What your cyber insurer will actually ask you

A cyber insurance questionnaire is not an audit: it hunts for four or five specific proofs. Knowing which ones changes the premium, and sometimes whether you are covered at all.

A cyber insurance questionnaire looks like a security audit. It is not one. An audit asks where you stand; an insurance questionnaire asks whether you are insurable and at what price, which is a far narrower question.

That difference explains the usual frustration: you prepare dozens of pages on governance, and the insurer keeps coming back to five technical points you have no evidence for.

The questions that decide

The wording changes from one insurer to the next. The substance does not.

Strong authentication, and on exactly which perimeter. Not "do you have MFA". Rather: on remote access, on privileged accounts, on email, yes or no. An answer of "yes, for users" with administrators excluded becomes a negative answer once a claim is filed.

Backups, and above all their restoration. Nobody cares that backups exist. What matters: are they isolated from the domain, and when was the last restore actually tested? A backup never restored is a hypothesis, not a control.

Privileged access management. How many admin accounts, assigned to whom, reviewed when. A tenant with seventeen global administrators, three of them former contractors, is a strong signal — in the wrong direction.

Email filtering and anti-spoofing. This is where DMARC shows up, increasingly by name. The insurer's reasoning is statistical, not ideological: business email compromise and phishing remain the leading vectors behind the claims they pay.

Logging and its retention period. Because in the event of a claim, that is what will — or will not — establish the scope of the compromise, and therefore the amount paid.

The hard part is not doing it, it is proving it

Most organizations we meet already do the essentials. What is missing is dated evidence.

"We enabled MFA everywhere" is a claim. A timestamped export showing effective coverage, privileged accounts included, on a given date, is evidence. The first is worth nothing when filing a claim; the second is worth the file.

That is why we insist on history rather than snapshots: a state at time T says nothing about whether it held the week before, or what has changed since.

How to answer without spending three weeks on it

The approach that works has three steps.

Measure before writing. A configuration scan gives you the tenant's real state in under an hour: strong authentication coverage, privileged accounts, legacy authentication, external sharing, logging. You then answer from facts, not memory.

Fix the two or three gaps that downgrade the file before sending the questionnaire back. An administrator without MFA takes an hour to fix; fixing it before you answer changes the answer.

Attach evidence rather than assertions. A dated export appended to the questionnaire shortens the back-and-forth and avoids the insurer's follow-up three weeks later.

The overlap with NIS2

The two exercises overlap heavily — insurer and regulator care about the same thing: risk management and the ability to account for it. The difference in nature remains total: NIS2 is a legal obligation whose scope you assess with your legal counsel and the competent national authority; insurance is a contract.

In practice, the evidence produced for one serves the other. It is the only compliance work that pays for itself twice. We cover what changes on the email and Microsoft 365 side on our NIS2 page.

David PekmezTwenty years securing Microsoft environments and corporate email, from the endpoint to tenants with several thousand accounts. LinkedIn
Share on LinkedIn

And where does your configuration stand?

Thirty minutes to look at your actual situation. If this article applies to you, we will tell you frankly how much.