Hiscox UK cyber policy application, held
The questions of the CyberClear Proposal form for companies sub-10 million turnover, held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. Hiscox UK is a source document, never a customer.
This document's questions reach 36 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 5 questions here are flagged knockout (a "no" is a common decline point) and 0 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).
This is an attestation question, not a control requirement. It reaches no held control.
Answer options on this form: No / Yes.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
- Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
- Evidence that initial credentials are unique, delivered over protected channels and changed at first use
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
- Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
- EDR coverage report by asset class
- File integrity monitoring baseline and drift alerts
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
- Backup job monitoring reports with evidence that failed jobs were investigated and rerun
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Site plans showing defined security perimeters and their strength relative to the assets inside
- Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Disaster recovery or continuity test plan and results in the period
- Backup restore test records with verification of completeness
- Backup policy with frequency and retention
- Backup integrity test reports
- Physical access control system inventory
- Badge issuance and revocation records
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific removable media policy and evidence it was communicated to users
- Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
- The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
- Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- TLS configuration standards and scan results
- VPN and zero trust network access policy
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
- Evidence that initial credentials are unique, delivered over protected channels and changed at first use
- The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
- Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Multi factor authentication coverage report
- Phishing resistant authentication rollout plan
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
- Evidence that initial credentials are unique, delivered over protected channels and changed at first use
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Multi factor authentication coverage report
- Phishing resistant authentication rollout plan
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
- Evidence that initial credentials are unique, delivered over protected channels and changed at first use
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Multi factor authentication coverage report
- Phishing resistant authentication rollout plan
- Access policy framework with role definitions
- Privileged access management deployment evidence
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
- Completion records for initial training of new starters and role changers and for periodic refreshers
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Fraud risk assessment or fraud section of the enterprise risk assessment
- Analysis of privileged access and data misuse scenarios
- Access policy framework with role definitions
- Privileged access management deployment evidence
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
Prior-knowledge question. This asks whether the applicant knows of any circumstance that could give rise to a claim. A wrong answer here is the classic route to a prior-knowledge exclusion or rescission, so it is the highest-consequence line on the form, not a line to leave unread. It reaches no control by itself: it is about what the applicant knows, not a control to hold.
No held control answers this line.
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
This is an attestation question, not a control requirement. It reaches no held control.
No held control answers this line.
This is an attestation question, not a control requirement. It reaches no held control.
No held control answers this line.
- The topic-specific privacy and PII protection policy and its communication to relevant parties
- Privacy procedures communicated to everyone who processes PII
- A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
- Records of periodic review of the register and of new or changed legislation identified
- Published privacy notice with effective date and version history
- Evidence notice is presented at collection points (forms, apps)
- Data inventory showing purpose for each personal data field
- Privacy review of new collection forms or features
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
No held control answers this line.
Controls not asked in this held document (254)
None of this held document's questions reach 254 of the 290 held controls (for example A.5.1, A.5.2, A.5.4, A.5.5, A.5.6, A.5.7, A.5.8, A.5.9). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.