Should Your MSP Complete Your Cyber Insurance Questionnaire?

If you’re completing a cyber insurance application or renewal, it can seem logical to send the cybersecurity questions to your Managed Service Provider (MSP) and ask them to fill them out.

After all, your MSP manages your technology.

But your MSP may be able to provide the technical facts without being the right party to complete the cyber insurance questionnaire for your organization.

The better approach is usually to determine which questions require technical validation, obtain those facts from the appropriate provider, and make sure management understands the answers being provided.

Why Businesses Turn to Their MSP for Cyber Insurance Questions

Cyber insurance questionnaires routinely ask about controls such as:

  • Multi-factor authentication (MFA)
  • Endpoint Detection and Response (EDR)
  • Antivirus and endpoint protection
  • Email security
  • Backups
  • Recovery testing
  • Vulnerability and patch management
  • Administrative and privileged accounts
  • Remote access
  • Security awareness training
  • Incident response

A business owner or executive may reasonably look at that list and think:

“That’s IT. Our MSP handles IT. They should answer this.”

Sometimes the MSP can answer many of the underlying technical questions.

But there is an important distinction between providing technical information and making the organization’s response on an insurance application.

What Your MSP Should Be Able to Help Verify

Your MSP can be one of your most valuable sources of technical information.

Depending on the services it provides, your MSP may be able to verify:

  • Whether MFA is enabled
  • Which users or systems are protected by MFA
  • What endpoint security platform is installed
  • Whether EDR is deployed
  • How operating systems and applications are patched
  • How backups are configured
  • Where backups are stored
  • Whether email filtering or phishing protection is deployed
  • How remote access is secured
  • Which systems and devices the MSP manages

These are factual questions about your technology environment.

If the MSP implements or manages a control, it should generally be able to provide information about that control.

Why an MSP May Not Want to Complete the Questionnaire

Some businesses are surprised when their MSP says:

“We’ll provide the technical information, but we won’t complete the insurance application for you.”

That doesn’t necessarily mean the MSP is being uncooperative.

The cyber insurance application is being submitted by the organization seeking insurance. It may contain questions that extend beyond the MSP’s technical responsibilities or knowledge.

For example, an MSP may know how your backups are configured but may not know:

  • Whether your organization has a formal incident response plan
  • Whether all employees have completed security awareness training
  • How third-party vendors are evaluated
  • Whether every cloud application requires MFA
  • Whether another technology provider manages certain systems
  • What cybersecurity policies management has formally adopted
  • Whether a control applies to systems outside the MSP’s scope

An MSP may therefore be reluctant to make a broad organizational representation based only on the systems it manages.

The Bigger Problem: What Does Your MSP Actually Manage?

The phrase “our MSP handles cybersecurity” can hide a significant amount of ambiguity.

Managed service agreements vary considerably.

One MSP might provide:

  • Help desk support
  • Microsoft 365 administration
  • Endpoint management
  • Backups
  • Network management

Another might also provide:

  • EDR
  • Security monitoring
  • Vulnerability management
  • Email security
  • Security awareness training
  • Managed detection and response

And some cybersecurity responsibilities may remain entirely with the business or another provider.

That’s why a cyber insurance questionnaire can expose something important:

The organization may not have a clear understanding of who owns each cybersecurity responsibility.

Don’t Confuse “We Have It” With “The MSP Manages It”

Suppose the application asks whether your organization uses MFA.

You know employees receive authentication prompts, so the answer appears obvious.

But several additional questions may matter:

  • Is MFA required for every employee?
  • Is it required for Microsoft 365?
  • Is it required for remote access?
  • Is it required for privileged or administrator accounts?
  • Are there applications outside the MSP’s management?
  • Are service accounts or legacy systems excluded?
  • Who can verify the configuration?

The business may indeed have MFA.

But the MSP may manage only part of the environment covered by the insurer’s question.

The same problem can occur with EDR, backups, email security, patching and other controls.

Management Still Needs to Understand the Answer

A business shouldn’t treat a cyber insurance questionnaire as an IT form that can simply be forwarded elsewhere and forgotten.

Management doesn’t necessarily need to know how to configure an EDR platform or administer an identity system.

But someone representing the organization should understand the basis for the answers being submitted.

That means knowing:

What control exists?
Where is it implemented?
Are there exceptions?
Who manages it?
What evidence supports the answer?

If you’re unsure about a specific question, see our guide to what to do when you can’t answer a cyber insurance application question.

What If Your MSP Says, “That’s Not Included in Your Service”?

That can be one of the most valuable discoveries made during a cyber insurance renewal.

Suppose you believed your MSP handled a particular security control, but the MSP explains that it isn’t part of your current service.

Now you know there is a responsibility gap that needs to be evaluated.

The next question isn’t:

“How do we make this answer Yes?”

It is:

“What actually exists today, and what do we need to do about the gap?”

The answer may involve adding a service, changing a configuration, assigning responsibility internally, engaging another provider, documenting an existing process, or discussing the situation with your insurance professional.

The important thing is that the organization discovered the gap before making an unsupported assumption.

What If the MSP and the Business Give Different Answers?

That should trigger additional validation.

For example:

Management: “Yes, we have EDR.”

MSP: “You have antivirus, but not an EDR service.”

Or:

Management: “Our backups are tested.”

