The proposal form asks yes or no questions. Answering optimistically is how a claim gets disputed.
Cyber insurance applications ask about controls in specific terms. We help you establish what is actually true, evidence it, and close the gaps that matter, so the answers you give are ones you could defend at claim time.

- 18 controlsIn the widely referenced control set
- 153 safeguardsAcross the current control versions
- IG1 firstEssential cyber hygiene as the starting point
- EvidenceWhat separates an answer from an assertion
A proposal form is a statement about your organisation, made in writing, before an incident.
We are not insurance advisers, and this much is simply prudent: answer questions about your controls the way you would want to defend them afterwards.
- The questions are usually binary and the reality usually is not. Multifactor authentication on all remote access is a yes or a no on the form, and in most estates the truthful answer is that it covers most access with several documented exceptions.
- The gap between those two answers is invisible until something happens. At that point the exceptions become the interesting part of the conversation, and the organisation is explaining a discrepancy rather than dealing with an incident.
- The practical remedy is to establish the true position first. Where a control is partial, either close the gap before answering or answer accurately and describe the exceptions, which is a conversation better had at application time.
- None of this is legal or insurance advice, and it is not a substitute for your broker. It is a security assessment aligned to the questions insurers actually ask, so that what you state about your controls is something you have evidenced.
Eight things to establish before you complete a proposal form.
Asset inventory is the first control for a reason
Inventory and control of enterprise assets sits first in the published control set, followed by software assets. Almost every other control statement is qualified by scope, and scope means knowing what you have. Most estates cannot answer this precisely.
Account and access management get examined closely
Account management and access control management are separate controls. Questions about privileged accounts, multifactor coverage and joiner mover leaver processes are asking about both, and the honest answer is frequently mostly rather than yes.
Data recovery has to be demonstrated
Data recovery is a control in its own right, distinct from backup. The relevant question is not whether backups run but whether a restore has been performed and timed, which is a different and considerably less comfortable question.
Vulnerability management is continuous, not periodic
The published control is continuous vulnerability management. An annual scan is a point in time exercise, and describing it as continuous vulnerability management is exactly the kind of generous characterisation that becomes contentious later.
Audit log management is frequently the weak point
Audit log management is a distinct control covering collection, retention and review. Organisations that collect logs but retain them for two weeks, or never review them, are in a materially weaker position than the questionnaire answer suggests.
Service provider management is in scope
Service provider management is one of the eighteen controls. Questions about suppliers, their access to your systems, and what security is required of them contractually are asking about a control most organisations have not formalised.
Training is a control, with records
Security awareness and skills training is control fourteen. The distinction that matters is between having run training and being able to show completion records by person, which is what an evidence request actually asks for.
Start with essential cyber hygiene
IG1 is defined as the foundational set of safeguards every enterprise should apply to guard against the most common attacks, and the published guidance is that every enterprise should start there. It is also a realistic scope for a readiness exercise.
Eighteen controls, and what evidence typically looks like.
| Control | Evidence that supports the answer | |
|---|---|---|
| Inventory and Control of Enterprise Assets | A current inventory with a stated discovery method | |
| Inventory and Control of Software Assets | Installed software list with an approval position | |
| Data Protection | Classification and encryption coverage stated | |
| Secure Configuration of Enterprise Assets and Software | Baselines and drift detection | |
| Account Management | Joiner mover leaver records and dormant account reports | |
| Access Control Management | Multifactor coverage with the exception list | |
| Continuous Vulnerability Management | Scan cadence and remediation timelines met | |
| Audit Log Management | Sources, retention period and review evidence | |
| Email and Web Browser Protections | Filtering configuration and its coverage | |
| Malware Defenses | Deployment coverage percentage across the estate | |
| Data Recovery | A timed restore test, not a backup report | |
| Network Infrastructure Management | Device inventory, configuration and firmware currency | |
| Network Monitoring and Defense | What is monitored and who acts on it | |
| Security Awareness and Skills Training | Completion records by person | |
| Service Provider Management | Supplier list with access and contractual requirements | |
| Application Software Security | Testing evidence for applications you build | |
| Incident Response Management | A plan plus evidence it has been exercised | |
| Penetration Testing | A recent report and the remediation status |
Four things we do, and one we do not.
We state coverage as a proportion
Multifactor authentication on ninety four percent of accounts with a named exception list is a true statement. Yes is not, and the difference between them is exactly what surfaces when evidence is requested rather than accepted.
We test recovery rather than reporting on backups
Data recovery is a control distinct from taking backups. A timed restore of a representative system produces a figure you can state and defend, and it regularly produces a surprise that is far better found now than during an incident.
We prioritise gaps by how much they move the answer
Some gaps are expensive and change one answer. Others are cheap and change several. Sequencing by that ratio is what makes a readiness exercise fit inside the weeks available before a renewal rather than becoming a security programme.
We do not advise on insurance
We do not recommend cover, interpret policy wording, estimate premiums or act as a broker. What we provide is an evidenced assessment of your controls, which your broker and underwriter can then use for the parts that are properly theirs.
Three phases across roughly five to nine weeks.
- 01Weeks 1 to 3
Establish what is actually true
Each control assessed against evidence rather than against recollection, with coverage stated as a proportion of the estate rather than as a yes. Exceptions are documented deliberately, because exceptions are what the binary questions conceal.
- Control position assessed with evidence
- Coverage stated as a proportion, not a yes or no
- Exceptions documented per control
- Evidence located and gathered in one place
- 02Weeks 4 to 7
Close the gaps that matter before you answer
Prioritised by which controls proposal forms concentrate on and by which gaps are cheap to close. Multifactor coverage, restore testing and log retention are frequently the three that move furthest in the shortest time.
