August 21, 2026

Vendor Security Questionnaire: Insurance Answers Malaysia

Written by
Michelle Chin

Entrepreneur & strategist - experienced in driving digital-first insurance innovation, with extensive experience in scaling successful businesses

A procurement email arrives with a spreadsheet attached. Forty to two hundred questions, a due date five working days out, and a line saying the contract cannot proceed until it comes back complete. Somewhere around question 90, under a heading like Risk Transfer or Insurance, are four or five questions about your policies.

That short section is answered badly more often than any other part of the questionnaire, and it is the one where a wrong answer is written down and kept.

This is for Malaysian suppliers filling one in: software vendors, agencies, consultancies, payroll and data processors, anyone whose customer has a vendor risk team.

Stuck on the insurance section with a deadline this week?

Send us the questions and your policy schedule and we will tell you what you can answer yes to and what you cannot. We place cybersecurity insurance for Malaysian technology and services businesses.

WhatsApp Us Now

Key Facts: Insurance Questions in a Vendor Security Questionnaire

What is a vendor security questionnaire? A standard set of questions a buyer sends before onboarding a supplier who will touch their systems or their data. It is due diligence, and the answers usually become a contractual representation.

Why does it ask about insurance at all? Because the buyer is measuring what happens after a failure, not just how likely one is. Controls tell them how well you defend; insurance tells them whether you can absorb the cost if the defence fails.

Is cyber insurance required in Malaysia? No Malaysian statute requires a business to carry cyber insurance. The Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024, imposes obligations on how you handle personal data, not an obligation to insure. Where you are being asked for cyber cover, the requirement is contractual and comes from your buyer.

Which policy answers a cyber question? A cyber liability policy answers breach response, notification, forensics and extortion. A professional indemnity policy answers financial loss caused by your service failing. Buyers frequently ask for both, and one will not satisfy a question about the other.

What is the single most common wrong answer? Answering yes to a cyber insurance question on the strength of a general business or office package policy. Those policies rarely carry a cyber section, and the schedule will show it.

Last verified: August 2026. Checked against the Verizon 2026 and 2025 Data Breach Investigations Reports and the current PDPA breach notification position.

Why the insurance section exists

Third-party failure has become one of the main ways large organisations get breached, and the people sending you the questionnaire have watched that number move. Verizon's own summary of its 2026 report puts it directly:

"breaches involving a third party now accounting for 48% of all breaches"

Source: Verizon, 2026 Data Breach Investigations Report, published 19 May 2026, which also reports that third-party involvement in breaches is up 60%.

A year earlier the same report put third-party involvement at 30%, and described that figure as having doubled from the previous edition. The direction of travel is the reason your buyer now has a vendor risk team and a questionnaire.

The questions you will actually see, and what each one is testing

Wording differs between buyers and between the platforms they use, but the underlying questions are stable. The table below gives the question, the thing being tested, and where your answer comes from.

The question What it is testing Where your answer comes from
"Do you maintain cyber liability insurance?" Whether a dedicated cyber policy exists, not whether you have any insurance A cyber policy schedule with its own limit
"State the limit of indemnity" Whether the limit is proportionate to the data and revenue at stake The limit line on the schedule, and whether it is per claim or aggregate
"Do you maintain professional indemnity or errors and omissions cover?" Whether a service failure that causes them financial loss is insured A separate professional indemnity or technology E&O schedule
"Does your policy cover breaches caused by your subcontractors?" Whether their risk stops at you or runs down your own supply chain The wording, not the schedule. This one usually needs your insurer to answer
"Will you name us as an additional insured or provide a certificate?" Whether they get evidence and standing, or just your word Your insurer. Do not commit to this in a questionnaire before asking
"Have you made a claim in the last three to five years?" Your incident history, cross-checked later against anything you disclose elsewhere Your own records. Answer it the same way you answered your insurer
"Does your cover extend to regulatory fines?" Whether you understand your own policy Your wording and your insurer, and see the caution below

The last question deserves care. Regulatory fines and penalties are frequently uninsurable as a matter of public policy, and the answer for your specific policy depends on your wording. Do not write yes because it would be a better answer. Say that it depends on the wording and that you will confirm it, then go and confirm it.

"We have general business insurance" is the answer that fails

It fails because the person reading it will ask for the schedule, and the schedule will not have a cyber section on it. At that point you have not just failed the question, you have created a record of an answer that was not accurate.

The comparison below shows what different policies actually answer.

