MSP Insights··5 min read

Cyber insurance questionnaire: an MSP walkthrough for renewal season

Cyber insurance renewals start in December. Here are the questions insurers ask, what each one means, and the evidence an MSP should attach to every answer.

By Pardeep Sharma

The short version: Cyber insurance renewal season runs from December to February, and the questionnaire arrives with a deadline. Your client signs it, so your job is to make every answer true and provable. Pull the evidence for MFA, backups, patching, endpoint protection and training in October, while there is time to fix a gap instead of explaining it.

What do cyber insurers ask?

They ask the same handful of questions in different words. Australian brokers and MSPs describing 2026 proposal forms, such as CCP Australia, report the same clusters: MFA, endpoint detection, backups, patching, plus email security, training and incident response.

MFA gets the most attention. Insurers want it on remote access, email, admin accounts and cloud platforms. A yes that covers most users but not all is treated as a risk, not a pass.

What does each question mean, and what do you attach?

Each question has a plain meaning and a piece of proof. Use this table as your template.

QuestionWhat the insurer meansEvidence to attach
MFA on email and remote access?Every user, no exclusionsConditional Access policy list, plus sign-in report showing exceptions
MFA on admin accounts?No admin signs in with a password aloneAdmin role list matched to MFA registration report
Endpoint detection and response?More than antivirus, on every deviceDevice list from the tool, with coverage count against the device inventory
Backups, tested, offline or immutable?Ransomware cannot encrypt your only copyBackup job report and the date of the last restore test
Critical patches within 48 hours?Internet-facing systems get fixed fastPatch compliance report with dates
Staff security training?People are told what phishing looks likeCompletion report from the training tool
Incident response plan?Someone knows who to call at 2amThe plan, with a named contact list

The 48-hour figure matches the Essential Eight maturity model, where ASD expects critical or actively exploited vulnerabilities in internet-facing services to be fixed within 48 hours. Insurers increasingly echo it.

Why does a wrong answer matter more than a gap?

A gap is a risk the insurer can price. A wrong answer can put the claim in question. Under the Insurance Contracts Act 1984, an insured must disclose what is relevant to the insurer's decision, and the insurer's remedies depend on what was wrong and whether it was fraudulent. We are not lawyers, and your client's broker is the right person for the legal detail.

What an MSP can say with confidence: "yes, for everyone" must be true for everyone. A single admin account with no MFA turns a clean answer into a problem.

If you're a small business

Ask your IT provider three things before you sign: "Can you show me the evidence behind each yes?", "Which answers are only mostly true?" and "What is the plan and date to fix them?" Then read the form yourself. You sign it, not your IT provider.

If you're an MSP

Run this in October, not the week the form lands.

  1. Pull the client's last form and the broker's checklist.
  2. Collect the evidence for each question, with today's date on every file.
  3. Mark each answer true for all, true for most, or false.
  4. Fix the "most" answers first. They are cheap to fix and costly to leave.
  5. Send the client the answers and the evidence together, in one pack.

The pack is worth charging for. Clients are asking for it already. Our post on the evidence problem covers how to file it.

Worked example

A 20-person accounting firm has Microsoft 365, 22 laptops and a cloud backup. Its MSP checks the form in October. MFA is enforced for staff but two shared mailboxes and one old admin account are excluded, so "MFA on all accounts" is true for most. The MSP removes the exclusions or documents them, and runs the sign-in report again. It finds 21 of 22 laptops report to the endpoint tool and enrols the last one. The backup has not had a restore test, so it runs one and saves the log. In December the firm signs a form where every answer has a dated file behind it.

Where CYBERWHITE fits

CYBERWHITE scans a client's Microsoft 365 tenant and shows which controls are met, which are not and which need review, per control, with evidence. That covers the Microsoft 365 questions: MFA, Conditional Access, and device and patch settings. Backups, training and the incident response plan sit outside Microsoft 365, so they are recorded through attestation, and the product does not claim to verify them. It does not lower a premium or change what an insurer accepts. See the cyber insurance calculator, insurance readiness, MSP solutions or pricing. To see what an assessor or underwriter would still ask for, book a free proof check. We scan one tenant with you.

Your checklist

  • Get last year's form and the broker's current checklist.
  • Pull dated evidence for MFA, EDR, backups, patching and training.
  • Check MFA covers every user, admin account and shared mailbox.
  • Run a restore test and save the log.
  • Mark each answer true for all, most, or false.
  • Fix the "most" answers before December.
  • Send the client one pack: answers plus evidence.
  • Ask the broker which frameworks the underwriter accepts.

Sources

  • CCP Australia: cyber insurance questionnaire guidance
  • Australian Signals Directorate: Essential Eight Maturity Model, cyber.gov.au
  • Insurance Contracts Act 1984 (Cth), legislation.gov.au

Keep reading: The evidence problem and SMB1001 Certification in Australia: Bronze, Silver, Gold and Beyond

Frequently asked questions

What do cyber insurers ask on the proposal form?
Australian underwriters commonly ask about multi-factor authentication (MFA), endpoint detection and response, backups, patching, email security, staff training and incident response planning. MFA is usually the most scrutinised answer, and partial coverage is treated as a risk factor.
Who is responsible for the answers, the client or the MSP?
The client signs the form, so the client carries the duty to the insurer. Under the Insurance Contracts Act 1984, an insured must disclose matters relevant to the insurer's decision, and the insurer's remedies depend on what was wrong and whether it was fraud. The MSP's job is to give the client answers that are true and provable.
Should an MSP answer yes if a control is mostly in place?
No. Answer what is true today, for every user and device in scope, and note the gap with a date for fixing it. A yes that holds for most users but not all is the kind of answer that causes trouble at claim time.
What evidence should we keep for each answer?
A dated export or screenshot from the system itself, such as the Conditional Access policy list, the backup job and last restore test, and the patch compliance report. Save it with the date in the file name and keep it with the signed form.
Does Essential Eight or SMB1001 lower a premium?
Do not promise it. Both are useful frameworks for organising the controls insurers ask about, but insurer recognition varies by insurer. Ask the broker which frameworks the underwriter accepts before you sell it as a discount.

Ready to assess your compliance?

CYBERWHITE helps Australian businesses reach Essential 8 and SMB1001 audit-readiness faster. Start with our free 5-minute assessment.