The short version: the work you do for clients is only worth as much as the proof you can show. Insurers, assessors and government buyers increasingly ask to see it, not hear about it. This month, build a one-folder evidence pack for each client with five items, and date everything. Start with your five most important clients.
Why does proof matter more now?
Because the questions have changed from "do you have this?" to "show me". Australian insurance and IT providers report that underwriting has moved from tick-box proposal forms to detailed technical questionnaires, with some insurers asking for configuration reports or external scans for higher cover. Sources include Upcover and 4iT. Treat those as provider reports, since each insurer sets its own rules.
Government's own assessment guidance points the same way. ASD's Essential Eight assessment process guide tells assessors to gather and review credible evidence. They sample systems and accounts and examine configurations and records.
October is Cyber Security Action Month in Australia, and the government has framed it as a move from awareness to action. It is a good prompt to ask your clients a plain question: if someone asked us to prove this today, what would we hand over?
What is the evidence problem?
You fix something, the client is safer, and nothing is written down. Six months later the insurer, auditor or buyer asks. You either scramble for screenshots or answer from memory. The control may be perfectly in place, but "we did it" without a date and a record often gets treated as "we can't show it".
ASD's guide also has an outcome for exactly this situation: "No visibility", where the assessor could not get adequate visibility of a control. That is a worse place to be than a control you know is weak, because you cannot even start fixing what you cannot show.
What counts as good evidence?
Good evidence is dated, scoped and shows the setting itself. Check each item against three questions:
- Dated: can a reader see when it was captured?
- Scoped: does it show which tenant, users or devices it covers?
- Specific: does it show the actual setting, not only a page title?
A Conditional Access policy export that names the tenant, lists the policy state as On and shows the user scope passes all three. A cropped screenshot of a green tick passes none.
The five-item evidence pack
Build this folder per client. It takes an afternoon the first time, and about 30 minutes to refresh.
| Item | What to capture | Where to get it in Microsoft 365 |
|---|---|---|
| 1. Sign-in protection | MFA and Conditional Access policy list, with scope and state | Entra admin centre, Conditional Access |
| 2. Admin accounts | List of admin role holders, and which use phishing-resistant MFA | Entra admin centre, Roles and administrators |
| 3. Device health | Patch status and encryption status by device | Intune, device compliance report |
| 4. Backups | Backup policy, plus the date and result of the last restore test | Your backup platform |
| 5. Decisions | Signed notes for accepted risks and exceptions | Your own records |
Save each file with the date in the name. Never overwrite last quarter's file. The history is part of the proof, because it shows the control was on continuously, not switched on the week before the questionnaire.
If you're a small business
Ask your IT provider two questions: "Can you show me a dated report that MFA covers everyone?" and "When did you last test a restore?" If either answer is a shrug, that is your first job. You do not need to understand the report. You need it to exist, be dated, and sit somewhere you can find it.
If you're an MSP
Turn evidence into a service line. Clients already pay you to do the work, and many do not know they can also pay for the proof. A quarterly evidence refresh is a fixed-scope, low-effort item you can price into a plan. It also protects you: when a client is asked to prove a control, the file shows you did your part.
Worked example
A 20-person accounting firm renews its cyber policy in December. The broker's form asks whether MFA covers all users and admins, and whether backups are tested. Because the MSP kept a dated pack, it exports the Conditional Access policy list in October, notes that two admin accounts still use SMS codes, and moves them to passkeys. It attaches the updated export and the last restore test log. The renewal answers take 20 minutes, and every one is backed by a file.
Where CYBERWHITE fits
We built CYBERWHITE around this problem. One Microsoft 365 scan checks the Essential Eight controls and feeds the other frameworks, and it produces dated, exportable evidence per client. When AutoFix deploys a policy, it takes a snapshot first and logs the change with rollback available, so there is a record of what changed and when. AutoFix supports a control being in place. Whether an assessor rates it effective is their call, not ours.
You can do this by hand with the table above. CYBERWHITE cuts the repeat work across a portfolio. See MSP solutions, the free Essential 8 assessment or pricing.
Your checklist
- Pick your five most important clients and make one folder each.
- Export the Conditional Access and MFA policy list, dated.
- List admin role holders and their MFA method.
- Export the Intune device compliance report.
- Run one restore test and save the result.
- Collect signed notes for every accepted risk.
- Set a quarterly reminder to refresh each folder.
Sources
- Australian Signals Directorate (ASD): Essential Eight assessment process guide, cyber.gov.au
- Upcover: Cyber insurance requirements in Australia
- 4iT: Cyber insurance for Australian SMEs in 2026
- Cyber.gov.au: Cyber Security Action Month 2026
Keep reading: How an Essential 8 Assessment Works: Process, Evidence and Timelines and Essential 8 MFA Requirements and Microsoft is retiring SMS MFA: a passkey rollout plan for MSPs