Cyber insurance compliance: the evidence your insurer wants
Cyber insurance used to be a form you filled in. Now it is a set of declarations about how your business is actually run — and the insurer will look at them again if you ever claim.
Quick answer: IT Live is a New Zealand managed service provider, certified to SMB1001 Gold against 27 independently assessed controls, that gets businesses to the point where every answer on a cyber insurance proposal form can be evidenced with a report rather than an opinion.
What does a cyber insurance proposal form actually ask?
New Zealand cyber insurance proposal forms ask about seven things: multi-factor authentication, tested backups, endpoint detection and response, patching cadence, administrator rights, staff phishing training, and a written incident response plan. The wording differs between insurers, but IT Live sees the same seven areas on almost every form.
| What the form asks | What they mean by it | What the evidence looks like |
|---|---|---|
| Do you enforce multi-factor authentication? | Every account with email or remote access – not just the directors. | An MFA or conditional access report out of your Microsoft 365 tenant showing coverage across all users. |
| Are your backups tested? | Backed up, held separately from the live system, and restored from at least once. | A restore log – what was restored, when, by whom, and whether the data came back. |
| Do you have endpoint detection and response? | EDR – detection plus someone actually acting on the alerts. Plain antivirus is no longer the answer. | The product name, the number of devices covered, and who is watching it around the clock. |
| How quickly do you patch? | A defined cadence applied to everything, not just the machines somebody remembered. | A patch compliance report across the whole fleet, over time. |
| Who holds administrator rights? | Admin accounts should be few, named, and separate from the account someone reads email on. | An access review – the list of privileged accounts and the date it was last checked. |
| Do you train staff on phishing? | Regular awareness training, not one slide in the induction pack three years ago. | Completion records, plus simulation results if you run them. |
| Do you have an incident response plan? | A written plan naming who does what, who gets called, and in what order. | The document itself, with a date on it and the right phone numbers in it. |
What happens if you tick yes without the evidence?
The claim gets difficult, and it is the most expensive mistake IT Live sees on these forms. A proposal form is a declaration: you are telling the insurer how the business runs, and they underwrite on the strength of it.
The problem shows up at claim time. When something happens the insurer investigates, and the investigation includes whether the controls you declared were actually in place on the day. If you said MFA was enforced everywhere and the compromised account didn’t have it, the claim gets difficult. Insurers can reduce or decline on that basis – and cover you can’t claim on is money spent for nothing.
Most people aren’t lying. They tick yes because they believe MFA is on, or that the backups get tested, because someone said so a few years back. Nobody has looked since.
So the honest answer to the form isn’t always “yes”. It’s “yes, and here is the report”.
How does SMB1001 Gold map to the insurer's questions?
Almost one-for-one. SMB1001 is an independent cyber security standard built for small and medium business, and Gold means 27 specific controls have been assessed and certified by an outside body rather than self-declared by you – which is the same ground a cyber insurance proposal form covers.
Read down those 27 controls and the overlap is obvious – multi-factor authentication, email security, patching, backup and restore testing, access control and reviews, staff awareness, incident response, an asset inventory. SMB1001 was built for the same problem the insurer is underwriting.
That matters twice over. The work of getting to Gold is the work of being able to answer the form honestly. And the certificate is assessed by someone independent, which is a different thing from your own tick in a box.
IT Live is SMB1001 Gold certified itself, and takes the businesses it manages through the same 27 controls. Evidence is what insurers are asking for. Once you are certified, IT Live introduces you to an insurance broker who has arranged a cyber insurance discount for SMB1001 certified businesses – though your own premium will still depend on your insurer’s view of your risk.
How does Microsoft Secure Score prove the controls stayed on?
Because it keeps moving. Certification is a point in time; Microsoft Secure Score is a live number, and IT Live uses it as the ongoing evidence that the controls declared on the form were still on months later.
Secure Score is Microsoft’s own measure of how well a Microsoft 365 tenant is locked down – MFA coverage, admin account protection, mail flow rules, device policy, the lot. It shifts when your configuration shifts, so it shows whether the controls stayed on after the audit was signed off.
IT Live holds every managed client above 70% and keeps them there. If you don’t know your own score, that is the quickest place to start – ask IT Live and the team will show you how to check it in three clicks.
How does IT Live get a business to a state it can evidence?
In four steps, and the gap between where most businesses sit and where the form wants them is usually smaller than it feels. The order IT Live works in:
- Find out what is actually true. IT Live audits the Microsoft 365 tenant, the devices, the backups and the admin accounts, then puts the real answers next to the questions.
- Close the obvious gaps. MFA on everyone, patching brought current, dead admin accounts removed, backup turned on and a restore genuinely tested.
- Make the evidence repeatable. Reports that produce themselves, rather than a scramble the week before renewal.
- Go for certification if you want the certificate in your own name.
Not sure where you sit? The IT Live free 2-minute cyber readiness check gives you a rough read against SMB1001. From there, security and protection covers the tooling, and managed IT support covers who keeps it running.
Frequently asked questions
What does a cyber insurance proposal form ask for?
Typically multi-factor authentication on email and remote access, backups that are tested and held separately, endpoint detection and response with someone monitoring it, a patching cadence, control over who holds administrator rights, staff awareness training, and a written incident response plan.
What happens if I answer yes and it turns out not to be true?
You are making a declaration. If a claim is investigated and the control you declared was not actually in place, the insurer can reduce or decline the claim. The policy is only worth what you can evidence.
Does SMB1001 Gold certification help with cyber insurance?
It gives you independently assessed evidence across 27 controls, which lines up closely with what proposal forms ask about – MFA, backups, patching, access control and incident response. IT Live introduces certified clients to an insurance broker who has arranged a cyber insurance discount for SMB1001 certified businesses; your final premium still depends on your insurer’s own criteria.
What counts as evidence of a tested backup?
A restore somebody actually performed and wrote down: what was restored, when, by whom, and whether it worked. A green tick on a dashboard says the job ran, it does not prove the data comes back.
How do I show my patching is up to date?
With a report from the tool that does the patching, showing compliance across your fleet over time. IT Live runs NinjaOne for that, alongside Microsoft Secure Score as the ongoing measure of how locked down the Microsoft 365 tenant is.
Want to know what you could evidence today?
IT Live will audit your Microsoft 365 tenant, devices, backups and admin accounts and give you the real answers to every question on the form – the ones you can evidence, and the ones you can’t yet. That is the IT Live fixed-fee cyber security audit, and if IT Live already manages your IT it costs you nothing. Not ready for that? Start with the free cyber readiness check – two minutes, no cost, no sales call.
Email info@itlive.co.nz, or get in touch here.