{"id":20354,"date":"2026-09-02T13:41:06","date_gmt":"2026-09-02T10:41:06","guid":{"rendered":"https:\/\/lamdabroking.com\/?p=20354"},"modified":"2026-09-02T14:18:18","modified_gmt":"2026-09-02T11:18:18","slug":"cyber-insurance-for-software-companies-underwriting-questions","status":"publish","type":"post","link":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/","title":{"rendered":"Cyber Insurance for Software Companies: Underwriting Questions"},"content":{"rendered":"<p dir=\"ltr\"><span style=\"font-weight: 400;\">The short answer for a software company approaching renewal: policy terms follow what you can prove in documentation, not what you write on the form. A company arriving with operational evidence is priced as a measured risk, and a company arriving with intentions is priced as uncertainty.<\/span><\/p>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Key Takeaways<\/span><\/h2>\n<ul dir=\"ltr\">\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Two questions move pricing more than any others: where multi-factor authentication is enforced, and when recovery from backup was last tested. Underwriters look for enforcement across mailboxes, remote access, cloud management consoles and code repositories, and for a backup copy the attacker&#8217;s encryption tools could not reach.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data from 2026 points to an average cost of around 5 million dollars per data breach, a record, an increase of 12%. Data from 2026 also shows that the average time to identify and contain an incident rose to roughly 247 days, so underwriters test detection capability with the same seriousness they apply to prevention.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An Israeli company is also measured against the Privacy Protection Regulations (Data Security), which require a managerial framework around the database: a database definitions document, a security procedure, periodic risk assessment, appointment of a data security officer in certain organisations, and reporting of a severe security incident to the Privacy Protection Authority. Amendment 13 to the Privacy Protection Law strengthened enforcement powers and raised the weight of internal documentation.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The underwriter also examines the commercial side: the volume of personal data records, where they are stored, how revenue is spread across clients, and dependency on a single cloud provider. A client generating more than a fifth of revenue changes the business interruption calculation, and the insurance confirmation required by that client&#8217;s contract sometimes sets the limit of liability.<\/span><\/li>\n<\/ul>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">What Actually Changed in Cyber Underwriting for Software Companies<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Until a few years ago the cyber questionnaire held twenty broad questions about the nature of the business and the volume of data. Today it tests specific controls and asks for evidence of them, much like the vendor review a large enterprise client runs. The shift comes from claims experience: the underwriting market learned which controls actually reduce loss, and prices accordingly.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The underwriter builds two assessments in parallel, one for frequency and one for severity. Frequency follows from the external attack surface, from identity hygiene, and from how quickly the organisation detects an intrusion. Severity follows from the volume of personal data the company holds and from how fast an outage converts into lost revenue. Data from 2026 points to an average cost of around 5 million dollars per data breach, a record, an increase of 12%. According to 2026 data, the cost of a data breach in the United States runs at more than double the global average. For an Israeli software company whose clients are mostly American, that figure translates directly into the limit worth requesting. Some underwriters scan the applicant&#8217;s external attack surface before the first call, and arrive with a list of findings already in hand.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Underwriting questions look fairly similar across channels, partly because a large share of the technical capability in this line sits in the Lloyd&#8217;s market. A company that prepares one organised answer can use it with several markets and compare terms on identical ground.<\/span><\/p>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">The Technical Questions and What Sits Behind Them<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Every question in the questionnaire tests a particular loss scenario rather than filling a box. Whoever recognises the scenario behind the question answers in a way that lowers perceived risk, and whoever simply ticks yes or no gets the conservative reading.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Multi-Factor Authentication: Which Assets It Is Enforced On<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">A yes on multi-factor authentication barely moves pricing. The underwriter wants to know whether enforcement covers mailboxes, remote access, cloud management consoles, code repositories and internal admin interfaces, and whether legacy accounts remain excluded from the policy. One old service account without authentication is the path attackers look for, and it is also the detail that surfaces in the investigation after an incident.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Backups: The Test Is the Date of the Last Restore<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The question that separates organisations is when a full restore from backup was last performed and how long it took. Underwriters look for an immutable copy, offline or segregated from the operational network, one the attacker&#8217;s encryption tools could not reach. A recovery time objective written into a document and never tested is treated as a statement and nothing more.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Encryption and Key Management<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The question covers data at rest and data in transit, but the real weight sits in key management. An underwriter will ask who holds the keys, whether a documented rotation process exists, and whether production keys are separated from development environments. An organisation managing keys in a dedicated cloud provider service with separation of duties stands in a better place than one keeping them in a configuration file.