Cyber Insurance Readiness Assessment
Cyber Insurance Readiness Assessment is a 1-week, $1,950 fixed-price engagement that maps your Microsoft 365 and Azure security controls to the questions cyber insurance carriers actually ask — MFA coverage, endpoint detection and response, backup resilience, logging and retention, security awareness training — and gives you three things: an evidence pack you can attach to a questionnaire, a truthful-attestation checklist flagging anything you cannot honestly answer 'yes' to today, and a prioritized gap-fix plan. We are IT engineers, not insurance brokers: we do not advise on coverage or promise premium outcomes. We do carry cyber insurance ourselves, and our insured status is verifiable on our insurer's live verification page.
What this engagement is
Cyber insurance questionnaires have teeth now. Carriers routinely require attestations on multi-factor authentication, endpoint detection and response, backups, and security training before they will bind or renew — and an application answered inaccurately is not a paperwork problem, it is a claims problem: misstatements can put coverage of the exact incident you bought the policy for at risk. Most SMBs fill these questionnaires in under renewal pressure, guessing at technical answers, and only discover the gap between what was attested and what was configured when it matters most. This assessment closes that gap from the technical side. We review your Microsoft 365 and Azure environment against the control areas common across carrier questionnaires: MFA coverage for users, administrators, and remote access; EDR presence and coverage across the fleet; backup existence, immutability, and restore evidence; logging and retention; awareness training; and unsupported-software exposure. For each area you get the actual state, the evidence to prove it, and — where the honest answer today is 'no' or 'partially' — a concrete, prioritized fix mapped to a specific remediation path, including our MFA implementation, managed detection and response, and managed backup services where those fit. Two boundaries, stated plainly because they matter: we are not insurance brokers, we do not advise on carriers, coverage, limits, or policy language, and we never promise that this work will reduce your premium — underwriting is the carrier's decision, not ours. What we change is your ability to answer every technical question accurately, with evidence attached. And we hold ourselves to the same standard we sell: IT Partner carries cyber insurance, completes these questionnaires for its own policy, and our insured status is published on our insurer's live third-party verification page — the same verification we show clients during onboarding.
Success criteria
What you receive
How the work unfolds
Confirm scope, obtain your current or most recent carrier questionnaire if available (we map to common carrier question areas if not), and set up least-privilege, time-bound access you approve.
Assess MFA coverage, EDR presence, backup resilience, logging and retention, awareness training status, and unsupported-software exposure across the Microsoft 365/Azure environment, capturing evidence as we go.
Organize dated evidence per control area and build the truthful-attestation checklist — including the items where the honest answer today is 'no' or 'partially', because those are the ones that protect you.
Prioritize gaps by attestation impact and remediation effort, map each to a concrete path, and walk leadership (and your broker, if invited) through the findings and the checklist.
Prerequisites
Who does what
IT Partner
- Review the mapped control areas against your actual configuration and capture dated evidence.
- Produce the control-to-questionnaire mapping, evidence pack, truthful-attestation checklist, and prioritized gap-fix plan.
- Deliver the readout to leadership and, if invited, your broker.
- Recommend concrete remediation paths without pressure toward our own services where another path fits better.
Your team
- Provide approved access and the questionnaire or renewal context.
- Make the relevant system owners available for evidence questions during the assessment week.
- Review the checklist and evidence pack before anything is submitted to a carrier.
- Own all interactions with your carrier and broker — including what is ultimately attested and submitted.
What's not included
Limitations & technical notes
Frequently asked questions
What is the Cyber Insurance Readiness Assessment?
A 1-week, fixed-price ($1,950) technical assessment that maps your Microsoft 365 and Azure security controls to the question areas cyber insurance carriers commonly require — MFA, EDR, backup, logging and retention, awareness training, unsupported software — and delivers an evidence pack, a truthful-attestation checklist, and a prioritized gap-fix plan.
Are you insurance brokers? Will you advise us on coverage?
