Ask Actually

What Evidence Cyber Insurers Ask For.

In short

Start with your actual cyber insurance application and instructions from your insurer or broker. For each technical answer, identify relevant records, their dates, scope and exceptions. Policy configuration, activity reports and test results answer different questions. An evidence checklist does not establish coverage or guarantee acceptance of a claim.

A useful insurance evidence file lets the person answering a technical question trace the answer to its basis. Begin with the exact wording on your application, not a generic list of security products.

Start with your own application

The BOXX Canadian application linked below asks about categories including MFA, backups, patching and endpoint protection, and specifies an authorized representative's declaration. It is one example of an application, not evidence that every insurer uses the same questions or requires the same exports.

Ask your insurer or broker how to record uncertainty and exceptions. Keep their instructions with the completed application. This page is a technical evidence-planning aid, not legal or insurance advice.

Examples of records to examine

Adapt these requests to the question and environment
Question areaPossible supporting recordsWhat still needs checking
MFAPolicy configuration, assignments, exceptions and relevant sign-in recordsRegistration does not establish enforcement; account and access-path scope matter.
Privileged accessRoles, permissions, responsible owners and review recordsA list alone does not show whether each permission is justified.
BackupsJob results, retention, storage protection, permissions and recovery-test reportsA setting or successful job does not guarantee recovery or protection from every deletion path.
Endpoint protectionInventory reconciled with agent coverage and healthDefine the population and investigate unmanaged or unhealthy devices.
PatchingPatch status and exceptions against an agreed requirementDates, affected assets and the meaning of compliant need to be explicit.
TrainingAssignment and completion records for the relevant populationCompletion does not establish behavior in every incident.
Incident responsePlan version, responsibilities and exercise findingsA document's existence does not establish that every scenario has been rehearsed.

MFA registration, policy and activity are different evidence

Microsoft's Authentication Methods Activity documentation distinguishes registration/capability from usage and describes reporting limitations. Read the relevant view's definition before using its export as evidence.

For a question about enforcement, ask the responsible administrator to reconcile the applicable policy, account and application scope, exclusions and observed sign-ins. Do not treat an MFA-capable user count as proof of every access path.

Record exceptions without automatically calling them safe or unacceptable. A coverage percentage does not explain which accounts are excluded, why, or whether the actual requirement is met.

Read backup evidence in layers

Keep job completion, protection of backup copies and demonstrated recovery separate. Ask which permissions and retention controls apply to the selected copies, and which recovery scenario was tested.

The backup-testing guide explains how to read a result alongside its scope and limitations. An immutability label or separate credentials alone cannot establish that an intruder could never delete a copy.

Keep dates and context with the evidence

  • Record the application question and the proposed answer.
  • Identify the source, system, scope, reporting period and collection date.
  • Record exceptions, missing records and who is resolving them.
  • Keep the final submitted version and relevant instructions together.
  • Agree how changes and retention requirements will be reviewed for the actual policy.

Historical records can help explain what was in place at a relevant time. A current screenshot may not establish a past configuration. Ask the responsible team what history exists before promising that a report can be produced.

Review before submission

Use the questionnaire review guide to coordinate technical contributors, the signatory and your broker. The speed of a reply does not establish the quality of the underlying controls.

If you need an independent examination, discuss cybersecurity verification, including scope and intended use. Actually's report does not guarantee insurer acceptance or a claim outcome.

For a wider delivery question, consider the Actually Review. For recurring follow-up on agreed actions, provider oversight is a separate engagement.

Common questions

What evidence do cyber insurers ask for in Ontario?
Use the actual application and any supplemental requests. The examples here help organize technical evidence; they are not a universal Ontario requirement or an insurer-approved checklist.
Who should sign the application?
Read the application's signature instructions and confirm the authorized signatory with your organization and broker. Technical contributors and authorized signatories may be different people. This article does not determine anyone's legal responsibility.
Does an MFA registration report prove enforcement?
No. It shows registration or capability within that report's scope. Examine the relevant policy, assignments, exceptions and sign-in evidence as well. Licensing, report scope and reporting delays can affect what is available.
How long should we keep security logs?
Agree retention by log source with the responsible team, considering investigation needs, policy requirements and applicable obligations. Record what is available and for which dates. One retention figure may not describe every system.
Does a complete evidence file guarantee coverage?
No. Evidence supports particular statements within its scope. Requirements and coverage depend on the applicable application, policy and circumstances; confirm questions with the insurer or broker and appropriate advisers.
Sources

This is one question. An independent review answers the rest, with evidence.

Request an Independent Review