Cyber insurance compliance: the evidence your insurer wants
Cyber insurance used to be a form you filled in. Now it is a set of declarations about how your business is actually run – and the insurer will look at them again if you ever claim. Here is what New Zealand proposal forms ask, what each question really means, and the evidence you need to be able to produce.
What a cyber insurance proposal form actually asks
The wording differs between insurers, but the ground covered is remarkably consistent.
| What the form asks | What they mean by it | What the evidence looks like |
|---|---|---|
| Do you enforce multi-factor authentication? | Every account with email or remote access – not just the directors. | An MFA or conditional access report out of your Microsoft 365 tenant showing coverage across all users. |
| Are your backups tested? | Backed up, held separately from the live system, and restored from at least once. | A restore log – what was restored, when, by whom, and whether the data came back. |
| Do you have endpoint detection and response? | EDR – detection plus someone actually acting on the alerts. Plain antivirus is no longer the answer. | The product name, the number of devices covered, and who is watching it around the clock. |
| How quickly do you patch? | A defined cadence applied to everything, not just the machines somebody remembered. | A patch compliance report across the whole fleet, over time. |
| Who holds administrator rights? | Admin accounts should be few, named, and separate from the account someone reads email on. | An access review – the list of privileged accounts and the date it was last checked. |
| Do you train staff on phishing? | Regular awareness training, not one slide in the induction pack three years ago. | Completion records, plus simulation results if you run them. |
| Do you have an incident response plan? | A written plan naming who does what, who gets called, and in what order. | The document itself, with a date on it and the right phone numbers in it. |
Ticking yes without evidence is the expensive mistake
A proposal form is a declaration. You are telling the insurer how the business runs, and they underwrite on the strength of it.
The problem shows up at claim time. When something happens the insurer investigates, and the investigation includes whether the controls you declared were actually in place on the day. If you said MFA was enforced everywhere and the compromised account didn’t have it, the claim gets difficult. Insurers can reduce or decline on that basis – and cover you can’t claim on is money spent for nothing.
Most people aren’t lying. They tick yes because they believe MFA is on, or that the backups get tested, because someone said so a few years back. Nobody has looked since.
So the honest answer to the form isn’t always “yes”. It’s “yes, and here is the report”.
How SMB1001 Gold maps to the questions
SMB1001 is an independent cyber security standard built for small and medium business. Gold means 27 specific controls have been assessed and certified by an outside body, rather than self-declared by you.
Read down those 27 and you will see the same ground the proposal form covers – multi-factor authentication, email security, patching, backup and restore testing, access control and reviews, staff awareness, incident response, an asset inventory. It was built for the same problem.
That matters twice over. The work of getting to Gold is the work of being able to answer the form honestly. And the certificate is assessed by someone independent, which is a different thing from your own tick in a box.
We are SMB1001 Gold certified ourselves. What any of this does to your premium is a conversation for your broker or insurer – they price on their own criteria and their own view of your risk. Evidence is simply what they are asking for.
Secure Score is your ongoing evidence
Certification is a point in time. Microsoft Secure Score is the number that keeps moving.
Secure Score is Microsoft’s own measure of how well a Microsoft 365 tenant is locked down – MFA coverage, admin account protection, mail flow rules, device policy, the lot. It shifts when your configuration shifts, so it shows whether the controls stayed on after the audit was signed off.
We hold every managed client above 70% and keep them there. If you don’t know your own score, that is the quickest place to start – ask us and we will show you how to check it in three clicks.
Getting to a state you can evidence
The gap between where most businesses sit and where the form wants them is usually smaller than it feels. The order we work in:
- Find out what is actually true. We audit the tenant, the devices, the backups and the admin accounts, then put the real answers next to the questions.
- Close the obvious gaps. MFA on everyone, patching brought current, dead admin accounts removed, backup turned on and a restore genuinely tested.
- Make the evidence repeatable. Reports that produce themselves, rather than a scramble the week before renewal.
- Go for certification if you want the certificate in your own name.
Not sure where you sit? Our free 2-minute cyber readiness check gives you a rough read against SMB1001. From there, security and protection covers the tooling, and managed IT support covers who keeps it running.
Frequently asked questions
What does a cyber insurance proposal form ask for?
Typically multi-factor authentication on email and remote access, backups that are tested and held separately, endpoint detection and response with someone monitoring it, a patching cadence, control over who holds administrator rights, staff awareness training, and a written incident response plan.
What happens if I answer yes and it turns out not to be true?
You are making a declaration. If a claim is investigated and the control you declared was not actually in place, the insurer can reduce or decline the claim. The policy is only worth what you can evidence.
Does SMB1001 Gold certification help with cyber insurance?
It gives you independently assessed evidence across 27 controls, which lines up closely with what proposal forms ask about – MFA, backups, patching, access control and incident response. What it does to your premium is a question for your broker or insurer; they price on their own criteria.
What counts as evidence of a tested backup?
A restore somebody actually performed and wrote down: what was restored, when, by whom, and whether it worked. A green tick on a dashboard says the job ran, it does not prove the data comes back.
How do I show my patching is up to date?
With a report from the tool that does the patching, showing compliance across your fleet over time. We run NinjaOne for that, alongside Microsoft Secure Score as the ongoing measure of how locked down the Microsoft 365 tenant is.
Want to know what you could evidence today?
We’ll audit your Microsoft 365 tenant, devices, backups and admin accounts and give you the real answers to every question on the form – the ones you can evidence, and the ones you can’t yet. It costs nothing and the report is yours to keep either way.
Email info@itlive.co.nz, or get in touch here.