- Gaps prioritised by question weight and effort
- Quick wins implemented and evidenced
- Remaining gaps documented with a plan and dates
- Position restated after remediation
- 03Weeks 8 to 9
Assemble the evidence pack
A single pack supporting each control statement, so that when a question is asked the answer comes with its evidence attached. The same pack serves customer security questionnaires, which is where much of its ongoing value sits.
- Evidence pack assembled per control
- Supporting documents dated and owned
- Maintenance cadence agreed
- Board summary of the control position
Six situations that make readiness worth doing.
A business applying for cyber cover for the first time
The proposal form is the first structured examination of the security position many organisations have faced. Establishing the true answers before writing them down is the difference between a smooth application and an awkward one.
An organisation approaching renewal
Renewal questions tend to become more specific each year, and the estate has changed since the last set of answers. Reassessing rather than copying forward last year responses is what keeps the statements accurate.
A company asked for evidence rather than answers
Evidence requests are increasingly common and they are where optimistic answers become visible. An organisation with an assembled pack responds in days, and one without spends weeks reconstructing a position it already asserted.
A group with inconsistent controls across entities
Group level answers frequently describe the best entity rather than the whole group. Assessing per entity and stating coverage as a proportion produces an answer that survives an examination of any single site.
An operation with technology outside the IT estate
Production systems, building management and specialist equipment are frequently excluded from inventories and from control coverage. They are rarely excluded from the questions, which is where a coverage percentage becomes important.
A business whose customers ask the same questions
Service provider management is a control, and your customers apply it to you. The evidence assembled for an insurance application answers a large part of a customer security questionnaire, which is where much of the ongoing value sits.
How UAE organisations approach an insurance application.
| Feature | Assessed and evidenced | Completed from memory | Delegated to whoever is free |
|---|---|---|---|
Control statements verified | With evidence | From recollection | Guessed |
Coverage stated accurately | As a proportion | As a yes | As a yes |
Exceptions known | Documented | Unknown | Unknown |
Evidence producible on request | Same day | Days to weeks | No |
Gaps closed before answering | The cheap ones | None | None |
Position at an evidence request | Comfortable | Uncertain | Exposed |
Reusable for customer questionnaires | Yes | Partly | No |
Board visibility of the real position | Yes | Optimistic | None |
Time required | Weeks | An afternoon | An hour |
Value beyond the application | Substantial | Little | None |
Essential cyber hygiene is the sensible target, and the published guidance says so.
There are 153 safeguards across the current control versions. Attempting all of them before a renewal is not a plan.
- IG1 is defined as the foundational set of cyber defence safeguards that every enterprise should apply to guard against the most common attacks, and the published position is that every enterprise should start with IG1 regardless of size.
- That is a coherent scope for a readiness exercise. It covers the controls that proposal forms concentrate on, it is achievable inside a renewal cycle, and it corresponds to the attacks that actually generate claims rather than to sophisticated targeted intrusion.
- IG2 builds upon IG1 and IG3 comprises all the controls and safeguards. Progression beyond the first group is a decision based on risk profile and available resources, and it belongs in a security roadmap rather than in a pre renewal sprint.
- The practical benefit of using a published control set is that the answers travel. The same evidence supports the insurance conversation, a customer security questionnaire and an internal board discussion without being rebuilt each time.
Five steps, timed to sit before the deadline.
- 1
Scope to essential cyber hygiene
The foundational set of safeguards every enterprise should apply against the most common attacks, which is both the published starting point and a realistic scope for the weeks available before an application or renewal deadline.
- 2
Assess each control against evidence
Asset and software inventory, data protection, secure configuration, account and access management, vulnerability management, logging, email and browser protections, malware defences, recovery, network management and monitoring, training, suppliers, application security, incident response and testing.
- 3
State coverage honestly, with exceptions
As a proportion of the estate rather than as a binary answer, with exceptions named. That is what converts a questionnaire response from an assertion into a statement you could stand behind if somebody asked to see the underlying position.
- 4
Close what can be closed
Prioritised by how many answers each gap affects and by how quickly it can be closed. Multifactor coverage, a tested restore and log retention are frequently the three that move the position furthest in the time available.
- 5
Assemble the evidence and keep it current
One pack per control, dated and owned, so an evidence request is a retrieval rather than a project. A maintenance cadence keeps it usable for the next renewal and for the customer questionnaires that arrive in between.
What organisations ask about insurance readiness.
Fifteen questions to answer honestly first.
Access
- Is MFA on all remote access?Including exceptions.
- Is MFA on all privileged accounts?A separate question.
- How many dormant accounts exist?A number, not a process.
- Do leavers lose access same day?Evidenced how.
- Who holds local administrator rights?And how many.
Recovery and logging
- When did we last restore from backup?A date.
- How long did it take?A measured figure.
- Are backups isolated from the network?A common question.
- How long are logs retained?Often shorter than assumed.
- Who reviews them?Collection is not review.
Process and people
- Has the incident plan been exercised?Not just written.
- Do we have training completion records?By person.
- Do we know our suppliers with access?A named control.
- When was the last penetration test?And what was fixed.
- Is patching within our stated timelines?Measured, not intended.
Take the last proposal form you completed and check one answer against evidence.
Pick the multifactor authentication question, or the one about restore testing. Whichever you choose, the exercise usually tells you what you need to know about the rest.
Related Services
Explore more solutions that work great with this service
CIS Controls Assessment
Eighteen controls, assessed and re-assessed
Backup and Restore Audit
We test whether your backups actually restore
Incident Response Plan
Written, exercised, and findable when the network is not
IT Risk Assessment
A short register with an owner against every risk
Access Rights Review
Certification that removes access, not one that gets approved
Gap Assessment
Distance to a target you actually have to meet
Tabletop Exercise
Test the decisions, not the documentation
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly