Cyber insurance renewals can put dealership leaders in an uncomfortable position. A questionnaire may ask whether multi-factor authentication is enabled, backups are regularly tested, employee access is controlled, endpoint security is deployed, or an incident response plan is in place. The Controller, General Manager, or Dealer Principal may understand why those questions matter without necessarily knowing whether every answer is technically accurate.

There is no single cybersecurity checklist that applies to every cyber insurance policy. Requirements vary by insurer, the dealership’s size and risk profile, the coverage being requested, and the individual policy. However, current cyber insurance applications show recurring attention to controls such as multi-factor authentication, email protection, endpoint security, backups, patching, administrator access, and incident response.

For an auto dealership, that means the cyber insurance application should not simply become another form someone completes once a year. Dealerships depend on email, their dealer management system (DMS), CRM, lender and OEM portals, accounting systems, service applications, and numerous outside vendors. Before answering questions about how those systems are protected, someone should confirm what is actually in place.

That distinction matters. The goal is not to find a way to answer “yes” to every question. It is to understand what the insurer is asking, verify the dealership’s actual cybersecurity controls, identify anything that needs attention, and make sure the answers provided accurately reflect how the dealership operates today.

In this article, we’ll look at the cybersecurity controls insurers commonly ask about, how cyber insurance differs from FTC Safeguards Rule compliance, and what dealership leadership should review before the next application or renewal.

Why Cyber Insurance Applications Ask So Many Technology Questions

When a cyber insurance application asks detailed questions about multi-factor authentication, backups, endpoint protection, software updates, or incident response, the insurer is trying to understand more than what technology the dealership has purchased. It is evaluating the controls that are actually being used to manage cyber risk.

For example, a current Beazley cyber insurance application asks about multi-factor authentication for remote access and web-based email, incoming email security, phishing training, endpoint protection, business-critical backups, critical patching, EDR and MDR, and incident response planning. Larger applicants are asked additional questions about backup restoration testing, unsupported software, administrator privileges, firewalls, and other security controls.

For a dealership, these questions can touch many different parts of the business. Email may be managed one way, the dealer management system another, while CRM systems, lender portals, OEM systems, vendor access, accounting applications, and employee computers may each have their own security controls. A dealership can therefore have strong protection in one area while still having gaps somewhere else.

This is also why simply asking, “Do we have MFA?” may not be enough. A better question is, “Where is MFA enabled, and are there important systems or accounts where it is not?” The same applies to backups. Knowing that backups exist is different from knowing what is backed up, how those backups are protected, and whether the dealership has successfully tested its ability to restore information.

The practical goal before completing a cyber insurance application is to get a clear picture of what is actually in place. That gives dealership leadership better information to work with, helps the IT provider identify questions that need to be verified, and makes it easier to discuss any gaps with the dealership’s insurance broker or carrier before the application is submitted.

The Cybersecurity Controls Insurers Commonly Ask About

There is no universal list of cybersecurity controls that every auto dealership must have to obtain cyber insurance. Each insurer evaluates risk differently, and requirements can change based on the dealership, the coverage requested, and the policy. However, several controls appear repeatedly in insurer applications and cyber insurance guidance.

For dealership leadership, the important question is not simply whether these protections sound familiar. It is whether they are consistently in place across the employees, computers, accounts, locations, and systems the dealership actually uses.

1. Multi-Factor Authentication

Multi-factor authentication (MFA) requires another form of verification in addition to a password. Cyber insurers frequently ask about MFA, particularly for remote access, web-based email, and privileged accounts.

For a dealership, the more useful question is not just: Do we have MFA?

It is: Where do we have MFA, and where don’t we?

Email, remote access, administrator accounts, cloud applications, and other important systems should all be reviewed. A dealership may discover that MFA is protecting Microsoft 365, for example, while another important account or vendor portal is still protected by a password alone.

2. Endpoint Detection and Response

Insurers may ask what protections are installed on company computers and servers. Current applications may distinguish between traditional endpoint protection, endpoint detection and response (EDR), and managed detection and response (MDR).

