How to answer
Do you carry cyber liability insurance, and what is the coverage limit?
The question FillTrust most often leaves deliberately blank. No security document contains the answer, and guessing a coverage limit is a representation you cannot support.
Yes. We carry cyber liability insurance with a limit of [$X] per claim and [$Y] in aggregate, underwritten by [insurer], with the policy running to [date]. A certificate of insurance is available on request.
Square brackets are yours to fill in. FillTrust grades an answer like this not in your documents when your documents support it.
- Answered from
- Your insurance certificate. Nothing in your security documentation answers this, which is why it is the question most often left blank.
- Evidence to attach
- A certificate of insurance from your broker. It is a one-page document and brokers issue them on request.
- Where it is asked
- CAIQ v4.0SIG LiteVSA Core
This is the archetype of a question that no amount of reading your security documentation will answer, and it is worth understanding why.
Every other question on a questionnaire is answered by a policy, a report or an architecture decision. This one is answered by an insurance certificate held by whoever runs finance. A retrieval system searching your SOC 2 report, your policies and your DPA for a coverage limit will find nothing, because nothing is there. This is precisely the case where the correct behaviour is to leave the cell blank and say so, rather than to produce a plausible number, and it is the single clearest illustration of why "left blank on purpose" is a feature rather than a failure. A confident-sounding "$5,000,000" that nobody verified is a representation about your insurance made to a customer, and it is checkable in one email.
So the answer is a process rather than a lookup. The good version:
Ask your broker for a certificate of insurance. It is a one-page summary naming the insurer, the policy type, the per-claim and aggregate limits and the expiry date. Brokers issue them routinely and usually within a day.
Quote both limits. Per-claim and aggregate are different numbers and reviewers ask for both. A single number invites a follow-up.
Check it is actually cyber cover. General liability and professional indemnity or E&O are separate policies that do not respond to a data breach. A reviewer asking this question knows the difference, and answering with the wrong policy type is worse than answering that you do not have one.
If you do not carry it, say so. Cyber cover is not universal at seed stage and a plain "we do not currently carry a cyber liability policy" is an answer a reviewer can weigh. Some enterprise contracts require it, in which case you will find out now rather than at signature, which is the cheapest possible time.
Once you have the numbers, this becomes a library answer: approve it once and it should be reused until the policy renews.
How this one goes wrong
Specific to this question, not general advice.
- Guessing the limit. A number in a questionnaire is a representation, and this one is trivially checkable against the certificate a reviewer will then ask for.
- Confusing general liability or E&O with cyber. They are different policies and reviewers who ask this question know that.
- Leaving it blank because security cannot answer it. The person who can is in finance, and it takes one email.