Stedra
Sign inCheck my business
BlogBASICS6 min read

The account-ownership questions on your cyber-insurance application, explained

Steps verified against the official documentation below · last checked 2026-07-18

Cyber-insurance applications used to be a formality. They aren't anymore: questionnaires have grown long and specific, premiums move with your answers, and — the part many owners miss — your answers function as representations. Answer "yes, MFA is enforced on all admin accounts" when it isn't, and you've handed the carrier an argument against paying your claim.

Strip away the jargon and a large share of the questionnaire is really asking one thing: do you know what accounts exist, who can get into them, and what happens when someone leaves? Here's the translation.

The questions behind the questions

  • "Is MFA enforced on email, remote access, and all administrator accounts?" — Do you even know where all the admin accounts are? MFA on the accounts you remember isn't MFA on the ones you forgot.
  • "Are administrative accounts separated from daily-use accounts?" — Is the login that can delete everything also the one reading newsletters all day?
  • "Do you have a documented offboarding process?" — When someone leaves, does their access provably go with them, or does it linger in tools nobody listed?
  • "Do third parties/vendors have access to your systems?" — Does your agency or old IT contractor still hold admin somewhere? Documented where?
  • "Do you maintain an inventory of systems and data?" — The register question, asked directly.

Why 'documented offboarding' trips up small businesses

Most SMBs genuinely do disable email when someone leaves. What they can't do is *demonstrate a process* that also catches the informal estate: the Mailchimp account the marketer signed up for, the registrar login from 2019, the Instagram on a personal phone, the vendor who still has admin "temporarily." Carriers ask for documentation precisely because the informal accounts are where incidents start.

The fix isn't paperwork theatre. It's an asset register that maps accounts to people, plus a departure checklist generated from it. That artifact answers the offboarding question, the inventory question, and half the vendor question at once.

How to answer without hurting yourself

  • Don't guess and don't aspirationally 'yes'. An inaccurate application is worse than an unflattering one — it risks the claim being contested exactly when you need it.
  • Audit before you answer: list the admin accounts, check MFA on each, write down the offboarding steps you actually perform.
  • Where the honest answer is 'no', fix the cheap ones before filing — enforcing MFA on admin logins and writing the offboarding checklist are usually days, not months.
  • Keep the evidence: the register, the checklist, the MFA settings. Renewals ask again, and carriers increasingly verify.
This is one of the trigger moments Stedra is built for: the register and the people-to-asset map are the documentation the questionnaire is asking you to have.
InsurableIT — Cyber insurance requirements 2026: the controls carriers ask aboutForbes — Your cyber controls now decide what coverage you can get
This is one asset. How many others does your business not control?

The free scan maps your domain, email, cloud, social and tools from public records — and shows what you'd lose access to tomorrow. No login, nothing to install.

Check my business
The employee offboarding checklist for digital accounts
7 min read
Who controls your Microsoft 365 tenant? Global admins, explained.
6 min read