B BROCENT

The Insurer's Questionnaire Had Twelve Questions: What a Hong Kong Firm Learned Renewing Cyber Cover

A composite scenario from Hong Kong: a seventy-person distributor opens its cyber-insurance renewal pack and finds twelve specific, checkable questions where last year there was one page. What the questions cluster into, why nobody in the building can answer four of them, and what changes when identity, patching, devices and training stop being four separate purchases.

Insurance renewal paperwork, a laptop and documents laid out on a desk, representing a Hong Kong SME working through a cyber-insurance renewal questionnaire
In short: Cyber-insurance renewals for Hong Kong SMEs increasingly arrive with a detailed IT controls questionnaire rather than a one-page declaration. The questions are specific and checkable — multi-factor authentication coverage, patch cadence, device management, staff training. The hard part is rarely the technology. It is producing evidence, and knowing who owns each answer.

Somewhere in a Kowloon office this year, an operations director opened the renewal pack for her company's cyber-insurance policy and found something that had not been there twelve months earlier. Last year, renewal had been a single page: tick the boxes, sign at the bottom, send it back to the broker. This year it was twelve questions, each one asking for a specific, checkable fact about how the company's IT was actually run.

The company is a Hong Kong distributor of laboratory and industrial equipment — roughly seventy staff across a Kowloon East office and a small warehouse, no internal IT department beyond one office manager who is good with computers and one external vendor who comes when something breaks. This scenario is a composite, drawn from patterns that recur across Hong Kong SMEs of this size rather than from any one named client. But the questionnaire is real in shape, and so is the discomfort of reading it for the first time.

What follows is what each question was actually asking, why Hong Kong companies of this size struggle to answer, and what changes when the four areas the questionnaire cares about stop being four separate purchases.

Why are Hong Kong cyber-insurance renewals getting harder?

The short answer is that underwriting has caught up with claims experience. Cyber cover was, for a period, sold on a light-touch basis: a short declaration, a modest premium, and a policy that a Hong Kong SME bought largely because a client or a bank asked whether it had one. As the claims data accumulated — business email compromise, ransomware, funds-transfer fraud, all of which Hong Kong's trading and professional-services economy produces in volume — insurers began pricing the risk more carefully, and pricing risk more carefully means asking better questions.

For a Hong Kong SME, three things make this shift feel abrupt.

The first is that nothing about the company has changed. The renewal is harder even though the business is the same size, doing the same work, with the same systems. It is the questionnaire that moved, not the company.

The second is that the questions are now written to be verifiable. "Do you have appropriate security measures in place?" can be answered with a confident yes by anyone. "What percentage of your user accounts have multi-factor authentication enforced, and on which systems?" cannot. The second version is a number, and either you have it or you are guessing.

The third is Hong Kong's particular business shape. A great many of the companies filling in these forms are between forty and a hundred staff, are profitable, are serious, and have no IT department at all. Their IT is a mixture of a break-fix vendor, a cloud accounting package, Microsoft 365, a couple of legacy servers nobody has touched since the last office move, and staff laptops of varying vintage. There is no single person whose job it is to know the answer to question seven.

None of this is a Hong Kong-specific regulatory matter, and it is worth being precise about that. The questionnaire is a commercial document from an insurer, not a requirement imposed by a regulator. What it does overlap with is the general expectation — familiar to any Hong Kong business handling personal data — that an organisation can describe and evidence how it protects the information in its custody. The insurer is asking a version of the same question a large customer's procurement team might ask, or a bank's onboarding pack, or a data-protection review. Answering it well is useful in more places than one.

What the twelve questions were actually asking

Read individually, the questions look like a technical audit. Read together, they cluster into four areas, and the clustering is the useful part.

Identity and access. Is multi-factor authentication enforced on email? On remote access? On administrative accounts? Are former employees' accounts disabled, and how quickly? This is usually where the questionnaire starts, because compromised credentials are where a very large share of claims start.

Patching and vulnerability management. How quickly are critical security updates applied to servers, workstations and network equipment? Is there a documented cadence? Is anything running an operating system that no longer receives security updates? Has an external vulnerability scan been run, and when?

Devices and data. Are company devices encrypted? Can a lost or stolen laptop or phone be wiped remotely? Are personal devices used for company email, and if so, what controls apply to them? Is there a backup, is it tested, and is a copy of it out of reach of an attacker who gets into the network?

People. Do staff receive security awareness training? How often? Is there a documented process for verifying a change of bank details before a payment is released?

The operations director in this scenario could answer four of the twelve questions with confidence. She could answer another four with "I believe so, but I would need to check." The remaining four she could not answer at all — not because the company was negligent, but because nobody had ever been asked to produce that specific fact before, and no system in the building was set up to produce it on demand.

That gap — between *we probably do this* and *here is the evidence that we do this* — is the real subject of the questionnaire.

