Cyber insurance for construction companies stopped being a checkbox purchase several years ago. Carriers took heavy ransomware losses, tightened underwriting, and now send a supplemental application that reads like a security audit. Answer it wrong and you either get declined, get quoted with a ransomware sublimit that guts the coverage, or, worst case, get a policy that a carrier can later void because an answer was inaccurate.
Here is what those applications actually ask for, why construction companies specifically get tripped up, and what it takes to answer honestly.
The five controls that decide whether you get a policy
These are the questions where a “no” usually ends the conversation, regardless of your revenue, claims history, or broker relationship.
1. Multi-factor authentication on email, remote access, and administrative accounts. All three, not just email. Business email compromise is the most common claim carriers see, and unprotected VPN or remote desktop access is the most common ransomware entry point. Underwriters ask about each separately because companies frequently have MFA on Microsoft 365 and nothing on the VPN into the office server.
2. Endpoint detection and response on every endpoint. Servers, office workstations, laptops, and the machines in the jobsite trailer. Applications now distinguish EDR from antivirus, and many ask whether it is monitored around the clock. A tool nobody watches at 2am on a Saturday is not the answer they’re looking for.
3. Backups that are offline or immutable, segregated from the network, and tested. The test part matters. Several applications ask when you last performed a full restore test, not whether backups are running. If your last verified restore is “we’ve never actually tried”, that is the honest answer and it is a problem worth fixing before you submit. Our backup and disaster recovery service exists largely because untested backups fail at exactly the wrong moment.
4. Email filtering plus security awareness training with phishing simulation. Carriers want a technical control and a human one. Training with no simulated phishing tests is generally treated as weaker than training with them, because simulations produce a measurable click rate the underwriter can look at.
5. A written, tested incident response plan. Written means a document that names who calls the carrier, who calls the attorney, who isolates systems, and who talks to the owner and the GC. Tested means you have walked through it at least once. This one is free to fix and is disproportionately common as a “no”.
Where construction companies specifically get caught
The supplemental application is industry-agnostic, but construction environments create predictable failure points.
Jobsite trailers. A trailer with a consumer router, one shared Wi-Fi password used by everyone including subs and inspectors, and a port forwarded so the superintendent can reach a PC from home will fail the remote access questions outright. The fix is business-grade equipment with the trailer network segmented from guest access, and remote access that runs through an MFA-protected connection instead of an open port. Setting jobsite connectivity up properly is a one-time project, not an ongoing cost.
On-premise construction software servers. Jonas, Sage 300 CRE, Viewpoint, and similar systems often run on a server nobody wants to touch during an active project. Underwriters ask how quickly critical patches get applied, typically expecting 30 days or better for critical severity. “We patch during the winter slowdown” is not a passing answer. See our notes on supporting Jonas and other construction platforms for how this gets handled without project downtime.
Shared logins on field devices. Tablets and trailer PCs used by whoever is on shift, logged into a single generic account, break the privileged access and accountability questions. They also make an incident nearly impossible to investigate, which is what the carrier’s forensics firm will need to do.
Funds transfer controls. This is the one construction companies underestimate. Applications ask whether you verify banking detail changes by callback to a known phone number before sending payment. With subcontractor payments, progress billing, and lien waivers moving by email constantly, construction is a prime target for payment diversion fraud, and the funds transfer fraud coverage in your policy usually depends on having attested to a verification procedure.
The controls that shape your premium
Past the five gating items, applications commonly ask about privileged access management and separate admin accounts, network segmentation, encryption on laptops, centralized logging with a stated retention period, vulnerability scanning, end-of-life systems still in production, and whether you have removed local administrator rights from standard users. None of these individually will sink an application, but a cluster of “no” answers moves you into a worse pricing tier or a lower ransomware sublimit.
If you want a framework to work against rather than chasing one carrier’s form, CIS Controls Implementation Group 1 covers nearly everything the standard supplemental application asks about, in a defined order.
Answer the application accurately, every time
The application is a warranty, not a wish list. Attesting to a control you do not have gives the carrier grounds to deny a claim or rescind the policy after the fact, which is a materially worse outcome than being declined up front. If a question is a “no”, answer “no”, then decide whether to fix it before binding or accept the pricing.
The practical sequence is: get the supplemental application from your broker, go through it honestly with whoever runs your IT, list the “no” answers, and fix the five gating controls first. Most construction companies in the Houston and Dallas-Fort Worth area can close those five gaps in a matter of weeks, not quarters, because the environments are small enough to move quickly.
If you want an outside read on where you stand before submitting, a cyber security risk assessment maps your current state against the same controls underwriters ask about, and our cybersecurity services cover the ongoing pieces, EDR monitoring, patching, training, and testing, that a carrier will re-verify at every renewal.
