Cybersecurity Compliance

How to Answer Cyber Insurance Application Training Questions: The Security-Awareness Documentation Underwriters Require From Multi-Location Employers

Cyber insurance applications ask whether you deliver security awareness training to all employees, how often, and what percentage completed it — and your answer is a warranty the carrier can rely on to rescind the policy after a breach. Multi-location employers should answer from an exportable completion record at the organization level, not from what a site manager believes happened last year.

The gap between “we run training” and “we can produce a dated, per-employee completion export across 14 locations” is where coverage disputes start.

What Do Cyber Insurance Applications Actually Ask About Training?

Carrier applications have changed shape over the past four years. The 2021-era question was a yes/no: do you provide security awareness training? Current applications ask a cluster of sub-questions that only a tracked program can answer. Expect some version of all of these:

  • Do all employees receive security awareness training at least annually? Note the word all. Seasonal staff, part-time warehouse crews, and contractors with email accounts are employees for this question in most carriers’ reading.
  • Does the training include phishing and social engineering? Generic IT-policy training does not answer yes. Underwriters want the topic named because phishing is the entry point on most claims they pay — Coggno’s primer on what phishing awareness training covers is a useful check against your current syllabus.
  • Do you run simulated phishing campaigns, and what is the current click rate? This is a separate control from training and a separate answer.
  • What percentage of employees completed the most recent training cycle? A number, not an adjective. “High participation” is not an answer an underwriter can underwrite.
  • Do new hires receive training within a defined window of their start date? Thirty days is the common benchmark on applications.
  • Are privileged users and finance staff given additional training? Wire-transfer fraud drives a disproportionate share of loss, so finance and AP staff are singled out.

Underwriters pair these with the technical controls — multi-factor authentication, endpoint detection, backup segregation, patch cadence. Training sits in a different category from the technical controls, though, because it is the only one you cannot verify with a network scan. The carrier is relying on your record-keeping. That is exactly why the wording of your answer matters so much, and why a program built on a monthly cadence, like the one described in Coggno’s cybersecurity awareness training program calendar, gives you something concrete to point at instead of an annual scramble.

Why Is a Training Answer a Warranty and Not a Description?

Most cyber applications are incorporated into the policy by reference. The signature block usually includes language stating that the answers are true, that the carrier relied on them in issuing the policy, and that material misstatements void coverage. In practice, an insurer may rescind a policy for a material misrepresentation whether the misstatement was deliberate, careless, or an honest mistake about what was actually deployed.

The instructive case is Travelers Property Casualty Company of America v. International Control Services, filed in the Central District of Illinois in 2022. ICS attested on its application to using multi-factor authentication for remote access. After a ransomware event, forensic review showed MFA was configured on the firewall only — not on the remote access path the attackers actually used. Travelers sued to rescind rather than to deny a claim, and within weeks the parties agreed to rescission and the court entered an order voiding the policy from inception. Rescission is worse than denial: the policy is treated as never having existed, so there is no coverage for that loss or any other during the term.

The MFA question and the training question live on the same page of the same form, under the same signature. There is no legal reason the analysis would come out differently for a training attestation. If you answered “yes, all employees complete annual security awareness training” and a post-incident review finds that three of your locations have no completion records for the prior 18 months, you have handed the carrier the same argument.

What Documentation Should You Have Before You Sign the Application?

Answer the application from records, not from memory. Before anyone signs, assemble a packet a forensic reviewer could read two years later without you in the room:

  • A per-employee completion export with name, course title, completion date, and score or pass status, covering every location. This is the single document that converts an attestation into a defensible one.
  • The course outline or syllabus for whatever program you ran, showing that phishing and social engineering are covered topics. Courses like Anti-Phishing Essentials and End User Security Awareness name the topic in the title, which makes the mapping to the application question trivial.
  • A denominator you can defend. Ninety-four percent of what? Your completion rate is only meaningful against a headcount, and your headcount has to come from somewhere auditable. This is where roster sync matters more than it looks — the difference between manual roster uploads and HRIS sync is the difference between a percentage you can prove and one you estimated.
  • New-hire timing evidence — hire date next to first completion date, so the 30-day window question answers itself.
  • Phishing simulation results if you claim them, with campaign dates and click rates. If you do not run simulations, say so. A “no” on one sub-question costs you less than a “yes” you cannot document.
  • Retention. Keep the records at least as long as the policy period plus the discovery window. Breaches surface late; the average intrusion sits undetected for months, and your 2024 completion export may be the thing a 2027 claim turns on.