What goes wrong when nobody owns the answer

Three failure patterns show up repeatedly, and none of them are about a company being careless.

"We think we have that covered"

Multi-factor authentication is the clearest example. Most Hong Kong SMEs on Microsoft 365 have MFA switched on for *some* users — often the directors, often after an incident at a company someone knows. Whether it is enforced on every account, including the shared mailbox that finance uses and the account belonging to the person who left in March, is a different question. The honest answer is frequently "for most people, I think." That is not a usable answer on a form that asks for a percentage, and attesting to something nobody has verified is its own kind of exposure.

Buying a point solution to answer one question

A questionnaire asks about vulnerability scanning. Somebody buys a scanning subscription, runs it once, saves the PDF, and files it with the renewal. The specific question is now answerable. The underlying gap — that nobody is reading the output, prioritising it, or fixing anything — is untouched, and next year's questionnaire will ask a slightly different question that the purchase does not cover.

This is the most expensive pattern, because it accumulates. Over three renewals a company can end up with a scanning tool, a training platform, a device-management licence and a patching agent, all bought separately, all only partially deployed, all invoiced from different vendors, and no single view of whether any of them is actually working. The spend is real. The evidence is still thin.

Nobody owns all four areas

Identity, patching, devices and people sit with different people in a small Hong Kong company — or with nobody. The external break-fix vendor handles the server. The office manager handles new starters. HR handles training, when there is time. The result is that no single person can look at the twelve questions and say, with evidence, what the company's actual position is. The questionnaire is not really testing security controls. It is testing whether anyone owns them.

The useful way to read the questionnaire

The instinct, faced with twelve questions and a renewal date, is to treat it as a form to get through. The more useful move is to treat it as a checklist against what the company actually has — because the four areas the insurer is asking about are, almost exactly, the four areas an ongoing managed IT arrangement is supposed to cover anyway.

That is not a coincidence. Insurers converged on these questions because these are the controls that correlate with claims. Managed IT providers converged on the same controls because these are the ones that prevent the incidents that generate emergency calls at 11pm. The questionnaire is, in effect, an outside party's summary of what competent day-to-day IT operations look like.

Which reframes the decision. The question is not "how do we answer question seven before the deadline." It is "who is going to own identity, patching, devices and training on an ongoing basis, so that next year this is a report we run rather than a scramble we survive."

For a seventy-person Hong Kong company, the honest answer is rarely an internal hire. One IT manager cannot cover MFA policy, patch cadence across every endpoint, mobile device management, staff training campaigns, and the day job of keeping the office working. It is a scope problem, not an effort problem.

What this looks like in practice

Working through a renewal questionnaire properly has four stages — and only one of them involves buying anything.

Walk the questionnaire line by line against reality. Not "do we have MFA" but "pull the report showing which accounts have it enforced." Not "do we patch" but "show the patch compliance figure for last month." Most companies discover that they are in better shape than they feared on two or three questions, and in worse shape than they assumed on one or two others. The value here is accuracy, not reassurance.

Close the specific gaps found, not a generic security upgrade. If the finding is that MFA is enforced for eighty per cent of accounts and the remainder are service and shared mailboxes, the work is finishing that rollout and documenting the exceptions — not replacing the identity platform. If the finding is that patching happens when someone remembers, the work is putting a cadence and a monthly compliance report in place. Managed patch management, which starts from US$3 per endpoint per month and includes a monthly compliance report, exists precisely so that "how quickly do you patch" has a number behind it rather than an impression.

Put the recurring controls on a footing that survives staff turnover. Mobile device and BYOD management is the usual gap for a company of this size, because it is genuinely an add-on rather than something Microsoft 365 does by default — enrolment, encryption enforcement, remote wipe for a lost device, and a work-profile boundary on personal phones so company data can be removed without touching an employee's photos. Security awareness training run as a managed campaign, from US$2.50 per user per month, rather than an annual slide deck, produces both a better-prepared finance team and a participation record. An external vulnerability scan run on a schedule, from US$150 a month with someone reading the output and turning it into a fix list, answers the scanning question honestly rather than decoratively.

Keep the documentation where the broker can be handed it. The point of doing the work is that next year's renewal is a folder, not a fire drill: the MFA coverage report, the patch compliance summary, the device inventory with encryption status, the training participation record, the most recent scan and what was done about it. A managed provider that runs these controls produces this evidence as a by-product of running them.

One caution worth stating plainly: nothing here is insurance or legal advice, and no control or combination of controls guarantees that a policy will be approved, renewed, or priced a particular way. Underwriting decisions belong to the insurer, and the terms of a specific policy belong between a company and its broker. What can be said is what the questions commonly ask about, and what it takes to answer them with evidence instead of impression.

