How brokers can reveal cyber exposure through practical, business-focused questions.
When brokers start cyber conversations with technical questions about firewalls, antivirus software and IT infrastructure, they don't get to heart of the true business risk that a cyber-attack presents.
A more effective tactic can be to focus on human behaviour, operational dependencies, board accountability and what happens when systems fail. These are the questions that can make clients realise that cyber isn't an IT problem, it's an overarching issue that deserves board-level attention.
This is how brokers can position themselves as trusted advisors, not just policy processors, and provide genuine value for their clients.
Questions about human risk and daily controls
Firewalls are important, but they won't stop a staff member accidentally handing over credentials or transferring funds to a fraudulent account. Ask: "If a senior executive or key supplier emails your finance team on a Friday afternoon requesting an urgent bank detail change, what strict verification steps must your staff follow?"
That question usually exposes a gap. Too many organisations won't have procedures in place in case such a request should arise. Then ask: "How often do you run simulated phishing tests or cyber awareness training to ensure employees don't become the weakest link?"
These aren't technical questions, they're about processes and culture and they can reveal whether the client is genuinely prepared for a cyber-attack.
Questions about operational dependencies
Ask clients: "If your core systems or a critical cloud provider goes down for 48 hours, what's your plan to keep operating and how much revenue would you lose each day?"
Many won't have a clear answer. That's the moment when brokers can explain that cyber insurance isn't just about recovering from an attack, it's also about protecting revenues, covering business interruption, downtime losses and the cost of keeping operations moving.
Supply chain exposure matters too. Ask: "How dependent are you on outsourced providers like payroll, HR and payment processors, and what happens if one of them experiences a breach?" This opens the conversation about third-party cyber risk, which many policies now cover but many clients won't know about.
Indeed, our research found a quarter (24%) of SMEs don’t have cyber insurance because they said they don’t know enough about it and what it offers.
Questions about evolving threats
As businesses grow and adopt new technologies, their cyber risk profile evolves. Ask about geographic expansion: "Are you storing or handling data for clients or subsidiaries in different jurisdictions and how are you tracking their local data regulations?"
Then ask about AI: "As you integrate AI tools into your workflow, what policies prevent employees from inputting proprietary or sensitive data into public models?" This is the frontier and many organisations haven't thought about it. Brokers who ask these questions show genuine insight.
Questions about readiness and response
Finally, ask the question that matters most: "If your network is frozen by ransomware, who's your first call for 24/7 forensic support and crisis management?"
If clients don't have an answer, they're not ready. But that's not a problem, it's an opportunity, because cyber insurance increasingly provides access to specialist support, from forensic investigators to legal counsel and PR crisis management, from the moment an incident occurs.
The shift that matters
These questions don't always require technical expertise from brokers, they require a business perspective. It’s about understanding how cyber incidents actually affect clients’ revenues, operations, reputation, compliance and board liability.
When brokers ask these questions, they move the conversation from: “Do you have a firewall?”, to: “Are you genuinely prepared for an incident, and who will help you recover?" That's when cyber becomes essential, not optional.
The policy wording will follow, but the conversation starts with better questions.