotation, and separate production keys from development and test environments.
  6. Run a tabletop incident response exercise once a year, with a management representative and legal counsel present.
  7. Define in the response plan the reporting path to the Privacy Protection Authority and who approves it.
  8. Set target remediation times for vulnerabilities by severity, and measure compliance every month.
  9. Cut the time to revoke a departing employee’s access to one business day, and back the process with an automated control.
  10. Map personal data stores by data type, storage location and record volume, and refresh the map every six months.
  11. Calculate revenue per day of downtime, and build the requested limit of liability on that figure.
  12. List essential suppliers and the recovery times they committed to in their contracts with you.
  13. Compare the insurance requirements in client contracts against the policy wording before signing the contract.
  14. Open the underwriting questionnaire with the security team ninety days before the renewal date.
  15. Keep a single evidence folder holding every document the underwriter asked for last year.

Frequently Asked Questions

Can a company obtain cyber insurance without full multi-factor authentication enforcement?

In most channels today, enforcement across email and cloud management consoles is a threshold condition. A company missing enforcement on some assets can still receive an offer, usually with a higher deductible or with a subjectivity requiring completion within ninety days. The practical route is to complete enforcement before submission, because the cost of doing so is normally lower than the premium gap it creates.

How long does it take to prepare for an underwriting questionnaire?

An organization already running the controls finishes in two weeks, and most of the work is gathering evidence. An organization that still needs to complete authentication enforcement and a restore test needs sixty to ninety days, because some evidence requires a real action rather than a document. A restore has to be performed, and a response exercise has to be run before a record can be attached. Opening the process three months before renewal leaves room to fix findings.

What is the difference between a SOC 2 report and the underwriting questionnaire?

SOC 2 is an attestation report issued by an independent CPA firm against AICPA criteria, covering a defined period and controls the organization itself chose to assert. The underwriting questionnaire tests points tied directly to the loss scenarios the insurer carries, so it goes into detail the report does not always contain. An existing report shortens the discussion and builds confidence, and it does not replace the technical answers.

Does an insurance requirement in a client contract change the cover you need?

It frequently determines it. An insurance clause in an enterprise contract sets a limit of liability, the lines required, and sometimes a binding format for the insurance confirmation. A company that signs before checking the requirement against its policy discovers the gap at the point where the client already expects a signed confirmation. Comparing both documents before signature prevents that situation.

What is expected of the board on cyber?

The SEC disclosure rules from 2023 require public companies to describe how the board exercises oversight of cyber risk. The proposal to require disclosure of cyber expertise among board members was dropped from the final text. In private companies with investors and enterprise clients the expectation is similar in substance: a discussion recorded in the minutes, metrics presented to management, and a remediation plan with dates.

Does dependency on a single cloud provider rule out business interruption cover?

It does not rule it out, but it changes pricing and definitions. Underwriters examine the outage duration at which cover begins and the dependency on third-party services sitting at the core of the product. A company presenting a written fallback scenario and a recovery plan usually receives a shorter waiting period. A company without an organised answer receives a sub-limit for supplier-originated events.

What happens when you tell an underwriter that something is in progress?

That answer is priced against the worst case, because the underwriter cannot verify what already exists. It is better to set out what is complete, what remains and the timetable for finishing, and to attach a document showing real progress. Underwriters accept a work plan with dates, and will sometimes grant a subjectivity instead of an exclusion. A vague answer with no target date reads as open risk.

The cyber insurance terms a software company receives are set by the controls it can prove in documentation on the day it submits the questionnaire, and not by the ones it plans to implement afterwards.

The above is general information only and does not constitute insurance, legal or other professional advice. Terms of cover, exclusions and duties are set by the specific policy wording and by applicable law. Each case should be assessed on its own facts against the policy wording and with a qualified adviser.