SecureMyEmail logoSecureMyEmail
← All articles
Insurance9 July 2026 · 5 min read

Answering the cyber insurance questionnaire honestly

Business owner completing a cyber insurance questionnaire on a tablet

▶ Watch the short explainer for this tip

Cyber insurance applications have changed. Five years ago they asked whether you had antivirus. Now they ask whether multi-factor authentication is enforced on all remote access and email accounts, how many privileged accounts exist, and whether backups are tested and offline. Those are verifiable claims made on a proposal form.

Why 'yes, mostly' is the dangerous answer

A proposal form is a disclosure document. If you attest that MFA is enforced on all email accounts and a claim later traces back to the one service account that was excluded, you have handed the insurer a coverage argument at the worst possible moment.

The fix is not to answer conservatively — it's to answer from evidence rather than memory.

The questions that come from your tenant

  • Is MFA enforced for all users on email and remote access, with no exceptions?
  • How many accounts hold global or super-administrator rights?
  • Are legacy authentication protocols disabled?
  • Are external email auto-forwarding rules blocked or monitored?
  • Is email flagged as external clearly marked to users?
  • Are backups of cloud mail and files retained independently and restore-tested?

What good evidence looks like

A dated report from your tenant showing enforcement counts, admin lists and protocol status — not a screenshot of a settings page. Keep it with the policy documents so the renewal conversation starts from fact.

It also tends to help commercially. Brokers can argue a better position when the controls are documented rather than asserted, and remediating the gaps before renewal is usually cheaper than the premium difference.

Fill the form in from a report, not from recollection. Everything on it is checkable after a claim.

Frequently asked questions

What do insurers actually check on email security?
MFA coverage for all users and admins, blocking legacy authentication, external forwarding controls, email filtering and offboarding. Answering yes without evidence is the common mistake.
Can a claim be declined over an inaccurate questionnaire answer?
Yes. Cover can be reduced or declined where the declared controls were not actually in place at the time of the incident. Dated evidence protects you.
Does the audit report satisfy an insurer?
It gives you dated, tenant-specific evidence of each control an insurer asks about, which is what underwriters want instead of a tick-box declaration.
How often should the evidence be refreshed?
Annually at renewal, and after any major change such as a new IT provider, an acquisition or a migration.

Sources

Every reference below was link-checked when this article was published.

  1. 1.Implementing Multi-Factor AuthenticationAustralian Signals Directorate — ACSC
  2. 2.Block legacy authentication with Conditional AccessMicrosoft Learn
  3. 3.Control automatic external email forwardingMicrosoft Learn
  4. 4.Business Email CompromiseAustralian Signals Directorate — ACSC
  5. 5.Scam statisticsScamwatch — National Anti-Scam Centre

Want to know where your own tenant stands?

The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.