At a dealership, the practical question is whether the expected protection is actually installed and operating everywhere it should be. With employees changing, computers being replaced, and potentially several dealership locations involved, coverage should be verified rather than assumed.

3. Backups and Recovery Testing

Cyber insurers commonly ask whether business-critical information is backed up. Some applications go further by asking where backups are stored and how often the organization performs a test restoration.

There is an important distinction here:

Having backups is not the same as knowing you can recover from them.

A dealership should understand what information it is responsible for backing up, where those backups are stored, how they are protected, and whether recovery has been tested. Some dealership applications may be hosted and protected by outside vendors, while Microsoft 365 data, accounting information, files, local servers, or other business information may depend on completely different backup processes.

4. Email Security and Employee Training

Cyber insurance applications may ask about protections for incoming email and how often employees receive phishing or social-engineering training. One current Beazley application, for example, specifically asks about malicious attachment screening, malicious-link screening, external-email tagging, and interactive phishing training.

For dealership leadership, this is partly a technology issue and partly an employee process. Employees in sales, finance, accounting, service, and management routinely receive messages containing links, attachments, invoices, customer information, and requests from outside companies.

The dealership should therefore understand both the protections around email and how employees are prepared to recognize suspicious requests.

5. Software Updates and Vulnerability Management

Insurers may also ask about critical patching and unsupported software. A current Beazley application asks whether critical patches are actively managed on internet-facing systems, while its application for larger organizations also asks whether end-of-life or end-of-support software remains on the network.

This can be easy to overlook in a busy dealership. A computer may continue doing its job for years, so there may seem to be little operational reason to replace it. From a cybersecurity standpoint, however, a system that is no longer receiving security updates deserves a different conversation than a computer that is simply getting older.

6. Administrator and Remote Access

Not every employee or outside vendor needs unrestricted access to dealership systems. Insurer applications may examine privileged accounts, local administrator rights, remote access, and controls that limit what an account can reach.

This is especially relevant in dealerships because so many outside companies may need occasional access to technology. DMS providers, software vendors, phone companies, copier companies, security vendors, and other technology partners may all have some form of remote access.

Dealership leadership should be able to answer a fairly straightforward question:

Who currently has remote or administrator access, and does each person or vendor still need it?

7. Incident Response Planning

Insurers may also ask whether the business has an incident response plan. Current Beazley applications specifically ask whether an organization has a plan for network intrusions and malware incidents, while cyber insurer Coalition identifies incident response planning as an important component of cyber-insurance readiness.

For a dealership, that plan should make responsibilities clear before there is an emergency. Leadership should know how to reach the appropriate IT resources, insurance contacts, legal counsel when appropriate, and other people who may need to become involved.

The important point across all of these controls is that the exact insurance requirement has to come from the dealership’s insurer and policy. An IT provider can help confirm what technology and security processes are actually in place, but it should not assume that a particular cybersecurity control automatically satisfies an insurer’s requirement.

Why “Yes” on the Cyber Insurance Application Needs to Mean Yes

One of the biggest mistakes a dealership can make during a cyber insurance renewal is treating technical questions as assumptions.

Someone asks whether MFA is enabled.

“Yes, I think IT set that up.”

Someone asks whether backups are tested.

“Yes, we have backups.”

Someone asks whether all company computers have endpoint protection.

“They should.”

Those may ultimately be the correct answers, but they are not the same as verifying them.

Cyber insurance applications themselves reinforce this point. Beazley’s current application instructs applicants that their responses should be accurate as of the date the application is signed and provides space for clarification when an answer needs additional detail.

For dealership leadership, that creates a practical process: when a questionnaire contains a technical question, send the exact question to the person responsible for that area and ask them to confirm the answer.

If the application asks whether MFA protects remote access, confirm remote access specifically.

If it asks whether business-critical data is backed up, identify what the dealership considers business-critical and confirm how it is backed up.

If it asks about endpoint protection on all company devices, verify the actual coverage.

If it asks about an incident response plan, make sure there is a real plan rather than assuming one could be created when needed.