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Incident Response: A Plan That Has Been Exercised<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">An incident response plan is measured by the date of the last exercise and by the identity of the person in charge. The underwriter will ask who decides to take a system offline, who speaks to clients and to the Privacy Protection Authority, and who is authorised to approve spending in the first hour. Data from 2026 shows that the average time to identify and contain an incident rose to roughly 247 days, and every one of those days rolls into the cost of the claim.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Vulnerability Management, Patching and Access<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">These two families are examined together because they describe the same operational discipline. On vulnerabilities the underwriter will ask the target time to remediate a high severity finding, how often scanning runs, and whether it covers third-party libraries too. On access the question is how long it takes to revoke a departing employee&#8217;s access, and whether privileged access is managed in a separate system with an audit trail. An answer that rests on a manual process with no automated control reads as open risk.<\/span><\/p>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">What to Prepare in Advance for Each Underwriting Topic<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The table brings together the nine topics that recur in almost every cyber questionnaire for a software company, what the underwriter is really trying to learn from each, the document worth bringing with you, and the red flag that pushes terms upward.<\/span><\/p>\n<p dir=\"ltr\"><b>What the underwriter asks on each topic, what to prepare, and what counts as a red flag:<\/b><\/p>\n<table dir=\"ltr\">\n<tbody>\n<tr>\n<td><b>Underwriting topic<\/b><\/td>\n<td><b>What the underwriter really asks<\/b><\/td>\n<td><b>What to prepare in advance<\/b><\/td>\n<td><b>Red flag<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Multi-factor authentication<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Which systems enforcement covers, and which accounts were excluded<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A screenshot of the enforcement policy from the identity provider and an approved exception list<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Authentication available to users but not enforced by policy, alongside open legacy accounts<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Backups and recovery<\/span><\/td>\n<td><span style=\"font-weight: 400;\">When a full restore was last performed, how long it took, and whether the copy is segregated<\/span><\/td>\n<td><span style=\"font-weight: 400;\">The last restore test report with date and duration, and a description of the immutable copy<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A backup held in the same environment and under the same permissions as production systems<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Encryption and key management<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Who holds the keys and how rotation is performed<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A key management procedure and documented separation between production and development<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Keys sitting in configuration files or in repository history<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Incident response<\/span><\/td>\n<td><span style=\"font-weight: 400;\">When the last exercise was run and who leads the incident<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A plan with a named owner and an escalation tree, alongside the record of the last exercise<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A plan written for a previous questionnaire and never updated since<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Vulnerability management and patching<\/span><\/td>\n<td><span style=\"font-weight: 400;\">The target time to remediate a high severity finding and the scanning cadence<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A remediation policy by severity and a periodic scan report<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Patching driven only by customer complaints<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Access management<\/span><\/td>\n<td><span style=\"font-weight: 400;\">How long it takes to revoke a departing employee&#8217;s access<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A joiner and leaver procedure and a current list of privileged accounts<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Blanket administrator rights for the whole development team in production<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Personal data volume<\/span><\/td>\n<td><span style=\"font-weight: 400;\">How many records, in which jurisdictions, and which sensitive categories<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A database map by data type, storage location and record volume<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A verbal estimate with no written map and no owner for the figure<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Cloud and third-party dependency<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Who the essential suppliers are and what happens in an extended outage<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A list of essential suppliers, contractual recovery times and a continuity plan<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Single provider dependency with no written fallback scenario<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Revenue and client concentration<\/span><\/td>\n<td><span style=\"font-weight: 400;\">What annual revenue is and whether any single client exceeds a fifth of it<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A revenue report by client and an estimate of lost revenue per day of downtime<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A revenue per day figure that was never calculated<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Personal Data, Cloud Dependency and Client Concentration<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">These three topics set severity, and therefore they set the limit of liability and the price of business interruption cover. A software company holding millions of records for enterprise clients in the United States and Europe is priced differently from one holding hundreds of thousands in Israel alone.