Common problem

The questionnaire asks. Can you answer it?

Cyber insurance applications ask specific technical questions. Most of them are answerable from a Microsoft 365 tenant, and most businesses answer from memory rather than from the tenant.

The questions are technical, the answers are a declaration, and the person signing is usually not the person who could verify them. That gap is the risk, and it is entirely fixable before the form goes back.

Almost all of these can be answered from your Microsoft 365 tenant. Not from what somebody remembers configuring, from what the tenant reports today.

,

What the forms usually ask, and what it means

Read each one carefully. Several are worded so that a confident yes is easy to give and hard to support.

  • Is multi-factor authentication enforced for all users? Enforced, not available. The real answer usually has exceptions in it, and those exceptions are the interesting part.
  • Is MFA enforced on administrative accounts? Asked separately for a reason. An excluded admin account undoes most of the value of the first answer.
  • Are privileged accounts limited and reviewed? How many people hold global administrator, and when anybody last looked. Covered in admin account ownership.
  • Is access removed when somebody leaves? Whether there is a process, and whether it was followed for the last few leavers. See former employee access.
  • Are company devices managed and encrypted? Enrolment and disk encryption, which is Intune and Autopilot. Handing somebody a laptop is not management.
  • Is email filtered and authenticated? Filtering on inbound mail, and SPF, DKIM and DMARC on your own domain so nobody can send as you.
  • Are backups in place and tested? Note the word tested. Microsoft 365 retention is not the same as a backup, and the difference is worth understanding before answering.
  • Is there logging, and for how long? What is retained and how far back you could look. This one varies by licence plan and often surprises people.
,

Before you sign the form

  1. Get the questions in front of somebody technical

    Ideally before the deadline rather than the evening it is due.

  2. Check each answer against the tenant

    Not against what was configured at setup. Configuration drifts.

  3. Write down the exceptions

    Every "yes, except" is worth recording, because that is what an insurer would examine later.

  4. Fix what is quick

    Some of these are an afternoon. MFA exclusions and dormant admin accounts usually are.

  5. Answer honestly about the rest

    A truthful no is a manageable conversation with a broker. An inaccurate yes is a problem at claim time.

,

Who this is for

  • You have a cyber insurance application or renewal in front of you.
  • A customer or a contract requires you to attest to specific controls.
  • You answered these questions last year and are not certain the answers still hold.
  • You are a broker whose client needs the technical work doing.

When this is not the right fit

  • You want advice on which policy to buy, or what a policy covers. We are not insurance advisers and cannot help there.
  • You need somebody to certify or attest on your behalf. We are not an assessor and cannot sign for you.
  • You need continuous monitoring or incident response to satisfy the form.
,
,

Common questions

Can you fill in the questionnaire for us?

We can tell you what is true about your Microsoft 365 environment, in writing, so that whoever signs the form is answering from fact rather than hope. The answers themselves are yours to give, because you are the one making a declaration.

That distinction matters. An inaccurate answer is a problem for your business at exactly the moment you least want one.

We answered yes to MFA. Is that safe?

It depends what "yes" meant. Many tenants have multi-factor authentication available and enabled for some people, with exclusions that have quietly grown, and no enforcement on the accounts that matter most.

The honest version of that answer is usually "for most users, with these exceptions", and it is worth knowing which exceptions before somebody signs.

Do you provide the monitoring these forms ask about?

No. We do not run a twenty-four hour help desk, a security operations centre or a managed detection and response service, and we will not present ourselves as one.

If a form requires continuous monitoring, that is a different kind of provider and we will say so rather than blur it.

Will this get us a better premium?

We have no idea, and anybody who tells you otherwise is guessing about somebody else's underwriting. Pricing is the insurer's decision and it takes in far more than your Microsoft 365 configuration.

What we can do is make the technical answers true. What that is worth to your policy is between you and your broker.

,
Get a Quote

Answer it from the tenant

The review checks each of these and writes down what is actually configured, so the form is filled in from evidence.

Call now Request a quote