Answering the cyber insurance questionnaire honestly

▶ Watch the short explainer for this tip
Cyber insurance applications have changed. Five years ago they asked whether you had antivirus. Now they ask whether multi-factor authentication is enforced on all remote access and email accounts, how many privileged accounts exist, and whether backups are tested and offline. Those are verifiable claims made on a proposal form.
Why 'yes, mostly' is the dangerous answer
A proposal form is a disclosure document. If you attest that MFA is enforced on all email accounts and a claim later traces back to the one service account that was excluded, you have handed the insurer a coverage argument at the worst possible moment.
The fix is not to answer conservatively — it's to answer from evidence rather than memory.
The questions that come from your tenant
- Is MFA enforced for all users on email and remote access, with no exceptions?
- How many accounts hold global or super-administrator rights?
- Are legacy authentication protocols disabled?
- Are external email auto-forwarding rules blocked or monitored?
- Is email flagged as external clearly marked to users?
- Are backups of cloud mail and files retained independently and restore-tested?
What good evidence looks like
A dated report from your tenant showing enforcement counts, admin lists and protocol status — not a screenshot of a settings page. Keep it with the policy documents so the renewal conversation starts from fact.
It also tends to help commercially. Brokers can argue a better position when the controls are documented rather than asserted, and remediating the gaps before renewal is usually cheaper than the premium difference.
Fill the form in from a report, not from recollection. Everything on it is checkable after a claim.
Frequently asked questions
- What do insurers actually check on email security?
- MFA coverage for all users and admins, blocking legacy authentication, external forwarding controls, email filtering and offboarding. Answering yes without evidence is the common mistake.
- Can a claim be declined over an inaccurate questionnaire answer?
- Yes. Cover can be reduced or declined where the declared controls were not actually in place at the time of the incident. Dated evidence protects you.
- Does the audit report satisfy an insurer?
- It gives you dated, tenant-specific evidence of each control an insurer asks about, which is what underwriters want instead of a tick-box declaration.
- How often should the evidence be refreshed?
- Annually at renewal, and after any major change such as a new IT provider, an acquisition or a migration.
Sources
Every reference below was link-checked when this article was published.
- 1.Implementing Multi-Factor AuthenticationAustralian Signals Directorate — ACSC
- 2.Block legacy authentication with Conditional AccessMicrosoft Learn
- 3.Control automatic external email forwardingMicrosoft Learn
- 4.Business Email CompromiseAustralian Signals Directorate — ACSC
- 5.Scam statisticsScamwatch — National Anti-Scam Centre
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.


