← All articles
Use case

Answering your cyber insurer's questionnaire, with evidence

AssuranceSegmentationPreuves

The cyber-insurance questionnaire has become one of the first concrete triggers of industrial cybersecurity. It conditions underwriting, the premium and the exclusions. And it asks questions many sites cannot answer with certainty: is your industrial network segmented? Who accesses your systems remotely?

What insurers actually ask

Beyond the classics (backups, MFA, antivirus), questionnaires increasingly focus on the network: separation between office and production, systems inventory, control of remote-maintenance access, internet exposure. Answering "yes" without evidence commits the company: an inaccurate declaration discovered after a claim can compromise the payout.

The problem: good faith is not enough

Most executives answer from the architecture diagram or their provider's word. Yet what passive listening reveals about real traffic often differs from the diagram: a forgotten bridge between the office network and the shop floor, a permanent supplier access, a PLC reachable from IT. The issue is not good faith - it is visibility.

The approach: measure, fix, prove

  • Measure. Passive mapping establishes reality: equipment inventory, cross-level flows, communication channels, observed remote access. Without touching production.
  • Fix. Segmentation findings (abnormal cross-level flows, IT/OT bridges, traversing protocols) yield a short, prioritised action list - often switch and firewall settings rather than investments.
  • Prove. The analysis report - network map, zones, controlled flows, risk scoring - becomes the questionnaire's appendix. A documented, dated answer, renewable every year at contract time.

The benefit goes beyond insurance

The same file serves several times: insurance questionnaire, principal's requirements, NIS2 preparation, group internal audit. That is the point of answering with evidence rather than declarations: the work is done once, and it serves everywhere.