This approach is not about making the application harder. It is about replacing assumptions with clear answers.

Cyber Insurance and the FTC Safeguards Rule Are Related, but They Are Not the Same Thing

This is where dealership leaders can easily mix two different issues together.

The FTC Safeguards Rule is a regulatory requirement. According to the FTC, most automobile dealers that finance or lease vehicles are financial institutions covered by the Rule and must develop, implement, and maintain a written information security program to protect covered customer information.

The FTC identifies specific elements of that program, including a written risk assessment, access controls, encryption, multi-factor authentication, monitoring and testing, employee security awareness training, service-provider oversight, an incident response plan, and ongoing reporting and review.

Cyber insurance is different. The insurance carrier is evaluating the dealership for insurance coverage under its own underwriting standards and policy terms. An insurer may ask about some of the same controls because those controls are relevant to cyber risk, but the insurer’s questions are not simply another version of the FTC checklist.

That means:

Meeting an FTC requirement does not automatically answer every cyber insurance question, and satisfying an insurer’s underwriting expectations does not by itself establish FTC Safeguards Rule compliance.

There is considerable overlap, but they are two different conversations.

If you want to understand the dealership’s regulatory obligations, see our FTC Safeguards Rule for Auto Dealerships: A Practical Compliance Checklist. For a cyber insurance renewal, start with the actual application and requirements provided by your broker or insurance carrier.

Who Should Complete the Cyber Insurance Questionnaire?

A Controller, General Manager, or Dealer Principal should not have to know the technical configuration of every system in the dealership.

At the same time, simply forwarding the entire questionnaire to the IT company and asking it to “fill this out” may not be the best approach either.

The application can contain several kinds of questions:

  • Business and financial questions
  • Insurance and claims questions
  • Cybersecurity questions
  • Questions about employees and processes
  • Questions about vendors
  • Questions about systems or data that the IT provider may not manage

A better approach is collaborative.

Dealership leadership should own the application process and work with the insurance broker or carrier to understand what is being asked. The IT provider can then verify the technical questions that fall within its responsibility and clearly identify anything it cannot confirm.

For example, the IT provider may be able to verify MFA settings, endpoint protection, backup systems, patching, Microsoft 365 security, or remote-access controls. It may not know how an outside DMS provider protects information inside its own systems or how a dealership department handles a process that falls outside IT.

That distinction is valuable. “We don't know yet” is a much better starting point than an unverified “yes.”

What Should Your Dealership Review Before Its Next Cyber Insurance Renewal?

The best time to find a cybersecurity gap is not the afternoon the insurance application is due.

A dealership can make the renewal process much easier by reviewing the environment ahead of time.

1. Get the Actual Questionnaire

Do not work from a generic internet checklist. Ask the broker or carrier for the questions that apply to the dealership's policy.

2. Separate Business Questions From Technical Questions

Identify which questions dealership leadership can answer and which need verification from IT, HR, accounting, vendors, or other responsible parties.

3. Verify the Controls

For each technical question, confirm what is actually in place.

That may include reviewing MFA, endpoint security, backups, recovery testing, patching, supported software, administrator access, vendor access, email protections, security training, and incident response.

4. Identify Anything That Cannot Be Confirmed

A question should not automatically become a “yes” because everyone believes the protection probably exists.

Make a list of the items that need further investigation.

5. Address Gaps Before the Deadline When Practical

Some gaps may be simple to correct. Others may require planning, budgeting, vendor involvement, or discussion with the insurer.

The important thing is to discover them while there is time to make a thoughtful decision.

6. Keep Supporting Information

Document what was reviewed, who confirmed the information, and any changes that were made.

That makes next year's renewal easier and gives dealership leadership a clearer understanding of its cybersecurity environment throughout the year.

What If Your Dealership Can't Answer Every Question “Yes”?

A “no” answer does not automatically mean the dealership should rush out and purchase a new cybersecurity product.

First determine exactly what the insurer is asking.

Is the control required for the requested coverage?