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">A single client generating more than a fifth of revenue turns business interruption from a statistical scenario into a concrete one.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">Cloud dependency is examined in two layers: what happens when the primary infrastructure provider goes down, and what happens when a SaaS provider sitting at the core of the service goes down. An underwriter will ask whether a multi-region architecture exists and what recovery time the provider committed to in contract. Many companies discover at this point that they never calculated revenue per day of downtime, and without that number it is hard to justify a request for a higher limit.<\/span><\/p>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">What Israeli Regulation Adds to the Questionnaire<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">An Israeli company is also measured against the Privacy Protection Regulations (Data Security), which require a complete managerial framework around the database. The regulations call for a database definitions document, a data security procedure, periodic risk assessment matched to the security level, access control, appointment of a data security officer in certain organisations, and reporting of a severe security incident to the Privacy Protection Authority. Amendment 13 to the Privacy Protection Law strengthened the Authority&#8217;s enforcement powers, which turned internal documentation into an asset in front of the regulator and in front of the underwriter alike.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The table below maps the sources of obligation that actually appear in underwriting questionnaires for Israeli software companies.<\/span><\/p>\n<p dir=\"ltr\"><b>Regulatory and contractual anchors and how they translate into an underwriting question:<\/b><\/p>\n<table dir=\"ltr\">\n<tbody>\n<tr>\n<td><b>Source of obligation<\/b><\/td>\n<td><b>What it actually requires<\/b><\/td>\n<td><b>How it appears in the questionnaire<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Privacy Protection Regulations (Data Security)<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A database definitions document, a security procedure, periodic risk assessment and access control<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A question about a documented managerial framework and a named owner for data security<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Reporting duty to the Privacy Protection Authority<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Reporting a severe security incident and running an orderly notification procedure<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A question about the regulatory reporting path inside the incident response plan<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Amendment 13 to the Privacy Protection Law<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Broader enforcement powers and greater weight on internal documentation<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A question about audit readiness and the allocation of managerial responsibility<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">GDPR<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A lawful basis for processing, data processing agreements and breach notification<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A question about European clients and the volume of European records<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">NIS2 and DORA<\/span><\/td>\n<td><span style=\"font-weight: 400;\">ICT supplier risk management and operational resilience at supervised European entities<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A question about selling to banks, insurers and supervised infrastructure in Europe<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">SOC 2 and ISO 27001<\/span><\/td>\n<td><span style=\"font-weight: 400;\">An attestation report from an independent CPA firm, or a certified management system standard<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A question about the scope of controls and the period the report covers<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">NIST and OWASP<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Frameworks for security controls and secure development<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A question about the standard the company built its security programme around<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Insurance confirmation<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Matching limits, lines and clauses to the requirement in the client contract<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A question about contractual insurance requirements that set the limit of liability<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Where the Questionnaire Meets the Client Contract<\/span><\/h2>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The insurance requirements in an enterprise client contract often set the limit of liability more decisively than any internal risk assessment. A clause requiring cyber and professional liability cover at a stated limit, together with an insurance confirmation in the client&#8217;s own format, turns the policy into a commercial condition for closing the deal. The broker (<a href=\"https:\/\/lamdabroking.com\/en\/about-lamda-an-insurance-broker\/\">LAMDA Broking<\/a>) and legal counsel compare the policy wording against the contract clauses, in order to find gaps between what the contract demands and what the wording delivers.<\/span><\/p>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">A common gap sits between the definition of a covered event and the definition of a security breach in the contract, and in the waiting period on business interruption cover. A contract promising 99.9% availability against a policy carrying a twelve hour waiting period creates a shortfall the company absorbs. Reviewing both documents together in advance saves renegotiation in the middle of an incident.