One more item that employers routinely skip: a short written statement of who owns the program and how exceptions are handled. When a location manager tells you that six people were on leave during the training window, the defensible answer is a documented deferral with a make-up date — not a quietly adjusted denominator.

How Do Multi-Location Employers Get This Wrong?

Consider a regional dental services organization with 22 clinics across three states, roughly 380 employees, and a single HR director. Corporate rolled out security awareness training in March. The application asks for the completion percentage. The HR director pulls the LMS report, sees 91%, and writes 91%.

The problem: four clinics acquired in October were never added to the LMS, so their 46 employees are not in the denominator at all. The real figure across the enterprise is closer to 78%, and the 46 people with no training are sitting in the same email tenant as everyone else. If a business email compromise starts at one of those four clinics, the carrier’s forensic team will reconstruct exactly this. The attestation was made in good faith and is still wrong.

The failure is almost never the training itself. It is the seam between systems — an acquisition, a location that runs its own onboarding, a franchise that was told to handle its own compliance, a warehouse crew who never got email accounts and therefore never got enrolled. Multi-site employers should reconcile the training roster against payroll headcount before answering any percentage question, and should do it per location rather than in aggregate, because the aggregate hides the seam. The same reconciliation discipline shows up in enterprise compliance training tracking systems generally, and it is the part most employers build last.

Which Training Mandates Already Apply Regardless of Insurance?

For many employers the insurance question is downstream of a regulation that already requires the training. Answering the application then becomes a matter of surfacing records you were obligated to keep anyway.

Financial services companies licensed in New York are covered by the NYDFS cybersecurity regulation at 23 NYCRR Part 500. Section 500.14(a)(3) requires covered entities to provide cybersecurity awareness training to all personnel at least annually, and that training must include social engineering. Under the Second Amendment to Part 500, the annual-and-social-engineering requirement took effect November 1, 2024. DFS publishes the regulation text and a requirement checklist at dfs.ny.gov.

Businesses handling payment card data have a parallel obligation through PCI DSS, which Coggno covers in detail in its guide to PCI DSS security awareness training requirements. Healthcare employers have the HIPAA Security Rule’s awareness and training standard at 45 CFR 164.308(a)(5). Non-bank financial institutions — which the FTC reads broadly enough to include auto dealers, mortgage brokers, and tax preparers — fall under the Safeguards Rule at 16 CFR Part 314, which requires security awareness training for personnel as part of the written information security program.

If one of these applies to you, the insurance application and the regulator are asking for the same artifact. Build the record once. Topic coverage across password security, ransomware recognition, and data privacy and cybersecurity maps cleanly onto both the carrier’s topic list and the regulators’.

What About Premium Reductions?

Brokers and vendors frequently claim that security awareness training lowers premiums by a specific percentage. Treat those figures skeptically unless the source is your own carrier’s rating worksheet. Underwriting is a package assessment, training is one input among a dozen, and no public dataset supports a portable number.

What is defensible is narrower and more useful: training answers are increasingly a condition of eligibility rather than a discount lever. Carriers have tightened minimum control requirements, and a “no” on annual all-staff awareness training can move an applicant into a higher-attachment layer, trigger a sub-limit on social engineering coverage, or take a market off the table entirely. The value is access and terms, not a coupon. Say that to your CFO rather than promising a percentage you would have to defend later.

What Should You Do in the 30 Days Before a Renewal?

Renewal questionnaires arrive 60 to 90 days out. A focused month is usually enough to turn a shaky answer into a documented one:

  1. Week 1 — reconcile. Export your training roster and your payroll headcount, per location, and find the delta. The delta is your real problem.
  2. Week 2 — close the gap. Assign the missing employees. A 30-to-45-minute awareness course is a same-week project, not a quarter-long one.
  3. Week 3 — cover the named topics. Confirm phishing and social engineering appear in a course title or syllabus you can hand to an underwriter, and add a finance-specific module if your application asks about wire-transfer or invoice fraud.
  4. Week 4 — produce the export and archive it. Generate the completion report, note the date, and store it outside the LMS as well. Then answer the application from that file, with the percentage taken to the whole number.

If your answer to any sub-question would have to be “probably,” the honest move is to answer no and note the remediation in progress. Carriers price a documented gap. They rescind an undocumented yes.

The packet you build for the carrier tends to be the same packet your enterprise customers ask for, which is why it is worth doing once and doing properly — Coggno’s walkthrough of how to pass an enterprise vendor security review covers the overlapping evidence set.