Three ways Hong Kong SMEs handle the renewal questionnaire

Self-attesting without evidence

  • What it looks like: the form is completed from memory and general confidence, ticking boxes that feel true.
  • Cost: nothing, upfront.
  • What it gets you: a submitted form, quickly.
  • Where it fails: the answers are unverified, so the company does not actually know its own position; and if a claim is ever made, the accuracy of what was declared matters. It also means the same uncertainty recurs, identically, every year.

Buying point solutions reactively

  • What it looks like: each awkward question triggers a purchase — a scanner for the scanning question, a training platform for the training question.
  • Cost: real and cumulative, spread across several vendors and renewal dates.
  • What it gets you: a specific answer to a specific question, this year.
  • Where it fails: tools bought to answer a question are rarely deployed, monitored or acted on. Coverage is patchy, nobody owns the whole, and next year's slightly different question is not covered by last year's purchase.

Mapping the questionnaire to real, documented controls

  • What it looks like: identity, patching, devices and training are treated as four parts of one ongoing arrangement, with a named owner and reporting that runs whether or not a renewal is due.
  • Cost: a predictable monthly per-user figure, with the genuinely optional pieces priced separately and visibly.
  • What it gets you: answers backed by reports, a documented position that improves year on year, and one party accountable for all four areas.
  • Where it costs more: it is an ongoing commitment rather than a one-off spend, and it only pays back if the controls are genuinely run rather than nominally bought.

Frequently asked questions

What do cyber-insurance questionnaires actually ask about?

In practice they cluster into four areas: identity and access (multi-factor authentication coverage, administrative accounts, leaver processes), patching and vulnerability management (cadence, unsupported systems, external scanning), devices and data (encryption, remote wipe, personal devices, backup and its recoverability), and people (security awareness training, and payment-verification procedures). The specific wording varies by insurer and by year, but those four categories are remarkably stable.

Does enabling MFA on its own satisfy most requirements?

It addresses one of the four areas, and it is usually the single highest-value control on the list — but a questionnaire that asks about patch cadence, device management and training is not answered by MFA. It is also worth being precise about what "we have MFA" means: enforced on every account, including shared and service accounts, on email and on remote access, is a different statement from enabled for some users.

How often do the questionnaires get harder?

There is no fixed schedule, but the direction over recent renewal cycles has been consistently towards more specific and more evidence-based questions. Planning on the assumption that next year's form will ask for at least as much detail as this year's is the safer bet.

What happens if we cannot answer one of the questions?

That is a conversation for the company and its broker, and the outcome depends on the insurer and the question. What is generally unhelpful is guessing. A candid "we do not currently have this, and here is the plan and timeline to put it in place" is a more defensible position than an unverified tick, and brokers are generally better able to work with the former.

Does a managed IT provider fill in the questionnaire for us?

The company signs the declaration, and the answers should be the company's own. What a managed provider can and should do is supply the underlying facts — MFA coverage, patch compliance figures, device inventory and encryption status, training participation, latest scan results — so the person signing is working from reports rather than recollection, and can see clearly which questions still have gaps behind them.

Is a vulnerability scan enough evidence on its own?

A scan answers the scanning question and nothing else. It is also worth distinguishing a scan that was run once so a PDF could be attached from a scanning practice where findings are prioritised, fixed, and re-tested. Questionnaires increasingly ask about remediation, not just detection — the second question being "and what did you do about what it found."

What does getting this wrong cost at renewal?

It varies too much by insurer, sector and policy to put a number on, and anyone who gives you one is guessing. The costs that are predictable are the non-premium ones: renewal timelines that slip because answers cannot be produced, senior time spent reconstructing facts that a report should have supplied, and — the expensive one — the discovery, mid-questionnaire, that a control everyone assumed was in place is not.

Where this ends up

The questionnaire is a useful document, and not only for the insurer. Twelve specific questions, written by an outside party with a financial interest in being right about risk, is a better security review than most Hong Kong SMEs of this size ever commission for themselves.

But treating it as an annual event is the expensive way to use it. The four areas it asks about — identity, patching, devices, people — are not renewal artefacts. They are what running IT properly looks like for the other eleven months of the year, and they belong together under one owner rather than as four separate purchases made under deadline pressure.

That is the argument for putting them inside an ongoing plan. Brocent's managed IT support covers the recurring controls a questionnaire asks about — patch management, backup and recovery, 24/7 monitoring, help desk, a named vCIO who owns the roadmap — as part of a per-user monthly plan, with the pieces that genuinely are optional, such as device management, scanning and training, priced visibly alongside it rather than bundled invisibly. Our pricing page shows the Hong Kong figures for each plan tier and each add-on, so the cost of answering next year's questionnaire properly can be worked out before committing to anything.

If you are holding a renewal pack right now and cannot answer four of the questions, that is an ordinary place to be. It is also a solvable one, and the version of the company that can answer all twelve next year is meaningfully better run than the one that could not — insurance aside.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →