What Evidence Do Cyber Insurers Expect for MFA, EDR and Backups?

If your cyber insurance application asks whether you have MFA, EDR or protected backups, simply knowing that you purchased those technologies may not be enough to answer confidently.

You may also need to establish where the control is implemented, what it protects, whether there are exceptions, who manages it, and what evidence supports your answer.

The exact evidence requested varies by insurer and application. But screenshots, configuration reports, system inventories, security-console reports, backup records and restore-test documentation can all help establish what is actually in place.

Why Evidence Matters on a Cyber Insurance Application

Cyber insurance questionnaires frequently ask businesses to make specific statements about cybersecurity controls.

For example:

  • Is multi-factor authentication required?
  • Is Endpoint Detection and Response deployed?
  • Are backups protected from ransomware?
  • Are backups tested?
  • Are privileged accounts protected?
  • Are remote users required to use MFA?

These may look like simple Yes/No questions.

Operationally, they often aren’t.

A business might have MFA enabled for Microsoft 365 but not for another critical application.

EDR might protect employee laptops but not every server.

Backups might run every night but never have been tested through an actual restoration.

The important question therefore becomes:

What can you demonstrate about the control you’re being asked about?

What Evidence Can Support an MFA Answer?

Multi-factor authentication is one of the most common controls addressed in cyber insurance applications.

But saying “we use MFA” doesn’t necessarily describe its full scope.

You may need to determine whether MFA applies to:

  • Email
  • Remote network access
  • Administrator accounts
  • Privileged users
  • Cloud applications
  • Critical business applications
  • Backup administration
  • Third-party or vendor access

Examples of MFA Evidence

Depending on your environment, useful evidence might include:

  • Identity-provider configuration screenshots
  • Conditional-access policies
  • MFA enrollment or coverage reports
  • User or account inventories
  • Administrator-account configuration
  • Remote-access or VPN configuration
  • Reports showing which users are subject to MFA
  • Documentation identifying approved exceptions

The objective isn’t simply to prove that an MFA product exists.

It’s to understand where MFA is actually enforced.

“Available” MFA Is Not Necessarily “Required” MFA

This distinction is important.

A system may support MFA without requiring every relevant user to use it.

For example, Microsoft 365 may support MFA, but that alone doesn’t establish:

  • Whether MFA is enforced
  • Which users are covered
  • Whether administrators are covered
  • Whether exceptions exist
  • Whether legacy authentication creates another path
  • Whether other important applications use MFA

When reviewing a cyber insurance question, look closely at words such as:

required, enforced, all, remote, privileged, administrative, critical, and access.

Those words can materially change what needs to be verified.

What Evidence Can Support an EDR Answer?

Endpoint Detection and Response, or EDR, is another control frequently addressed during cyber insurance underwriting.

One common problem is terminology.

A business may say:

“Yes, we have antivirus.”

But the application may specifically ask about:

EDR, MDR or another endpoint detection capability.

Those aren’t automatically interchangeable terms.

Before answering, determine exactly what endpoint security technology is deployed.

Examples of EDR Evidence

Useful evidence may include:

  • EDR management-console reports
  • Endpoint inventories
  • Agent deployment reports
  • Device coverage reports
  • Product and vendor identification
  • Agent status or last-check-in information
  • Reports identifying unmanaged or inactive devices
  • Monitoring or alerting documentation
  • MSP or security-provider service descriptions

A strong evidence set helps answer two different questions:

What endpoint security technology do we have?

and

Which endpoints does it actually protect?

Look for the EDR Coverage Gap

Suppose your company has 75 computers and servers.

Your EDR console shows 71 active agents.

That doesn’t automatically tell you whether the correct answer to a particular insurance question is Yes or No.

It tells you that you have four systems that need investigation.

Perhaps they were retired.

Perhaps they are newly deployed.

Perhaps another provider manages them.

Or perhaps they are active systems that aren’t protected.

That’s why comparing an EDR deployment report with a current asset inventory can be valuable.

You’re looking for the difference between:

what should be protected

and

what is actually protected.

What Evidence Can Support a Backup Answer?

Backups deserve particular attention because a successful backup job and a recoverable system aren’t necessarily the same thing.

A cyber insurance application may ask about:

  • Backup frequency
  • Backup location
  • Offline backups
  • Air-gapped backups
  • Immutable backups
  • Segmentation of backup systems
  • Separate credentials
  • MFA protecting backup administration
  • Geographic separation
  • Recovery testing

The exact questions vary by insurer.

Examples of Backup Evidence

Useful backup evidence might include:

  • Backup configuration reports
  • Backup-job histories
  • Successful and failed job reports
  • Retention settings
  • Storage-location documentation
  • Immutability configuration
  • Offline-copy documentation
  • Backup administrator access settings
  • MFA configuration for backup systems
  • Restore-test records
  • Recovery-test results

Again, the objective isn’t to collect screenshots for the sake of collecting screenshots.

It’s to establish whether the backup environment actually operates the way management believes it does.

“The Backup Ran Successfully” Is Not the Same as “We Tested Recovery”

This distinction can become important during a renewal.

A backup dashboard might show:

Backup completed successfully — 2:03 AM

That’s useful evidence that a backup job completed.

But it doesn’t necessarily establish that the organization has successfully restored systems or data from those backups.

If the application asks whether backups are tested, determine what kind of testing is actually being performed.

Ask:

  • When was the last restore test?
  • What was restored?
  • Was the restoration successful?
  • Who performed the test?
  • Is the result documented?
  • Were problems discovered?
  • Were those problems corrected?

If nobody knows the answer, that’s something to resolve before making an assumption on the application.

Your Evidence Should Match the Question

Avoid collecting a large folder of cybersecurity documents without first understanding the question you’re trying to support.

If the application asks whether MFA protects remote access, a general cybersecurity policy saying the company “uses MFA” may not establish that fact.

If it asks whether EDR covers all endpoints, an invoice showing that you purchased an EDR product may not establish deployment coverage.

If it asks whether backups are immutable, a report showing successful nightly backups may not establish immutability.

The evidence should support the specific representation being made.

What If the Evidence Doesn’t Match What You Thought?

This is where the evidence-gathering process becomes especially valuable.

You may discover:

  • MFA isn’t enforced for every relevant account
  • Several endpoints don’t have an active EDR agent
  • A server is managed by another provider
  • Backup administration doesn’t use MFA
  • Backups are successful but restore testing hasn’t been documented
  • Management thought the MSP handled a control that isn’t actually included in its service

Don’t treat these discoveries as paperwork problems.

They’re information.

The next step is to understand the gap, determine who owns it, and decide what needs to happen before answering the application.

What Should You Ask Your MSP or IT Provider?

If your MSP or IT provider manages the technology, ask specific questions rather than simply forwarding the entire application and saying, “Can you fill this out?”

For MFA, ask:

  • Where is MFA enforced?
  • Which users and systems are covered?
  • Are administrators covered?
  • Are there exceptions?
  • Can you provide evidence?

For EDR, ask:

  • What product is deployed?
  • Which devices are covered?
  • Are servers included?
  • Are any agents inactive or missing?
  • Who monitors alerts?
  • Can you provide a current coverage report?

For backups, ask:

  • What systems and data are backed up?
  • How frequently?
  • Where are the backups stored?
  • Are any copies offline or immutable?
  • How is administrative access protected?
  • When was the last restore test?
  • Can you provide documentation?

These questions turn a vague “we have cybersecurity” conversation into verifiable facts.

Keep Evidence Current

Cybersecurity environments change.

Employees join and leave.

Computers are replaced.

Servers are added.

Cloud applications are adopted.

Security agents stop checking in.

Backup jobs fail.

Configurations change.

Evidence from two years ago may accurately show what existed two years ago while saying very little about what exists today.

