First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Cyber Insurance Readiness Assessment
AssessmentSecurity and Protection

Cyber Insurance Readiness Assessment

Cyber Insurance Readiness Assessment is a 1-week, $1,950 fixed-price engagement that maps your Microsoft 365 and Azure security controls to the questions cyber insurance carriers actually ask — MFA coverage, endpoint detection and response, backup resilience, logging and retention, security awareness training — and gives you three things: an evidence pack you can attach to a questionnaire, a truthful-attestation checklist flagging anything you cannot honestly answer 'yes' to today, and a prioritized gap-fix plan. We are IT engineers, not insurance brokers: we do not advise on coverage or promise premium outcomes. We do carry cyber insurance ourselves, and our insured status is verifiable on our insurer's live verification page.

Timeline 1 weekService owner Dan ApplebyMicrosoft 365AzureMicrosoft Defender

What this engagement is

Cyber insurance questionnaires have teeth now. Carriers routinely require attestations on multi-factor authentication, endpoint detection and response, backups, and security training before they will bind or renew — and an application answered inaccurately is not a paperwork problem, it is a claims problem: misstatements can put coverage of the exact incident you bought the policy for at risk. Most SMBs fill these questionnaires in under renewal pressure, guessing at technical answers, and only discover the gap between what was attested and what was configured when it matters most. This assessment closes that gap from the technical side. We review your Microsoft 365 and Azure environment against the control areas common across carrier questionnaires: MFA coverage for users, administrators, and remote access; EDR presence and coverage across the fleet; backup existence, immutability, and restore evidence; logging and retention; awareness training; and unsupported-software exposure. For each area you get the actual state, the evidence to prove it, and — where the honest answer today is 'no' or 'partially' — a concrete, prioritized fix mapped to a specific remediation path, including our MFA implementation, managed detection and response, and managed backup services where those fit. Two boundaries, stated plainly because they matter: we are not insurance brokers, we do not advise on carriers, coverage, limits, or policy language, and we never promise that this work will reduce your premium — underwriting is the carrier's decision, not ours. What we change is your ability to answer every technical question accurately, with evidence attached. And we hold ourselves to the same standard we sell: IT Partner carries cyber insurance, completes these questionnaires for its own policy, and our insured status is published on our insurer's live third-party verification page — the same verification we show clients during onboarding.

Success criteria

01Every mapped questionnaire control area has a documented actual state with supporting evidence.
02You hold a truthful-attestation checklist identifying exactly which items you can answer 'yes' to today and which you cannot.
03Each gap has a prioritized, concrete remediation recommendation with an identified path (in-house, IT Partner service, or third party).
04The evidence pack is organized so your leadership or broker can attach it to a questionnaire without translation.
05Leadership understands the difference between what is configured and what has been attested, before signing anything.

What you receive

Control-to-questionnaire mapping: the common carrier question areas mapped to your actual Microsoft 365/Azure configuration state.
MFA coverage review: enforcement across all users, administrative accounts, and remote access paths, with exceptions enumerated — not averaged away.
EDR review: endpoint detection and response presence and fleet coverage, including unmanaged-device blind spots.
Backup resilience review: what is backed up, immutability/offline characteristics, retention, and whether restores have evidence behind them.
Logging and retention review against common carrier expectations, plus an unsupported-software exposure check (end-of-life operating systems are a questionnaire item — and a real one).
Security awareness training status review.
Evidence pack: organized configuration exports and screenshots per control area, dated, ready to attach to a questionnaire.
Truthful-attestation checklist: item-by-item, what you can honestly attest today and what you cannot yet.
Prioritized gap-fix plan with concrete remediation paths, and a readout call with your leadership and, if you wish, your broker on the line.

How the work unfolds

1. Kickoff and questionnaire alignment

Confirm scope, obtain your current or most recent carrier questionnaire if available (we map to common carrier question areas if not), and set up least-privilege, time-bound access you approve.

2. Technical control review

Assess MFA coverage, EDR presence, backup resilience, logging and retention, awareness training status, and unsupported-software exposure across the Microsoft 365/Azure environment, capturing evidence as we go.

3. Evidence pack and attestation checklist assembly

Organize dated evidence per control area and build the truthful-attestation checklist — including the items where the honest answer today is 'no' or 'partially', because those are the ones that protect you.

4. Gap-fix plan and readout

Prioritize gaps by attestation impact and remediation effort, map each to a concrete path, and walk leadership (and your broker, if invited) through the findings and the checklist.

Prerequisites

Administrative or read-oriented access to your Microsoft 365 tenant and relevant Azure subscriptions — we request granular, time-bound GDAP access that you approve, never standing global admin.
Your current or upcoming carrier questionnaire, if available (the assessment maps to common carrier question areas when no specific form exists yet).
A named point of contact and availability of whoever manages backups, endpoints, and training records for short evidence questions.
Access to backup and EDR consoles if those run outside Microsoft tooling, or exports from them.

Who does what

IT Partner

  • Review the mapped control areas against your actual configuration and capture dated evidence.
  • Produce the control-to-questionnaire mapping, evidence pack, truthful-attestation checklist, and prioritized gap-fix plan.
  • Deliver the readout to leadership and, if invited, your broker.
  • Recommend concrete remediation paths without pressure toward our own services where another path fits better.

Your team

  • Provide approved access and the questionnaire or renewal context.
  • Make the relevant system owners available for evidence questions during the assessment week.
  • Review the checklist and evidence pack before anything is submitted to a carrier.
  • Own all interactions with your carrier and broker — including what is ultimately attested and submitted.