<\/span><\/p>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Common Mistakes<\/span><\/h2>\n<ul dir=\"ltr\">\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ticking yes on multi-factor authentication when it is available to users but not enforced by policy.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Presenting a daily backup as proof of recovery, with no documented restore test carrying a date and a duration, and then discovering during a ransomware event that the copy was reachable by the same permissions that encrypted production.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Treating SOC 2 as a certification. It is an attestation report issued by an independent CPA firm against AICPA criteria, covering a defined period and controls the organisation itself defined.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Completing the questionnaire in the finance team without the head of information security, and sending answers the technical team would have phrased differently.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reporting the number of personal data records from memory, with no written database map.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Arriving at renewal a week before expiry, when there is no time left to fix a finding the underwriter flags.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Skipping the calculation of revenue per day of downtime, then requesting a limit with no numerical basis.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Signing a contract carrying an insurance requirement that was never checked against the existing policy wording.<\/span><\/li>\n<\/ul>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Professional Checklist<\/span><\/h2>\n<ol dir=\"ltr\">\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enforce multi-factor authentication on mailboxes, remote access, cloud management consoles and code repositories, and produce an exception report.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Close legacy and service accounts without authentication, and document every remaining exception with a justification and a review date.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Run a full restore test every quarter, and record the duration and the percentage of data recovered.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keep an immutable backup copy, separated from production environment permissions.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Write a key management procedure with rotation, and separate production keys from development and test environments.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Run a tabletop incident response exercise once a year, with a management representative and legal counsel present.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define in the response plan the reporting path to the Privacy Protection Authority and who approves it.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Set target remediation times for vulnerabilities by severity, and measure compliance every month.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cut the time to revoke a departing employee&#8217;s access to one business day, and back the process with an automated control.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Map personal data stores by data type, storage location and record volume, and refresh the map every six months.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Calculate revenue per day of downtime, and build the requested limit of liability on that figure.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">List essential suppliers and the recovery times they committed to in their contracts with you.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compare the insurance requirements in client contracts against the policy wording before signing the contract.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open the underwriting questionnaire with the security team ninety days before the renewal date.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keep a single evidence folder holding every document the underwriter asked for last year.<\/span><\/li>\n<\/ol>\n<h2 dir=\"ltr\"><span style=\"font-weight: 400;\">Frequently Asked Questions<\/span><\/h2>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Can a company obtain cyber insurance without full multi-factor authentication enforcement?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">In most channels today, enforcement across email and cloud management consoles is a threshold condition. A company missing enforcement on some assets can still receive an offer, usually with a higher deductible or with a subjectivity requiring completion within ninety days. The practical route is to complete enforcement before submission, because the cost of doing so is normally lower than the premium gap it creates.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">How long does it take to prepare for an underwriting questionnaire?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">An organization already running the controls finishes in two weeks, and most of the work is gathering evidence. An organization that still needs to complete authentication enforcement and a restore test needs sixty to ninety days, because some evidence requires a real action rather than a document. A restore has to be performed, and a response exercise has to be run before a record can be attached. Opening the process three months before renewal leaves room to fix findings.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">What is the difference between a SOC 2 report and the underwriting questionnaire?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">SOC 2 is an attestation report issued by an independent CPA firm against AICPA criteria, covering a defined period and controls the organization itself chose to assert. The underwriting questionnaire tests points tied directly to the loss scenarios the insurer carries, so it goes into detail the report does not always contain. An existing report shortens the discussion and builds confidence, and it does not replace the technical answers.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Does an insurance requirement in a client contract change the cover you need?