For cyber insurance application and renewal work, the goal should be to establish the current state of the controls being represented.

Who Should Review Cyber Insurance Evidence?

Different parties have different roles.

MSP / internal IT: Can provide technical information and evidence for systems and controls they manage.

Business management: Should understand the basis for the organization’s responses.

Insurance broker / carrier: Should address insurance coverage, policy language, underwriting and insurer-specific requirements.

Legal counsel: Should address legal interpretations when necessary.

Independent cyber risk advisor: Can help determine what a cybersecurity question is asking, identify the control that needs to be verified, evaluate available evidence and clarify responsibility when the answer spans multiple providers or business functions.

No single party necessarily has every piece of information.

Build an Evidence File Before Renewal

You don’t need to wait until an insurer asks for a document to begin organizing evidence.

Consider maintaining an evidence file containing current information for important controls such as:

  • MFA
  • Endpoint protection / EDR
  • Backups and recovery
  • Privileged access
  • Email security
  • Patch and vulnerability management
  • Security awareness training
  • Incident response
  • Vendor and third-party controls

For each control, try to answer:

What do we have?
Where is it implemented?
Who manages it?
What evidence do we have?
When was the evidence last verified?

That creates something more useful than a collection of screenshots.

It creates a record of the organization’s current cybersecurity control posture.

Need Help Establishing the Evidence Behind Your Answers?

InfoTech Innovators provides independent cyber risk advisory assistance to businesses working through cybersecurity questions on cyber insurance applications and renewals.

We help organizations determine what controls actually exist, identify available evidence, clarify responsibilities among management, MSPs and other technology providers, and identify areas requiring additional validation.

If you’re currently working through an application or renewal, visit our Cyber Insurance Application & Renewal Help page.

If you’re unsure whether your MSP should be answering these questions for you, see Should Your MSP Complete Your Cyber Insurance Questionnaire?

And if you’re stuck on a particular application question, start with What to Do When You Can’t Answer a Cyber Insurance Application Question.

Frequently Asked Questions

What evidence can prove MFA for a cyber insurance application?

Depending on the question and environment, evidence may include identity-provider configuration, conditional-access policies, MFA coverage reports, user inventories, administrator settings and documentation of exceptions. The evidence should demonstrate the scope of MFA enforcement relevant to the insurer’s question.

What evidence can show that EDR is deployed?

Examples include EDR console reports, endpoint inventories, agent deployment or status reports, product identification and information about unmanaged or inactive devices. Compare deployment information with the systems that are expected to be protected.

What backup evidence might a cyber insurer request?

Depending on the application, relevant information may include backup configuration, job history, retention settings, storage architecture, offline or immutable backup configuration, administrative access protections and records of successful restore testing.

Is a screenshot enough evidence for cyber insurance?

It depends on what the insurer is asking and what the screenshot demonstrates. A screenshot can help establish a configuration at a particular point in time, but it may not establish the full scope or continuing operation of a control.

What if we can’t produce evidence for an answer we gave last year?

Don’t assume that last year’s answer remains accurate. Determine the current state of the control, identify what evidence is available and resolve discrepancies before responding to the current application or renewal.

Can InfoTech Innovators tell us what evidence we need?

InfoTech Innovators can help interpret cybersecurity and operational questions, identify relevant controls and evidence, and clarify technical responsibilities. Insurance-specific requirements, coverage and policy interpretation should remain with your licensed insurance professional.


Important: InfoTech Innovators LLC provides cybersecurity, technical and operational advisory services. We do not sell insurance, act as an insurance broker or agent, determine insurance coverage, or provide legal advice or legal interpretations of insurance policies or service-provider contracts. Insurance coverage and policy interpretation should be addressed with your licensed insurance professional, and legal questions should be addressed with qualified legal counsel. No insurance placement, renewal, premium reduction, underwriting decision, coverage determination or claim outcome is guaranteed.

Comments are closed.