What's not included

Insurance brokerage, carrier selection, coverage or limits advice, policy-language interpretation, or premium negotiation — we are not brokers or agents, and your broker and counsel own those questions.
Any promise of insurability, policy approval, renewal, or premium reduction — underwriting decisions belong to the carrier.
Submitting the questionnaire or communicating with your carrier on your behalf — we prepare the technical evidence and draft technical answers for your review; you and your broker submit.
Remediation implementation — the gap-fix plan maps each item to a path, and fixes such as MFA enforcement, managed detection and response, or managed backup are separate, separately-quoted engagements.
Penetration testing, vulnerability scanning, or incident response.
Assessment of environments outside the agreed Microsoft 365/Azure scope (non-Microsoft infrastructure can be included by prior agreement where evidence is exportable).
Legal advice of any kind, including on attestation liability — the checklist is a technical-accuracy tool, not a legal opinion.

Limitations & technical notes

!Carrier questionnaires differ; we map to the control areas common across carriers and to your specific form when you provide it. A carrier can always ask something outside the mapped set.
!The assessment reflects your environment during the assessment week. Configurations drift; carriers ask at renewal time. Re-assessment before each renewal is the honest cadence.
!Findings depend on the access and evidence available during the week; systems we cannot see are marked as unverified on the checklist rather than assumed.
!The truthful-attestation checklist deliberately errs toward 'cannot attest yet' when evidence is incomplete — an uncomfortable checklist is doing its job.
!This engagement covers technical readiness only. Whether to attest, what to disclose, and how to answer any question ultimately remain decisions for you, your broker, and your counsel.

Frequently asked questions

What is the Cyber Insurance Readiness Assessment?

A 1-week, fixed-price ($1,950) technical assessment that maps your Microsoft 365 and Azure security controls to the question areas cyber insurance carriers commonly require — MFA, EDR, backup, logging and retention, awareness training, unsupported software — and delivers an evidence pack, a truthful-attestation checklist, and a prioritized gap-fix plan.

Are you insurance brokers? Will you advise us on coverage?

No, and no. We are IT engineers. We do not advise on carriers, coverage, limits, or policy language, and we do not communicate with your carrier on your behalf — your broker and counsel own that side. What we own is the technical truth underneath your answers: what is actually configured, what evidence proves it, and what needs fixing.

Will this assessment lower our premium?

We never promise premium outcomes — underwriting is the carrier's decision, influenced by factors well beyond your control state, and any provider promising a premium result is overreaching. What this assessment changes is concrete: you answer every technical question accurately, attach evidence instead of assertions, and fix the gaps that commonly block or complicate binding. What the carrier does with that is the carrier's call.

Why does answering a questionnaire accurately matter so much?

Because the application becomes part of the insurance relationship. A misstatement — attesting MFA is enforced everywhere when service accounts or a legacy protocol are excluded, for example — can put coverage of the very incident you bought the policy for at risk. The truthful-attestation checklist exists so that nobody in your organization signs a technical claim the environment does not support.

Which control areas do you assess?

The areas that recur across carrier questionnaires: MFA coverage for users, admins, and remote access; endpoint detection and response presence and fleet coverage; backup existence, immutability, retention, and restore evidence; logging and retention; security awareness training status; and unsupported or end-of-life software exposure. If you provide your specific carrier's form, we map to it directly.

What is in the evidence pack?

Dated configuration exports and screenshots organized per control area — MFA enforcement reports, EDR coverage views, backup configuration and restore evidence, retention settings, training completion records where available. It is assembled so your leadership or broker can attach it to a questionnaire without needing us in the room.

What is the truthful-attestation checklist?

An item-by-item list of common attestation statements marked as: can attest today with evidence, can attest with noted exceptions, or cannot attest yet. It deliberately errs toward caution — an item with incomplete evidence is marked 'cannot attest yet', not rounded up. It is a technical-accuracy tool for your signing decision, not a legal opinion.

What happens when you find gaps — do we have to buy your remediation services?

No. Every gap gets a concrete recommendation and a path: something your team fixes in an afternoon, a third-party tool you already own, or a scoped engagement. Where an IT Partner service fits — MFA enforcement, managed detection and response, managed backup — we say so and quote it separately in writing. The assessment fee buys the honest picture either way, and there is no lock-in: the evidence pack and checklist are yours.

Do you fill in and submit the questionnaire for us?

We prepare the evidence and draft technical answers for your review, but you and your broker submit the application. Attestation is your signature and your relationship with the carrier — our job is making sure that what you sign is true.

Do you carry cyber insurance yourselves?

Yes. IT Partner carries cyber insurance, we complete these same questionnaires for our own policy, and our insured status is published on our insurer's live verification page — hosted by the insurer, not by us, so you can check it independently. We built this service the way we run our own renewals.

What access do you need, and how is it controlled?

We request granular, time-bound admin access (GDAP) that you approve — never standing global admin. For backup or EDR platforms outside Microsoft tooling, read access or exports are enough. Everything we capture goes into your evidence pack; access ends with the engagement.

Our renewal is close — can this fit before the deadline?

The assessment is scoped to one week precisely because renewals do not wait, and the readout can include your broker so findings translate directly into the application. Tell us your deadline when booking and we will confirm scheduling honestly before you commit — what we will not do is compress the work to the point where the checklist stops being truthful.

What is not included in the assessment?

Brokerage or coverage advice, premium promises, carrier communication on your behalf, remediation implementation, penetration testing, incident response, legal advice, and environments outside the agreed Microsoft 365/Azure scope. Each of those either belongs to your broker and counsel or is a separate, separately-quoted engagement.

How often should we re-run this?

Before each renewal, and after any major environment change — a merger, a new backup platform, an EDR switch. Configurations drift and carrier questions evolve; last year's evidence pack answers last year's questionnaire. Many clients pair the assessment with an annual security review cadence such as our SCuBA-based security audit.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,950 per project
1 week
Book the assessment