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">It frequently determines it. An insurance clause in an enterprise contract sets a limit of liability, the lines required, and sometimes a binding format for the insurance confirmation. A company that signs before checking the requirement against its policy discovers the gap at the point where the client already expects a signed confirmation. Comparing both documents before signature prevents that situation.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">What is expected of the board on cyber?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">The SEC disclosure rules from 2023 require public companies to describe how the board exercises oversight of cyber risk. The proposal to require disclosure of cyber expertise among board members was dropped from the final text. In private companies with investors and enterprise clients the expectation is similar in substance: a discussion recorded in the minutes, metrics presented to management, and a remediation plan with dates.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">Does dependency on a single cloud provider rule out business interruption cover?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">It does not rule it out, but it changes pricing and definitions. Underwriters examine the outage duration at which cover begins and the dependency on third-party services sitting at the core of the product. A company presenting a written fallback scenario and a recovery plan usually receives a shorter waiting period. A company without an organised answer receives a sub-limit for supplier-originated events.<\/span><\/p>\n<h3 dir=\"ltr\"><span style=\"font-weight: 400;\">What happens when you tell an underwriter that something is in progress?<\/span><\/h3>\n<p dir=\"ltr\"><span style=\"font-weight: 400;\">That answer is priced against the worst case, because the underwriter cannot verify what already exists. It is better to set out what is complete, what remains and the timetable for finishing, and to attach a document showing real progress. Underwriters accept a work plan with dates, and will sometimes grant a subjectivity instead of an exclusion. A vague answer with no target date reads as open risk.<\/span><\/p>\n<p dir=\"ltr\"><b>The <a href=\"https:\/\/lamdabroking.com\/en\/cyber-insurance\/\">cyber insurance<\/a> terms a software company receives are set by the controls it can prove in documentation on the day it submits the questionnaire, and not by the ones it plans to implement afterwards.<\/b><\/p>\n<p dir=\"ltr\"><em><span style=\"font-weight: 400;\">The above is general information only and does not constitute insurance, legal or other professional advice. Terms of cover, exclusions and duties are set by the specific policy wording and by applicable law. Each case should be assessed on its own facts against the policy wording and with a qualified adviser.<\/span><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The cyber insurance questionnaire has stopped being an administrative form and become a technical review. An underwriter looking at a software company now asks where exactly multi-factor authentication is enforced, when a real restore from backup was last performed, who is named as incident lead, and what happens to revenue if the primary cloud provider goes down for two days.<\/p>\n","protected":false},"author":9,"featured_media":20284,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[86],"tags":[],"class_list":["post-20354","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-insurance-en"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyber Insurance for Software Companies: Underwriting Questions<\/title>\n<meta name=\"description\" content=\"Cyber underwriting now tests MFA enforcement, restore tests, encryption, incident response and access control. What to prepare, and the red...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber Insurance for Software Companies: Underwriting Questions\" \/>\n<meta property=\"og:description\" content=\"Cyber underwriting now tests MFA enforcement, restore tests, encryption, incident response and access control. What to prepare, and the red...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/\" \/>\n<meta property=\"og:site_name\" content=\"Lamda - High Tech Insurance\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/lamda.ins\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-02T10:41:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-02T11:18:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design-2.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1672\" \/>\n\t<meta property=\"og:image:height\" content=\"941\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Oded Oded\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Oded Oded\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/\"},\"author\":{\"name\":\"Oded Oded\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#\\\/schema\\\/person\\\/a5b8f4894f9fd6a7a2f3742ba5688174\"},\"headline\":\"Cyber Insurance for Software Companies: Underwriting Questions\",\"datePublished\":\"2026-09-02T10:41:06+00:00\",\"dateModified\":\"2026-09-02T11:18:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/\"},\"wordCount\":3126,\"publisher\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Untitled-design-2.jpg\",\"articleSection\":[\"Cyber insurance\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/\",\"name\":\"Cyber Insurance for Software Companies: Underwriting Questions\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Untitled-design-2.jpg\",\"datePublished\":\"2026-09-02T10:41:06+00:00\",\"dateModified\":\"2026-09-02T11:18:18+00:00\",\"description\":\"Cyber underwriting now tests MFA enforcement, restore tests, encryption, incident response and access control. What to prepare, and the red...