MSP Insights··5 min read

The evidence problem: you did the security work, but can you prove it?

Insurers, assessors and buyers now ask for proof, not promises. Here is the five-item evidence pack an MSP can build for each client, starting this month.

By Pardeep Sharma

The short version: the work you do for clients is only worth as much as the proof you can show. Insurers, assessors and government buyers increasingly ask to see it, not hear about it. This month, build a one-folder evidence pack for each client with five items, and date everything. Start with your five most important clients.

Why does proof matter more now?

Because the questions have changed from "do you have this?" to "show me". Australian insurance and IT providers report that underwriting has moved from tick-box proposal forms to detailed technical questionnaires, with some insurers asking for configuration reports or external scans for higher cover. Sources include Upcover and 4iT. Treat those as provider reports, since each insurer sets its own rules.

Government's own assessment guidance points the same way. ASD's Essential Eight assessment process guide tells assessors to gather and review credible evidence. They sample systems and accounts and examine configurations and records.

October is Cyber Security Action Month in Australia, and the government has framed it as a move from awareness to action. It is a good prompt to ask your clients a plain question: if someone asked us to prove this today, what would we hand over?

What is the evidence problem?

You fix something, the client is safer, and nothing is written down. Six months later the insurer, auditor or buyer asks. You either scramble for screenshots or answer from memory. The control may be perfectly in place, but "we did it" without a date and a record often gets treated as "we can't show it".

ASD's guide also has an outcome for exactly this situation: "No visibility", where the assessor could not get adequate visibility of a control. That is a worse place to be than a control you know is weak, because you cannot even start fixing what you cannot show.

What counts as good evidence?

Good evidence is dated, scoped and shows the setting itself. Check each item against three questions:

  • Dated: can a reader see when it was captured?
  • Scoped: does it show which tenant, users or devices it covers?
  • Specific: does it show the actual setting, not only a page title?

A Conditional Access policy export that names the tenant, lists the policy state as On and shows the user scope passes all three. A cropped screenshot of a green tick passes none.

The five-item evidence pack

Build this folder per client. It takes an afternoon the first time, and about 30 minutes to refresh.

ItemWhat to captureWhere to get it in Microsoft 365
1. Sign-in protectionMFA and Conditional Access policy list, with scope and stateEntra admin centre, Conditional Access
2. Admin accountsList of admin role holders, and which use phishing-resistant MFAEntra admin centre, Roles and administrators
3. Device healthPatch status and encryption status by deviceIntune, device compliance report
4. BackupsBackup policy, plus the date and result of the last restore testYour backup platform
5. DecisionsSigned notes for accepted risks and exceptionsYour own records

Save each file with the date in the name. Never overwrite last quarter's file. The history is part of the proof, because it shows the control was on continuously, not switched on the week before the questionnaire.

If you're a small business

Ask your IT provider two questions: "Can you show me a dated report that MFA covers everyone?" and "When did you last test a restore?" If either answer is a shrug, that is your first job. You do not need to understand the report. You need it to exist, be dated, and sit somewhere you can find it.

If you're an MSP

Turn evidence into a service line. Clients already pay you to do the work, and many do not know they can also pay for the proof. A quarterly evidence refresh is a fixed-scope, low-effort item you can price into a plan. It also protects you: when a client is asked to prove a control, the file shows you did your part.

Worked example

A 20-person accounting firm renews its cyber policy in December. The broker's form asks whether MFA covers all users and admins, and whether backups are tested. Because the MSP kept a dated pack, it exports the Conditional Access policy list in October, notes that two admin accounts still use SMS codes, and moves them to passkeys. It attaches the updated export and the last restore test log. The renewal answers take 20 minutes, and every one is backed by a file.

Where CYBERWHITE fits

We built CYBERWHITE around this problem. One Microsoft 365 scan checks the Essential Eight controls and feeds the other frameworks, and it produces dated, exportable evidence per client. When AutoFix deploys a policy, it takes a snapshot first and logs the change with rollback available, so there is a record of what changed and when. AutoFix supports a control being in place. Whether an assessor rates it effective is their call, not ours.

You can do this by hand with the table above. CYBERWHITE cuts the repeat work across a portfolio. See MSP solutions, the free Essential 8 assessment or pricing.

Your checklist

  • Pick your five most important clients and make one folder each.
  • Export the Conditional Access and MFA policy list, dated.
  • List admin role holders and their MFA method.
  • Export the Intune device compliance report.
  • Run one restore test and save the result.
  • Collect signed notes for every accepted risk.
  • Set a quarterly reminder to refresh each folder.

Sources

  • Australian Signals Directorate (ASD): Essential Eight assessment process guide, cyber.gov.au
  • Upcover: Cyber insurance requirements in Australia
  • 4iT: Cyber insurance for Australian SMEs in 2026
  • Cyber.gov.au: Cyber Security Action Month 2026

Keep reading: How an Essential 8 Assessment Works: Process, Evidence and Timelines and Essential 8 MFA Requirements and Microsoft is retiring SMS MFA: a passkey rollout plan for MSPs

Frequently asked questions

What counts as evidence for a security control?
Something dated that shows the control is on and covers the right systems: a configuration export, a policy report from your admin portal, a restore test log, or an approval record. A screenshot with no date or scope is weak. A report with a date, a tenant name and the settings visible is much stronger.
Does ASD accept self-declared answers in an Essential Eight assessment?
ASD's assessment process guide tells assessors to gather and review credible evidence, and says the quality of evidence varies with the approach taken. An assessor samples systems and accounts and checks configurations and records. Plan for your answers to be tested.
How often should we refresh client evidence?
Refresh it before every renewal, assessment or tender, and after any major change such as a new tenant policy or a staff turnover in admin roles. A quarterly review is a sensible habit. Evidence more than a few months old invites questions.
Is a signed statement from the client enough?
A signed statement records who accepted a risk or approved a decision. It does not prove a control is working. Keep both: the sign-off for decisions, and dated technical evidence for controls.

Ready to assess your compliance?

CYBERWHITE helps Australian businesses reach Essential 8 and SMB1001 audit-readiness faster. Start with our free 5-minute assessment.