The short version: cyber-insurance carriers now require MFA everywhere, endpoint detection on every device, tested and isolated backups, same-day offboarding, and an incident-response plan — and they require evidence, not checkboxes. Misstatements on the questionnaire are grounds for a denied claim when you need the policy most.
The controls carriers now expect
| Control | What underwriters actually ask | The gap we see most |
|---|---|---|
| MFA everywhere | “Is MFA enforced for all users, all remote access, and all admin accounts?” | The exceptions: legacy protocols, service accounts, that one executive who opted out |
| Endpoint detection (EDR) | “What percentage of endpoints run EDR, and who monitors the alerts?” | Coverage gaps on field laptops and unmanaged devices; alerts nobody reads |
| Backups — tested and isolated | “When was your last successful restore test? Are backups immutable or offline?” | Backups that run nightly and have never once been restored |
| Access lifecycle | “How quickly is access removed when someone leaves?” | Accounts that outlive employment by months |
| Email security | “What phishing and spoofing protections are configured?” | Defaults from three years ago, never revisited |
| Incident-response plan | “Who is notified, in what order, and where is it written down?” | A plan that exists only in the questionnaire answer |
Why this is an ownership problem
Every row above fails the same way: not for lack of tools, but because the control lives in the gap between the MSP, the security vendor, and “whoever set that up.” The questionnaire forces the question your operation should have answered already: who owns each control, and can they prove it works?
The 90-day path to a clean renewal
- Days 1–15: inventory reality — every account, device, backup job, and exception. The gaps list writes itself.
- Days 15–45: close the big four: MFA exceptions eliminated, EDR to full coverage, one restore test performed and documented, offboarding made same-day and automatic.
- Days 45–75: write the incident-response plan around named people, and run one tabletop walkthrough so it is real.
- Days 75–90: assemble the evidence pack — screenshots, reports, test records — so the questionnaire takes an afternoon instead of a scramble.
A renewal deadline is the most useful forcing function your security posture will ever get. Use it.