Their question Answered by an SME package policy? Answered by
Customer data exposed in a breach of your systems Usually not Cyber liability
Your software defect causes the client a financial loss No Professional indemnity or technology E&O
A visitor is injured at your office Usually yes Public liability section
Ransomware stops you delivering the service No Cyber liability, including the business interruption section where one is bought
Laptops and servers stolen from the office Usually yes, for the hardware Burglary or all risks section. The data on them is a separate question

The last row is where the two worlds meet and where most confusion lives. The property policy replaces the machine. Nothing in it deals with the personal data that left the building on it.

Answering a questionnaire is a poor time to discover a gap.

If the honest answer to two of these questions is no, the fix is usually one policy and a short underwriting conversation. See professional indemnity insurance and our cyber insurance guide for what each one answers.

Get a Quote

How to answer the limit question without overstating

Give the figure exactly as it appears on the schedule, and give the basis with it. "RM1,000,000 any one claim and in the aggregate" is a complete answer. "RM1 million" is not, and it invites a follow-up you will have to answer anyway.

Where your limit is lower than the buyer wants, say the number and say what you can do about it. Buyers accept a supplier who is short and honest about it far more readily than one whose evidence contradicts their form.

This table sets out the phrasing that survives review and the phrasing that generates a second round.

Weak answer Why it comes back Better answer
"Yes, fully insured" Says nothing checkable Name the policy type, the limit and the basis
"RM1 million" Omits whether it is per claim or aggregate "RM1,000,000 any one claim and in the aggregate"
"Covered under our business policy" The schedule will not support it Name the section, or answer no and say what you are arranging
"Yes" to subcontractor coverage Almost nobody has checked their wording before answering "Confirming with our insurer, response by [date]"

When the honest answer is no

A no with a plan reads better than a yes that unravels. This table gives the wording for the three nos suppliers most often have to write.

The question you must answer no to What to write What to arrange
No cyber policy at all "No standalone cyber liability policy currently in force. Cover is being arranged, expected in place by [date]." A cyber policy, sized against the data you hold rather than your revenue
Limit below what they asked for State your actual limit and basis, then "we can increase to [figure] on confirmation of award." A quotation for the higher limit, so the commitment is real
Subcontractor coverage unknown "Referred to our insurer for written confirmation, response by [date]." The written answer, kept on file for the next questionnaire

What to attach, and what to keep back

Attach the policy schedule or a certificate of insurance. Both show the insured name, the policy type, the limit and the period, which is everything the question is asking.

Do not attach the full policy wording, your proposal form, or your claims correspondence unless the contract specifically requires it. The proposal form in particular contains your own risk disclosures, and it is not a document to circulate through a procurement portal.

Redact nothing on the schedule itself. A schedule with the limit blacked out reads as an evasion, and it will be sent back.

Run these five checks before the file leaves your outbox.

Check Done
Every yes is supported by a document you have actually opened
Insured name on the schedule matches the entity that will sign the contract
Every limit is stated with its basis, per claim or aggregate
Policy period runs past the intended contract start date
No proposal form, claims file or full wording attached by accident

Where the questionnaire and the contract disagree

The questionnaire and the draft contract are usually written by different teams, and they routinely ask for different things. When they do, the contract is the document that binds you.

The table below shows the disagreements worth raising before signature.

Disagreement What to do
Questionnaire asks for RM1,000,000, contract asks for RM5,000,000 Work to the contract figure, and raise it in writing before you sign
Questionnaire asks only about cyber, contract requires cyber and professional indemnity Treat them as two requirements and price both
Contract requires cover "for the term and for three years after" This is a run-off obligation. Establish what it costs before agreeing to it
Questionnaire answer becomes a contractual warranty by reference Re-read every answer you gave. It is now a promise, not a form

That last row is the reason to take the section seriously. Many enterprise contracts incorporate the completed due diligence responses by reference, which turns a spreadsheet filled in under time pressure into a set of representations you have to stand behind.

The table below tracks where your answers go after you press send, and what each stage does with them.

Stage What the buyer does with your answers What it means for you
Scoring Answers are scored and gaps flagged for follow-up A vague answer generates a second round rather than a pass
Evidence request Schedules and certificates are requested against specific answers Any answer your documents do not support surfaces here
Contracting Responses are often incorporated into the agreement by reference Your answers become promises you are contractually bound to
Annual review The questionnaire is reissued, usually pre-populated with last year's answers A commitment you made and did not keep reappears in writing

The obligation you do have under Malaysian law

No Malaysian statute makes you buy cyber insurance. There is a separate obligation that catches most suppliers handling personal data, and it is worth separating the two clearly in your own head before you answer a compliance question.

