A useful insurance evidence file lets the person answering a technical question trace the answer to its basis. Begin with the exact wording on your application, not a generic list of security products.
Start with your own application
The BOXX Canadian application linked below asks about categories including MFA, backups, patching and endpoint protection, and specifies an authorized representative's declaration. It is one example of an application, not evidence that every insurer uses the same questions or requires the same exports.
Ask your insurer or broker how to record uncertainty and exceptions. Keep their instructions with the completed application. This page is a technical evidence-planning aid, not legal or insurance advice.
Examples of records to examine
| Question area | Possible supporting records | What still needs checking |
|---|---|---|
| MFA | Policy configuration, assignments, exceptions and relevant sign-in records | Registration does not establish enforcement; account and access-path scope matter. |
| Privileged access | Roles, permissions, responsible owners and review records | A list alone does not show whether each permission is justified. |
| Backups | Job results, retention, storage protection, permissions and recovery-test reports | A setting or successful job does not guarantee recovery or protection from every deletion path. |
| Endpoint protection | Inventory reconciled with agent coverage and health | Define the population and investigate unmanaged or unhealthy devices. |
| Patching | Patch status and exceptions against an agreed requirement | Dates, affected assets and the meaning of compliant need to be explicit. |
| Training | Assignment and completion records for the relevant population | Completion does not establish behavior in every incident. |
| Incident response | Plan version, responsibilities and exercise findings | A document's existence does not establish that every scenario has been rehearsed. |
MFA registration, policy and activity are different evidence
Microsoft's Authentication Methods Activity documentation distinguishes registration/capability from usage and describes reporting limitations. Read the relevant view's definition before using its export as evidence.
For a question about enforcement, ask the responsible administrator to reconcile the applicable policy, account and application scope, exclusions and observed sign-ins. Do not treat an MFA-capable user count as proof of every access path.
Record exceptions without automatically calling them safe or unacceptable. A coverage percentage does not explain which accounts are excluded, why, or whether the actual requirement is met.
Read backup evidence in layers
Keep job completion, protection of backup copies and demonstrated recovery separate. Ask which permissions and retention controls apply to the selected copies, and which recovery scenario was tested.
The backup-testing guide explains how to read a result alongside its scope and limitations. An immutability label or separate credentials alone cannot establish that an intruder could never delete a copy.
Keep dates and context with the evidence
- Record the application question and the proposed answer.
- Identify the source, system, scope, reporting period and collection date.
- Record exceptions, missing records and who is resolving them.
- Keep the final submitted version and relevant instructions together.
- Agree how changes and retention requirements will be reviewed for the actual policy.
Historical records can help explain what was in place at a relevant time. A current screenshot may not establish a past configuration. Ask the responsible team what history exists before promising that a report can be produced.
Review before submission
Use the questionnaire review guide to coordinate technical contributors, the signatory and your broker. The speed of a reply does not establish the quality of the underlying controls.
If you need an independent examination, discuss cybersecurity verification, including scope and intended use. Actually's report does not guarantee insurer acceptance or a claim outcome.
For a wider delivery question, consider the Actually Review. For recurring follow-up on agreed actions, provider oversight is a separate engagement.