No, and no. We are IT engineers. We do not advise on carriers, coverage, limits, or policy language, and we do not communicate with your carrier on your behalf — your broker and counsel own that side. What we own is the technical truth underneath your answers: what is actually configured, what evidence proves it, and what needs fixing.
Will this assessment lower our premium?
We never promise premium outcomes — underwriting is the carrier's decision, influenced by factors well beyond your control state, and any provider promising a premium result is overreaching. What this assessment changes is concrete: you answer every technical question accurately, attach evidence instead of assertions, and fix the gaps that commonly block or complicate binding. What the carrier does with that is the carrier's call.
Why does answering a questionnaire accurately matter so much?
Because the application becomes part of the insurance relationship. A misstatement — attesting MFA is enforced everywhere when service accounts or a legacy protocol are excluded, for example — can put coverage of the very incident you bought the policy for at risk. The truthful-attestation checklist exists so that nobody in your organization signs a technical claim the environment does not support.
Which control areas do you assess?
The areas that recur across carrier questionnaires: MFA coverage for users, admins, and remote access; endpoint detection and response presence and fleet coverage; backup existence, immutability, retention, and restore evidence; logging and retention; security awareness training status; and unsupported or end-of-life software exposure. If you provide your specific carrier's form, we map to it directly.
What is in the evidence pack?
Dated configuration exports and screenshots organized per control area — MFA enforcement reports, EDR coverage views, backup configuration and restore evidence, retention settings, training completion records where available. It is assembled so your leadership or broker can attach it to a questionnaire without needing us in the room.
What is the truthful-attestation checklist?
An item-by-item list of common attestation statements marked as: can attest today with evidence, can attest with noted exceptions, or cannot attest yet. It deliberately errs toward caution — an item with incomplete evidence is marked 'cannot attest yet', not rounded up. It is a technical-accuracy tool for your signing decision, not a legal opinion.
What happens when you find gaps — do we have to buy your remediation services?
No. Every gap gets a concrete recommendation and a path: something your team fixes in an afternoon, a third-party tool you already own, or a scoped engagement. Where an IT Partner service fits — MFA enforcement, managed detection and response, managed backup — we say so and quote it separately in writing. The assessment fee buys the honest picture either way, and there is no lock-in: the evidence pack and checklist are yours.
Do you fill in and submit the questionnaire for us?
We prepare the evidence and draft technical answers for your review, but you and your broker submit the application. Attestation is your signature and your relationship with the carrier — our job is making sure that what you sign is true.
Do you carry cyber insurance yourselves?
Yes. IT Partner carries cyber insurance, we complete these same questionnaires for our own policy, and our insured status is published on our insurer's live verification page — hosted by the insurer, not by us, so you can check it independently. We built this service the way we run our own renewals.
What access do you need, and how is it controlled?
We request granular, time-bound admin access (GDAP) that you approve — never standing global admin. For backup or EDR platforms outside Microsoft tooling, read access or exports are enough. Everything we capture goes into your evidence pack; access ends with the engagement.
Our renewal is close — can this fit before the deadline?
The assessment is scoped to one week precisely because renewals do not wait, and the readout can include your broker so findings translate directly into the application. Tell us your deadline when booking and we will confirm scheduling honestly before you commit — what we will not do is compress the work to the point where the checklist stops being truthful.
What is not included in the assessment?
Brokerage or coverage advice, premium promises, carrier communication on your behalf, remediation implementation, penetration testing, incident response, legal advice, and environments outside the agreed Microsoft 365/Azure scope. Each of those either belongs to your broker and counsel or is a separate, separately-quoted engagement.
How often should we re-run this?
Before each renewal, and after any major environment change — a merger, a new backup platform, an EDR switch. Configurations drift and carrier questions evolve; last year's evidence pack answers last year's questionnaire. Many clients pair the assessment with an annual security review cadence such as our SCuBA-based security audit.