The short version: Cyber insurance renewal season runs from December to February, and the questionnaire arrives with a deadline. Your client signs it, so your job is to make every answer true and provable. Pull the evidence for MFA, backups, patching, endpoint protection and training in October, while there is time to fix a gap instead of explaining it.
What do cyber insurers ask?
They ask the same handful of questions in different words. Australian brokers and MSPs describing 2026 proposal forms, such as CCP Australia, report the same clusters: MFA, endpoint detection, backups, patching, plus email security, training and incident response.
MFA gets the most attention. Insurers want it on remote access, email, admin accounts and cloud platforms. A yes that covers most users but not all is treated as a risk, not a pass.
What does each question mean, and what do you attach?
Each question has a plain meaning and a piece of proof. Use this table as your template.
| Question | What the insurer means | Evidence to attach |
|---|---|---|
| MFA on email and remote access? | Every user, no exclusions | Conditional Access policy list, plus sign-in report showing exceptions |
| MFA on admin accounts? | No admin signs in with a password alone | Admin role list matched to MFA registration report |
| Endpoint detection and response? | More than antivirus, on every device | Device list from the tool, with coverage count against the device inventory |
| Backups, tested, offline or immutable? | Ransomware cannot encrypt your only copy | Backup job report and the date of the last restore test |
| Critical patches within 48 hours? | Internet-facing systems get fixed fast | Patch compliance report with dates |
| Staff security training? | People are told what phishing looks like | Completion report from the training tool |
| Incident response plan? | Someone knows who to call at 2am | The plan, with a named contact list |
The 48-hour figure matches the Essential Eight maturity model, where ASD expects critical or actively exploited vulnerabilities in internet-facing services to be fixed within 48 hours. Insurers increasingly echo it.
Why does a wrong answer matter more than a gap?
A gap is a risk the insurer can price. A wrong answer can put the claim in question. Under the Insurance Contracts Act 1984, an insured must disclose what is relevant to the insurer's decision, and the insurer's remedies depend on what was wrong and whether it was fraudulent. We are not lawyers, and your client's broker is the right person for the legal detail.
What an MSP can say with confidence: "yes, for everyone" must be true for everyone. A single admin account with no MFA turns a clean answer into a problem.
If you're a small business
Ask your IT provider three things before you sign: "Can you show me the evidence behind each yes?", "Which answers are only mostly true?" and "What is the plan and date to fix them?" Then read the form yourself. You sign it, not your IT provider.
If you're an MSP
Run this in October, not the week the form lands.
- Pull the client's last form and the broker's checklist.
- Collect the evidence for each question, with today's date on every file.
- Mark each answer true for all, true for most, or false.
- Fix the "most" answers first. They are cheap to fix and costly to leave.
- Send the client the answers and the evidence together, in one pack.
The pack is worth charging for. Clients are asking for it already. Our post on the evidence problem covers how to file it.
Worked example
A 20-person accounting firm has Microsoft 365, 22 laptops and a cloud backup. Its MSP checks the form in October. MFA is enforced for staff but two shared mailboxes and one old admin account are excluded, so "MFA on all accounts" is true for most. The MSP removes the exclusions or documents them, and runs the sign-in report again. It finds 21 of 22 laptops report to the endpoint tool and enrols the last one. The backup has not had a restore test, so it runs one and saves the log. In December the firm signs a form where every answer has a dated file behind it.
Where CYBERWHITE fits
CYBERWHITE scans a client's Microsoft 365 tenant and shows which controls are met, which are not and which need review, per control, with evidence. That covers the Microsoft 365 questions: MFA, Conditional Access, and device and patch settings. Backups, training and the incident response plan sit outside Microsoft 365, so they are recorded through attestation, and the product does not claim to verify them. It does not lower a premium or change what an insurer accepts. See the cyber insurance calculator, insurance readiness, MSP solutions or pricing. To see what an assessor or underwriter would still ask for, book a free proof check. We scan one tenant with you.
Your checklist
- Get last year's form and the broker's current checklist.
- Pull dated evidence for MFA, EDR, backups, patching and training.
- Check MFA covers every user, admin account and shared mailbox.
- Run a restore test and save the log.
- Mark each answer true for all, most, or false.
- Fix the "most" answers before December.
- Send the client one pack: answers plus evidence.
- Ask the broker which frameworks the underwriter accepts.
Sources
- CCP Australia: cyber insurance questionnaire guidance
- Australian Signals Directorate: Essential Eight Maturity Model, cyber.gov.au
- Insurance Contracts Act 1984 (Cth), legislation.gov.au
Keep reading: The evidence problem and SMB1001 Certification in Australia: Bronze, Silver, Gold and Beyond