The renewal packet usually arrives through your broker, and somewhere past the revenue questions it turns technical. Is MFA enforced for remote access? Are backups kept offline, and when were they last tested?
Somebody has to answer those questions, and somebody in leadership signs the application. Often those are different people, and the renewal can land in the middle of storm season when everyone who'd gather evidence is also running jobs.
Your broker is the insurance professional here, and nothing in this article is insurance or legal advice. It covers the step before any answer goes on the form: confirming what's actually configured and what evidence supports it.
Why cyber insurance applications ask technical questions
An insurer can't inspect every applicant's systems, so the application does a lot of the work. When Oxford researchers studied 24 cyber insurance proposal forms from UK and US insurers in 2017, they described the typical form as a self-assessed questionnaire. Your answers are part of what the insurer uses to decide if it will offer coverage and on what terms.
The questions vary by insurer and by application. One form might ask a single yes-or-no about MFA, and another might break it out system by system. Treat the form in front of you as the checklist. Last year's answers and another company's application aren't a reliable guide.
Two kinds of answer
"We pay our MSP for this" is a true statement about a contract.
"We've checked what's configured, and here's the evidence" is a statement about your systems. That's the one leadership should have in hand before signing.
None of this suggests the MSP is cutting corners. The MSP is usually the best source of technical evidence. The question is whether anyone has compared that evidence against the exact wording on the form, especially when a question asks about "all users" or "all remote access."
What to verify, control by control
MFA coverage
Ask for proof by system and by user. In Microsoft 365, the user registration details report in Microsoft Entra shows which users are MFA capable, and viewing it requires an Entra ID P1 or P2 license. A user can be registered for MFA without a policy requiring it at every sign-in, so also ask which policy enforces it and which accounts are excluded.
Then look past email. Remote access tools and the accounting system are worth checking one at a time. CISA recommends requiring MFA wherever possible and starting with privileged, administrative and remote access users.
Privileged and administrator accounts
Get the current admin list for Microsoft 365 or Google Workspace, plus admin roles inside the accounting system and the job management platform. Microsoft recommends keeping the Global Administrator role to fewer than five people. For each admin account, confirm who uses it and that it's separate from that person's everyday email.
Endpoint and security tools
If the form asks about endpoint protection or EDR, ask your provider for a device list showing which computers and servers report to the security console and when each one last checked in. Compare it against what the company actually owns. Field tablets and the shared front-desk PC at a branch are easy to leave off.
Backups and restore testing
CISA's #StopRansomware Guide recommends offline, encrypted backups of critical data and regular testing of their availability and integrity. Ask what's backed up, where the copies live, if they can be reached from the main network and when someone last restored something on purpose. A backup report shows the job ran. A restore test shows you can get the data back.
For a restoration company, think past the server. Job photos and moisture logs often live in vendor platforms, and what those vendors back up is set by their contracts.
Remote access
List every way someone can get in from outside: VPN, remote desktop tools, the MSP's remote management agent and any vendor support tools. Each one needs a named owner and, where the form asks, evidence of MFA.
Offboarding
Applications sometimes ask how access is removed when someone leaves. Pull the last few departures and check that those accounts are disabled everywhere, including job management and vendor portals. The offboarding test in our article on MSP responsibilities is a fast way to run it.
Who should answer each question
The roles stay cleaner when they're written down.
| Role | Responsibility |
|---|---|
| Broker | Insurance and coverage guidance |
| MSP or internal IT | Technical operation, evidence and remediation |
| Independent reviewer | Checks technical answers against available evidence |
| Company leadership | Makes the representations and the final decisions |
It's normal for the provider that runs the systems to draft the technical answers. Leadership signs them, so leadership should know what evidence sits behind each one.
Build an evidence file before anyone signs
- Get the current questionnaire from your broker and work from its exact wording.
- Name the person who will supply evidence for each technical question.
- Collect dated exports or screenshots: the MFA report, the admin list, the device list and the record of the last restore test.
- Mark each answer as verified, evidence missing, a control gap or not determined, and take the open items to your broker and provider before signing.
Common questions about cyber insurance renewals
Does every cyber insurer require the same controls?
No. Requirements vary by insurer and by application, and they can change with the underwriting situation. Your broker is the right person to explain what a specific carrier is asking for.
Can our MSP fill out the technical section?
Your MSP is often the right source for technical answers and evidence. Leadership still makes the representations, so review the evidence behind each answer before signing.
Will verifying our controls guarantee renewal or a lower premium?
No. Underwriting decisions belong to the insurer. Verification gives leadership an accurate record of what's configured before making representations about it.
Sources (accessed October 5, 2026)
- Woods et al., Mapping the coverage of security controls in cyber insurance proposal forms, Journal of Internet Services and Applications (2017)
- Microsoft Learn: Authentication methods activity and user registration details
- Microsoft Learn: Best practices for Microsoft Entra roles
- CISA: Require Multifactor Authentication
- CISA: #StopRansomware Guide