MSP: “Backups run every night, but recovery testing isn’t included in our service.”

Or:

Management: “MFA is required everywhere.”

MSP: “We manage MFA for Microsoft 365, but not the other cloud applications your employees use.”

These aren’t merely wording disagreements.

They may reveal a difference between what management believes exists and what is actually implemented or managed.

Resolve that difference before answering the questionnaire.

What Evidence Should You Request From Your MSP?

When an MSP confirms that a security control exists, consider asking what information can support that confirmation.

Depending on the control, that might include:

  • Configuration reports
  • Screenshots
  • Endpoint inventories
  • Security platform reports
  • Backup reports
  • Patch reports
  • MFA enrollment or configuration information
  • Service descriptions
  • Monitoring reports
  • Written confirmation of the services being provided

The objective isn’t to create unnecessary paperwork.

It’s to establish a reasonable basis for important cybersecurity representations.

Where Does the Insurance Broker Fit?

Your licensed insurance broker plays a different role.

The broker can help with insurance-related matters, including questions about the application process, coverage, policy language and communication with the insurer.

But the broker may not be in a position to determine whether MFA is correctly deployed, whether an endpoint product qualifies as EDR, or whether backups are configured as management believes.

Those are technical and operational questions.

The broker, MSP and business therefore may each hold different pieces of the information needed to complete an application accurately.

Where Can an Independent Cyber Risk Advisor Help?

An independent cyber risk advisor can help connect those pieces.

The advisor can work with management and technical providers to determine:

  • What the cybersecurity question is actually asking
  • What control needs to be verified
  • Whether the control appears to be implemented
  • Whether it is fully or partially implemented
  • What evidence supports it
  • Which provider or internal function owns the responsibility
  • What requires additional technical validation

This can be particularly useful when management is caught between an insurance questionnaire it doesn’t fully understand and an MSP that understandably limits its answers to the technology it actually manages.

The objective isn’t to replace the MSP.

It’s to establish the facts needed for management to make an informed response.

A Simple Division of Responsibilities

A useful way to think about the process is:

Business management: Understand and take responsibility for the organization’s responses.

MSP / internal IT: Provide technical facts and evidence about the systems and controls they implement or manage.

Insurance broker / carrier: Address insurance coverage, policy language, underwriting and insurer-specific questions.

Legal counsel: Address legal interpretations of contracts, policy language or representations when required.

Independent cyber risk advisor: Help translate cybersecurity questions into the technical and operational facts that need to be established, identify evidence and clarify responsibility.

Keeping these roles distinct can make the renewal process much more manageable.

What Should You Do If You’re Stuck Between Your MSP and the Insurance Application?

Don’t guess, and don’t assume that either the MSP or the business has the complete picture.

Start by identifying the specific question you cannot confidently answer.

Then determine:

  1. What control is the insurer asking about?
  2. Which systems, users or locations are within scope?
  3. Who implements or manages that control?
  4. What does that provider confirm is actually in place?
  5. What evidence supports the answer?
  6. Are there exceptions or gaps that need to be addressed?

If you still can’t establish a reliable answer, that’s when independent cybersecurity assistance can be useful.

Cyber Insurance Application & Renewal Help

InfoTech Innovators provides independent cyber risk advisory assistance for businesses working through cybersecurity questions on cyber insurance applications and renewals.

We help organizations understand the technical questions, determine what controls actually exist, identify supporting evidence, and clarify responsibilities between the business, MSP, internal IT and other technology providers.

If you’re stuck between your cyber insurance questionnaire and your MSP, visit our Cyber Insurance Application & Renewal Help page to learn more.

Frequently Asked Questions

Should my MSP fill out my cyber insurance application?

Your MSP can provide technical information about the systems and cybersecurity controls it manages. However, the organization seeking insurance should understand the representations being made. The appropriate division of responsibility depends on the question, the MSP’s scope and the organization’s circumstances.

Why won’t my MSP answer my cyber insurance questionnaire?

An MSP may be willing to verify technical facts but unwilling to make broader representations about systems, policies or controls outside its responsibility. Asking the MSP to identify exactly what it manages can help clarify the situation.

Can my MSP confirm that we have MFA or EDR?

If the MSP implements or manages those controls, it should generally be able to provide technical information about their deployment and scope. Confirm whether the control applies to all systems and users covered by the insurance question.

What if my MSP doesn’t provide a security control required by the application?

First establish whether the control is provided elsewhere or managed internally. If it isn’t implemented, determine what action is appropriate rather than assuming the control exists or answering based on expectation.

Who should answer technical questions on a cyber insurance application?

The technical facts may come from an MSP, internal IT team, security provider or other responsible party. Management should understand the basis for the organization’s response, while insurance and legal interpretations should be directed to the appropriate licensed professionals or counsel.


Important: InfoTech Innovators LLC provides cybersecurity, technical and operational advisory services. We do not sell insurance, act as an insurance broker or agent, determine insurance coverage, or provide legal advice or legal interpretations of insurance policies or service-provider contracts. Insurance coverage and policy interpretation should be addressed with your licensed insurance professional, and legal questions should be addressed with qualified legal counsel. No insurance placement, renewal, premium reduction, underwriting decision, coverage determination or claim outcome is guaranteed.

Comments are closed.