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/#primaryimage\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Untitled-design-2.jpg\",\"contentUrl\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Untitled-design-2.jpg\",\"width\":1672,\"height\":941,\"caption\":\"\u05e9\u05d0\u05dc\u05d5\u05df \u05d4\u05d7\u05d9\u05ea\u05d5\u05dd \u05dc\u05d1\u05d9\u05d8\u05d5\u05d7 \u05e1\u05d9\u05d9\u05d1\u05e8\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance-for-software-companies-underwriting-questions\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber insurance\",\"item\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/cyber-insurance\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Cyber Insurance for Software Companies: Underwriting Questions\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/\",\"name\":\"Lamda - High Tech Insurance\",\"description\":\"Risk and Finance Management\",\"publisher\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#organization\",\"name\":\"Lamda - High Tech Insurance\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/lamdaLogo-2.svg\",\"contentUrl\":\"https:\\\/\\\/lamdabroking.com\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/lamdaLogo-2.svg\",\"width\":237,\"height\":102,\"caption\":\"Lamda - High Tech Insurance\"},\"image\":{\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/lamda.ins\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/lamda-risk-and-capital-management\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/#\\\/schema\\\/person\\\/a5b8f4894f9fd6a7a2f3742ba5688174\",\"name\":\"Oded Oded\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g\",\"caption\":\"Oded Oded\"},\"url\":\"https:\\\/\\\/lamdabroking.com\\\/en\\\/author\\\/oded\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyber Insurance for Software Companies: Underwriting Questions","description":"Cyber underwriting now tests MFA enforcement, restore tests, encryption, incident response and access control. What to prepare, and the red...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/","og_locale":"en_US","og_type":"article","og_title":"Cyber Insurance for Software Companies: Underwriting Questions","og_description":"Cyber underwriting now tests MFA enforcement, restore tests, encryption, incident response and access control. What to prepare, and the red...","og_url":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/","og_site_name":"Lamda - High Tech Insurance","article_publisher":"https:\/\/www.facebook.com\/lamda.ins","article_published_time":"2026-09-02T10:41:06+00:00","article_modified_time":"2026-09-02T11:18:18+00:00","og_image":[{"width":1672,"height":941,"url":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design-2.jpg","type":"image\/jpeg"}],"author":"Oded Oded","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Oded Oded","Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/#article","isPartOf":{"@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/"},"author":{"name":"Oded Oded","@id":"https:\/\/lamdabroking.com\/en\/#\/schema\/person\/a5b8f4894f9fd6a7a2f3742ba5688174"},"headline":"Cyber Insurance for Software Companies: Underwriting Questions","datePublished":"2026-09-02T10:41:06+00:00","dateModified":"2026-09-02T11:18:18+00:00","mainEntityOfPage":{"@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/"},"wordCount":3126,"publisher":{"@id":"https:\/\/lamdabroking.com\/en\/#organization"},"image":{"@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/#primaryimage"},"thumbnailUrl":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design-2.jpg","articleSection":["Cyber insurance"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/","url":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/","name":"Cyber Insurance for Software Companies: Underwriting Questions","isPartOf":{"@id":"https:\/\/lamdabroking.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/#primaryimage"},"image":{"@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/#primaryimage"},"thumbnailUrl":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design-2.jpg","datePublished":"2026-09-02T10:41:06+00:00","dateModified":"2026-09-02T11:18:18+00:00","description":"Cyber underwriting now tests MFA enforcement, restore tests, encryption, incident response and access control. What to prepare, and the red...","breadcrumb":{"@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/#primaryimage","url":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design-2.jpg","contentUrl":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2026\/08\/Untitled-design-2.jpg","width":1672,"height":941,"caption":"\u05e9\u05d0\u05dc\u05d5\u05df \u05d4\u05d7\u05d9\u05ea\u05d5\u05dd \u05dc\u05d1\u05d9\u05d8\u05d5\u05d7 \u05e1\u05d9\u05d9\u05d1\u05e8"},{"@type":"BreadcrumbList","@id":"https:\/\/lamdabroking.com\/en\/cyber-insurance-for-software-companies-underwriting-questions\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lamdabroking.com\/en\/"},{"@type":"ListItem","position":2,"name":"Cyber insurance","item":"https:\/\/lamdabroking.com\/en\/cyber-insurance\/"},{"@type":"ListItem","position":3,"name":"Cyber Insurance for Software Companies: Underwriting Questions"}]},{"@type":"WebSite","@id":"https:\/\/lamdabroking.com\/en\/#website","url":"https:\/\/lamdabroking.com\/en\/","name":"Lamda - High Tech Insurance","description":"Risk and Finance Management","publisher":{"@id":"https:\/\/lamdabroking.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lamdabroking.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/lamdabroking.com\/en\/#organization","name":"Lamda - High Tech Insurance","url":"https:\/\/lamdabroking.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lamdabroking.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2022\/12\/lamdaLogo-2.svg","contentUrl":"https:\/\/lamdabroking.com\/wp-content\/uploads\/2022\/12\/lamdaLogo-2.svg","width":237,"height":102,"caption":"Lamda - High Tech Insurance"},"image":{"@id":"https:\/\/lamdabroking.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/lamda.ins","https:\/\/www.linkedin.com\/company\/lamda-risk-and-capital-management\/"]},{"@type":"Person","@id":"https:\/\/lamdabroking.com\/en\/#\/schema\/person\/a5b8f4894f9fd6a7a2f3742ba5688174","name":"Oded Oded","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b963c1df1f438ebca5af4999ce87b49df17e02ee8c0229a090b47e0993913bb1?s=96&d=mm&r=g","caption":"Oded Oded"},"url":"https:\/\/lamdabroking.com\/en\/author\/oded\/"}]}},"_links":{"self":[{"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/posts\/20354","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/comments?post=20354"}],"version-history":[{"count":4,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/posts\/20354\/revisions"}],"predecessor-version":[{"id":20359,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/posts\/20354\/revisions\/20359"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/media\/20284"}],"wp:attachment":[{"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/media?parent=20354"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/categories?post=20354"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lamdabroking.com\/en\/wp-json\/wp\/v2\/tags?post=20354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}