Cyber insurance & attestation
Answer the insurer with evidence from your own systems, not a best guess.
Your insurer asks about MFA, administrator access, endpoint protection and backup recovery. Gather evidence from the agreed systems, record gaps and identify which answers need further checking.
What this looks like in real life
A renewal questionnaire arrives with the policy already close to expiry. It asks, in plain yes-or-no boxes, whether every administrator uses phishing-resistant MFA, whether privileged access is time-bound, and whether backups have been test-restored. MFA went out to most people at some point and the rest was never finished, so nobody can answer from records. Ticking the wrong box puts a future claim at risk, and answering honestly can move the premium.
What was at risk
- A renewal answer nobody can stand behind at claim time.
- Global admin accounts with standing access and no documented MFA enforcement.
- A broker waiting on answers while the policy runs down.
The work that resolves it
the authentication and administrator-access controls the carrier asks about configured, piloted and enforced under tested policy, with the evidence assembled from the live tenant: the method inventory, the policy register and the test results, so the questionnaire is answered from production rather than from memory.
The relevant scope
Start with a defined piece of work
The scope, the price, and how you will know it is finished are agreed in writing before anyone is given access. Review the engagement below for its deliverables, responsibilities and acceptance criteria.
The engagement
MFA and Conditional Access Hardening
MFA and Conditional Access configured, piloted and enforced under tested policy, administrator access cleaned up, and the evidence carriers ask about assembled from the live tenant: the method inventory, the policy register, the test results and the exception register. Whether a carrier accepts the answers stays the carrier’s decision.
What you walk away with
What the evidence looks like
Result tested before handoff
Every change is checked against what was agreed before the work is signed off, by the one engineer who scoped it and ran it.
Changes in approved windows
Nothing changes until the scope is agreed in writing. Changes to live systems run in windows the business approves, with the way back agreed before the window opens.
Fixed scope
A defined deliverable and a written test for when it is finished, agreed before anything starts.
Not sure this is the one?
Describe what happened, in a paragraph. A reply comes within one business day with the most direct next step, or a clear answer that AZ Innovations is not the right fit.
Discuss the scope and quoteWhat happens next
- 1Describe what happenedA few short fields: company size, environment, and what is going wrong.
- 2A reply within one business dayThe most direct next step, or a clear answer that AZ Innovations is not the right fit.
- 3A fixed-fee proposalNamed scope, price, and how you will know it is finished. No obligation.