Will it affect pricing, limits, or terms?

Is the insurer asking for additional information?

Is there another acceptable way to address the underlying risk?

Those are insurance questions that should be discussed with the dealership's broker or carrier.

The IT question comes next:

What would it take to put that control in place, and does doing so make sense for the dealership even apart from the insurance application?

This distinction matters because good cybersecurity decisions should not be made only to get through an annual questionnaire. If a missing control exposes the dealership to a meaningful business risk, leadership should understand that risk and decide how it should be addressed.

The objective is not to collect as many “yes” answers as possible. It is to make informed decisions based on what the dealership actually needs.

How Tech Marvel Helps Dealerships Prepare for Cyber Insurance Questions

When Tech Marvel works with an auto dealership, our role is not to decide what its insurance company requires.

Our role is to help dealership leadership understand and verify the technology side of the conversation.

That may mean confirming where MFA is enabled, reviewing endpoint protection, checking backup and recovery processes, identifying outdated systems, reviewing administrator and vendor access, or helping document the cybersecurity controls already in place.

If something cannot be verified, we want to find that out before the application is submitted. If a gap exists, we can explain what it means in plain English and help the dealership understand its options.

The insurance carrier or broker ultimately determines what is required for a particular policy. Tech Marvel helps make sure the dealership has accurate technical information to bring to that conversation.

Frequently Asked Questions About Cyber Insurance for Auto Dealerships

Is MFA required for cyber insurance?

There is no single requirement that applies to every cyber insurance policy. However, MFA is a common underwriting question. Current insurer applications specifically ask whether MFA protects remote network access, web-based email, and, in some cases, privileged accounts.

Dealerships should confirm the requirements of their individual insurer rather than assuming that having MFA on one system answers the question for the entire organization.

Do cyber insurers require EDR or MDR?

Requirements vary by insurer and policy, but endpoint security is commonly evaluated. Current cyber insurance applications may ask whether the organization uses endpoint protection, endpoint detection and response (EDR), or managed detection and response (MDR).

The dealership should review the exact wording of its application and confirm what protection is actually deployed.

Do cyber insurers require backups?

Backups are commonly included in cyber insurance questionnaires. Some insurer applications ask not only whether business-critical information is backed up but also where those backups are stored and how frequently restoration is tested.

That is why a dealership should be able to explain more than simply, “We have backups.”

Does FTC Safeguards Rule compliance guarantee that a dealership meets its cyber insurance requirements?

No. They are separate issues.

The FTC Safeguards Rule establishes information-security obligations for covered financial institutions, including most auto dealers that arrange financing or qualifying leases. Cyber insurance requirements come from the individual insurer and policy.

Many cybersecurity controls overlap, but one should not be used as proof that every requirement of the other has been satisfied.

Can our IT provider complete the cyber insurance questionnaire for us?

Your IT provider can be an important source of the technical information needed to complete the questionnaire, but not every question necessarily falls within IT's responsibility.

A better approach is for dealership leadership to coordinate with the insurance broker or carrier and ask the IT provider to verify the technical controls it actually manages.

When should a dealership review its cybersecurity before renewal?

Ideally, before the renewal deadline creates pressure.

Getting the application early gives the dealership time to verify answers, investigate anything that is unclear, discuss insurance-specific questions with the broker or carrier, and address technical gaps thoughtfully rather than rushing through the questionnaire at the last minute.

Get a Clearer Picture Before Your Next Cyber Insurance Renewal

A cyber insurance questionnaire can reveal an important question for dealership leadership:

Do we actually know what cybersecurity protections are in place?

If some of the answers are unclear, that does not mean something is necessarily wrong. It means there is something worth confirming.

Tech Marvel helps Morris County and Northern New Jersey auto dealerships review their current IT and cybersecurity environment, identify areas that may need attention, and get clearer answers about the systems they rely on every day.

Schedule your free 20-minute Dealership IT Review.

We’ll talk through your dealership's current environment, recurring technology concerns, cybersecurity priorities, and any questions you are trying to answer so you can make your next decision with better information.