Your duties sit in the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024. Two of them bite here: the Personal Data Protection (Data Breach Notification) requirements, mandatory from 1 June 2025, and mandatory DPO appointment, effective 1 June 2025. Both govern conduct around an incident, and neither requires a policy.

Insurance is how the cost of meeting those duties gets funded, which is a different sentence from saying the law requires it, and a buyer's compliance team will notice if you blur them. Our PDPA compliance checklist and breach response plan guide cover the obligation side.

Third-party risk, with sources and dates

The figures below are the ones behind the growth of vendor questionnaires, each with its publisher and publication date.

Figure Source Date
Third-party involvement in breaches is up 60%, with breaches involving a third party now accounting for 48% of all breaches Verizon, 2026 Data Breach Investigations Report 19 May 2026
Software flaws at 31% overtook stolen credentials as the leading entry point Verizon, 2026 Data Breach Investigations Report 19 May 2026
Third-party involvement in breaches doubled to 30% the previous year, across 12,195 confirmed breaches analysed Verizon, 2025 Data Breach Investigations Report 23 April 2025
Ransomware was present in 88% of breaches at small and medium businesses Verizon, 2025 Data Breach Investigations Report 23 April 2025

Read against each other, the 2025 and 2026 figures explain the shift in buyer behaviour better than any argument about controls. Your buyer is not asking because they distrust you specifically. They are asking because roughly half their breach exposure now arrives through somebody like you.

FAQ

Can I answer the insurance section before I have bought the policy?

Answer honestly about what you hold today and state separately what you are arranging and by when. A dated commitment is a normal answer that vendor risk teams accept. A yes that your schedule does not support is the answer that damages the relationship, because it will be checked at contract stage.

Does a cyber policy pay a PDPA fine?

Regulatory fines and penalties are frequently uninsurable as a matter of public policy, and whether any part of a regulatory response is covered depends entirely on your own wording. Do not state a position on this in a questionnaire from memory. Ask your insurer to confirm in writing what your specific policy does and does not respond to.

Our client wants to be named as an additional insured. Can we just tick yes?

No. Adding a party to a policy is a change only the insurer can make, and cyber and professional indemnity policies handle it differently from liability policies. Answer that the request has been referred to your insurer, and get the position confirmed before it goes into the contract.

What is the difference between a certificate of insurance and a policy schedule?

A certificate is a short confirmation that a policy exists, showing the insured, the type, the limit and the period. A schedule is the operative document issued with the policy and carries more detail, including the basis of the limit and any retroactive date. Where a buyer wants to verify specific terms, the schedule is what answers them.

The questionnaire came from a platform, not a person. Does that change anything?

Not for the insurance section. Automated platforms score the answers and flag gaps for a human to follow up, so an inaccurate answer is more likely to be caught, not less. Answer from the schedule in front of you rather than from what you remember buying.

How long should this section take?

About twenty minutes if you have your schedules to hand, and several days if you do not. The two questions that genuinely need an insurer's input are subcontractor coverage and any request to name the client on the policy. Start those first and fill in the rest while you wait.

Contingent Conclusion

The insurance section is short, and it is the part of a vendor security questionnaire that gets answered from memory rather than from documents. That is why it produces contradictions later, when procurement asks for the schedule that supports the answer.

Answer it with your schedules open. Name the policy type, the limit and the basis, say no where the answer is no, and refer the two questions that belong to your insurer rather than guessing at them.

Contingent helps Malaysian businesses get the cover their contracts and landlords require. Whether you're comparing options or checking whether your existing policy actually does what the contract asks, we can help.

Get a quote · or WhatsApp us directly

Further reading: cyber security insurance for Malaysian businesses, data breach insurance and the PDPA, and professional indemnity for SaaS startups.

Published by Contingent, the commercial insurance brand of Emerge Insurtech (Malaysia) Sdn. Bhd.

Disclaimer: This article provides general guidance on insurance questions in vendor due diligence for Malaysian businesses as of August 2026. Insurance terms, coverage, and availability vary by insurer and risk profile. This is not a policy document. Always consult a qualified insurance professional before making coverage decisions.

Protect your revenue, people and systems today