✓Is multi-factor authentication actually enforced on every account, including the exceptions?
✓Have the backups been restored, not just reported as successful?
✓Were former employees fully removed, everywhere?
✓Is anyone actually reading the security alerts?
✓Are systems actually patched, or only scheduled to be?
✓Does the evidence support the control statements on your cyber-insurance application?
We do not sell security tools and we take no vendor commissions, so we have no stake in the answer. That is what makes the answer worth having. More on what independence means here.