Architecture firms usually carry professional liability insurance. However, that policy is not built for ransomware, stolen data, or redirected payments. Cyber coverage fills that gap, and cyber insurance readiness means having the controls and records carriers expect before you apply or renew.
Why carriers ask more questions now
Insurers have paid many claims for ransomware and email fraud. As a result, applications now ask detailed questions about security controls. Some carriers also scan your internet-facing systems before they quote.
For a design firm, the questions often feel technical. Still, they tend to focus on a familiar set of basics. If you can show those basics are in place, the process goes more smoothly.
Controls carriers commonly expect
Requirements vary by carrier and policy. So confirm the specifics with your broker. That said, most applications ask about the following areas.
- Multifactor authentication for email, remote access, and admin accounts.
- Endpoint detection and response on workstations and servers.
- Backups kept offline or offsite, protected from deletion, and tested.
- Regular patching of operating systems and key applications.
- Security awareness training and phishing exercises for staff.
- Limits on admin rights and separate admin accounts.
- A written incident response plan.
- Email security, including filtering and domain authentication.
Also, expect questions about payment procedures. Many carriers want to know whether you verify changes to bank details by phone before sending money.
Answer the application accurately
The application is part of the policy. If an answer turns out to be wrong, the carrier may dispute a claim. Therefore, treat every question as a statement you must be able to prove.
First, involve your IT provider before you submit. They can confirm what is really in place, not what someone remembers. Next, answer “partially” or add notes when a control covers some systems but not others.
Honest detail is safer than a simple yes.
Finally, keep a copy of the completed application with your records. At renewal, compare it to your current setup so answers stay accurate.
Build an evidence folder for cyber insurance readiness
Carriers and brokers sometimes ask for proof. In addition, you may need that proof quickly after an incident. So keep a simple folder with current documentation.
Useful items include MFA enrollment reports, EDR coverage reports, backup test results, and training completion records. Also include your incident response plan and a recent security assessment. Update the folder at least once a year, ideally before renewal.
Understand what your policy covers
Cyber policies vary widely. Two policies with similar names can respond very differently to the same event. So review key terms with your broker and counsel.
- Coverage for ransomware response, recovery, and business interruption.
- Coverage for social engineering and funds transfer fraud, and any sublimits.
- Whether you must use the carrier’s approved response vendors.
- How the policy handles data belonging to clients and consultants.
- Waiting periods before business interruption coverage begins.
In addition, ask how cyber coverage interacts with your professional liability policy. Gaps between the two can surprise firms after a claim.
Close gaps before renewal
Renewal is the natural moment to fix weak spots. For example, if MFA covers email but not remote access, close that gap first. Similarly, if backups have never been tested, run a restore and record the result.
Start this work a few months before renewal. That way, you can answer the application with confidence instead of promises.
Know your insurer’s role in an incident
Many policies require prompt notice and set rules for which vendors you can hire. If you call outside responders first, you may complicate coverage. So put the carrier’s claim hotline in your incident response plan.
Then walk through the steps with firm leadership. That way, the people who make decisions during an incident know when and how to involve the insurer. Good cyber insurance readiness includes this practice, not just the paperwork.
How WEBIT helps
WEBIT baselines every client to the CIS Controls by default, and every managed device gets Security Essentials, including Zero Trust EDR and vulnerability management. Optional add-ons such as Duo MFA, Microsoft 365 backup, and security awareness training cover other common carrier questions.
Our vCISO advisory services can help you complete applications accurately and assemble evidence. Learn more about our cybersecurity services, or see how we support architecture firms.
Key takeaways
- Professional liability insurance does not replace cyber coverage.
- Carriers commonly expect MFA, EDR, tested backups, and training.
- Answer applications accurately with help from your IT provider.
- Keep an evidence folder and update it before each renewal.
- Review coverage terms and put the claim hotline in your response plan.