Answering the cyber insurance questionnaire honestly

Cyber insurance applications have changed. Five years ago they asked whether you had antivirus. Now they ask whether multi-factor authentication is enforced on all remote access and email accounts, how many privileged accounts exist, and whether backups are tested and offline. Those are verifiable claims made on a proposal form.
Why 'yes, mostly' is the dangerous answer
A proposal form is a disclosure document. If you attest that MFA is enforced on all email accounts and a claim later traces back to the one service account that was excluded, you have handed the insurer a coverage argument at the worst possible moment.
The fix is not to answer conservatively — it's to answer from evidence rather than memory.
The questions that come from your tenant
- Is MFA enforced for all users on email and remote access, with no exceptions?
- How many accounts hold global or super-administrator rights?
- Are legacy authentication protocols disabled?
- Are external email auto-forwarding rules blocked or monitored?
- Is email flagged as external clearly marked to users?
- Are backups of cloud mail and files retained independently and restore-tested?
What good evidence looks like
A dated report from your tenant showing enforcement counts, admin lists and protocol status — not a screenshot of a settings page. Keep it with the policy documents so the renewal conversation starts from fact.
It also tends to help commercially. Brokers can argue a better position when the controls are documented rather than asserted, and remediating the gaps before renewal is usually cheaper than the premium difference.
Fill the form in from a report, not from recollection. Everything on it is checkable after a claim.
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.