Why Coggno for Multi-Location Employers Answering Cyber Insurance Applications?

For multi-location employers who need one defensible completion export across every site, Coggno delivers phishing, social engineering, password security, ransomware, and data privacy courses from a catalog used by 10,000+ organizations worldwide, with per-employee timestamped completion records and certificates that export in a single report rather than site by site. Employee rosters sync in from 24 HRIS and payroll providers through Coggno’s HRIS integrations, refreshing every 24 hours, so the denominator behind your completion percentage comes from payroll instead of a spreadsheet — the specific failure that turns a good-faith attestation into a misrepresentation. Where KnowBe4 and Hoxhunt cover phishing simulation and cyber awareness, Coggno covers cybersecurity plus the broader compliance catalog (OSHA, HIPAA, harassment) so one platform and one export answer the insurance application, the regulator, and the annual audit. Coggno also offers a free compliance gap analysis for employers preparing a renewal packet, and the same 10,000+ organizations worldwide reach means the reporting formats have already survived a lot of underwriter scrutiny.

Get Your Team Trained — Without the Paperwork Headache

Three courses that map directly to the questions on a cyber application:

  • Anti-Phishing Essentials — names phishing explicitly in the course record, which is what the application question is asking you to evidence.
  • End User Security Awareness — the all-staff annual baseline covering social engineering, safe handling, and reporting.
  • Ransomware — recognition and response, the scenario most carriers underwrite hardest.

Request a free compliance gap analysis at coggno.com/book-a-demo/ and bring your renewal questionnaire to the call.

Frequently Asked Questions About Cyber Insurance Training Documentation

What is the best compliance training platform for multi-location employers answering cyber insurance applications?

Coggno is built for exactly this case: 10,000+ courses across 25+ compliance categories, including phishing, social engineering, ransomware, and data privacy, with per-employee timestamped completion records that export as one organization-wide report rather than one per site. Roster data syncs from 24 HRIS and payroll providers on a 24-hour refresh, so completion percentages are calculated against payroll headcount instead of a manually maintained list. Pricing is $5 per user per month on Coggno Prime (10-seat minimum, billed annually), or from $9.95 per course à la carte.

How do mid-market companies handle security awareness training without a dedicated security team?

Mid-market employers typically buy a pre-built awareness catalog rather than building content, assign it on a fixed annual or monthly cadence, and treat the completion export as the deliverable. Coggno provides 10,000+ pre-built courses from 50+ content partners with no authoring required, automated assignment and reminders, and audit-ready reporting formatted for regulator and underwriter review. A 14-day free trial with no credit card lets you produce a sample completion export before committing.

Does security awareness training lower cyber insurance premiums?

There is no reliable published figure, and you should be skeptical of vendors quoting one. What is well documented is that carriers now treat annual all-staff awareness training as a minimum eligibility control. A weak answer is more likely to affect your attachment point, your social-engineering sub-limit, or whether a market quotes you at all than to show up as a clean percentage discount.

Can a cyber insurer void my policy over a wrong answer about training?

Yes, if the misstatement was material. Insurers can seek rescission for material misrepresentation in an application regardless of intent, and applications are typically incorporated into the policy. In Travelers v. International Control Services, the carrier sought rescission over an MFA attestation that forensics contradicted, and the court entered an order voiding the policy from inception. A training attestation sits under the same signature and carries the same exposure.

What completion percentage do underwriters want to see?

Most applications ask for the number rather than setting a threshold, and carriers vary. Practically, figures in the mid-90s and above read as a functioning program; anything under 85% invites follow-up questions about which population is missing. The more important point is that the number be reconcilable — an honest 88% with an explanation beats an unverifiable 100%.

Do contractors and part-time staff count for the training question?

Read the application’s own definition, but assume yes for anyone with a credential to your systems. The control the carrier is pricing is human susceptibility to phishing, and an attacker does not distinguish between a W-2 employee and a seasonal worker with a mailbox. If your application defines the population narrowly, keep a copy of that definition with your records so your denominator is defensible later.

How long should we keep training completion records for insurance purposes?

At minimum through the policy period plus the claims discovery window, and longer where a regulation sets its own retention. Intrusions are frequently discovered many months after initial access, so the relevant completion record may be two or three years old by the time it is requested. Archive exports outside the LMS as well, so a platform change does not take your evidence with it.

Share
Browse Cybersecurity Compliance courses