Cyber-Insurance Evidence Guide

How smaller businesses can answer common carrier questions honestly and keep reusable proof for renewals, customer reviews, and owner decisions.

Important: this guide helps you organize evidence. It does not guarantee policy approval, premium changes, or claim outcomes. Your carrier and broker make those decisions.

What carriers commonly ask for

Control areaPlain-English questionUseful evidence
Multi-factor authenticationIs MFA enforced for email, remote access, and admins?MFA policy screenshot, user coverage export, exception list.
Endpoint protectionAre business devices protected and monitored?Device coverage report, alert history, unmanaged-device list.
BackupsCan you recover from ransomware or accidental deletion?Backup job report, restore-test notes, recovery priority list.
Email protectionDo you reduce phishing and spoofing risk?SPF/DKIM/DMARC status, mailbox rule review, awareness evidence.
Access managementDo you remove access when people leave?Onboarding/offboarding checklist, admin access review.
Incident responseDo you know what happens in the first day of an incident?Incident contact list, ransomware/account-compromise playbooks.

How to answer without overclaiming

Evidence folder structure

Create a simple folder for each renewal or questionnaire. Keep the most reusable proof at the top so you do not rebuild the packet every year.

30-day evidence sprint

  1. Day 1–3: gather current questionnaire, policy, and renewal deadline.
  2. Day 4–10: export MFA, endpoint, backup, and admin-access evidence.
  3. Day 11–17: validate restore evidence and email-domain posture.
  4. Day 18–24: document exceptions and create a remediation roadmap.
  5. Day 25–30: review with the business owner before sending anything externally.
Do not wait until renewal week. Insurance questions often expose gaps that take time to fix. Treat the questionnaire as an evidence-readiness drill, not a paperwork exercise.