Cyber insurance proposal
Northwind Traders has 4 controls not in place.
Judged from Microsoft 365 data collected ; 10 controls need evidence Microsoft 365 can't show.
What changed
Pick a point in time to see which controls passed then and not now, or the other way round: useful before a renewal, which comes round every 12 months.
Gaps to close
9 controls-
Legacy authentication is allowed. No enabled policy blocks legacy authentication for all users.
Fix: Block legacy authentication. See the rows →
-
4 of 36 computers not encrypted. For example DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted.
Fix: Turn on BitLocker. See the rows →
-
Anyone, including anonymous links. For example SharePoint and OneDrive: Anyone links are allowed.
Fix: Change SharePoint external sharing to "New and existing guests". See the rows →
-
Users can consent to any app. Any user can grant any app access to their mail and files.
Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. See the rows →
-
1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →
-
1 guest with admin roles. For example g#EXT#@northwindtraders.example: Guest holding Exchange Administrator.
Fix: Remove admin roles from guest accounts. See the rows →
-
4 accounts inactive for 90+ days or never used. For example hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026.
Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used. See the rows →
-
1 domain with SPF problems. For example parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing.
Fix: Publish one SPF record per domain ending in -all. See the rows →
-
4 external forwards. For example ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy).
Fix: Remove forwarding to outside addresses unless the client has a documented business reason. See the rows →
Multi-factor authentication and access
FailEvery account signs in with MFA, legacy protocols that can't are blocked, administrators are few, separate and named, and accounts go when people do.
Multi-factor authentication is enforced for all users accessing email (including webmail and mobile) and cloud applications.
- Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
- But: 14 users without MFA.
- Users with an MFA method registered
- 62.2% of 37
- Accounts covered by an enforced MFA policy
- 36 of 36
Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
What Microsoft 365 can't show: Judged for Microsoft 365 sign-ins only. Add VPNs, remote desktop and other systems.
Change this answer
Every privileged and administrator account is protected by MFA.
- 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
- But: 1 admin without MFA, and 1 whose registration isn't known.
- Accounts holding privileged roles
- 4
- Admins with no MFA policy
- 1
- Admins with no MFA method registered
- 2
Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
What Microsoft 365 can't show: Judged for Microsoft 365 and Entra ID admin roles. Add administrators of other systems.
Change this answer
VPN, remote desktop and remote support tools need MFA.
Remote access to the network is only possible through [VPN or remote access product], which requires multi-factor authentication. Remote support tools ([product]) also require multi-factor authentication.
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Sign-in protocols that can't use MFA (IMAP, POP, SMTP AUTH, older Office clients) are blocked.
- Legacy authentication is allowed.
- No enabled policy blocks legacy authentication for all users
- SMTP AUTH is on for the organisation.
- SMTP AUTH is allowed
Fix: Block legacy authentication (Exchange ActiveSync and other clients) with a Conditional Access policy for all users. Legacy protocols can't do MFA and are the most common password-spray target. See the rows →
Legacy authentication is allowed. No enabled policy blocks legacy sign-in for all users.
What Microsoft 365 can't show: Judged from Conditional Access and Exchange Online settings.
Change this answer
Administrators use a separate account for admin work, not the one they read email with.
- 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →
Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
What Microsoft 365 can't show: Judged from Microsoft 365 admin role holders: an admin account with a licence or a mailbox looks like an everyday account.
Change this answer
Administrator access is limited to a small number of named internal people: no guests, no unnecessary Global Administrators, no apps with admin roles.
- 2 Global Administrators.
- Cloud-only tenant: no accounts are synced from on-premises AD.
- Accounts holding privileged roles
- 4
- Admins with no MFA policy
- 1
- Admins with no MFA method registered
- 2
- 1 guest with admin roles.
- g#EXT#@northwindtraders.example: Guest holding Exchange Administrator
- 1 app with privileged roles.
- Some app: App holding Exchange Administrator
Fix: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. See the rows →
Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.
What Microsoft 365 can't show: Microsoft 365 shows who holds admin roles today; describe how the list is reviewed.
Change this answer
Accounts are disabled promptly when people leave, inactive accounts are removed, and no disabled account keeps a licence.
- No stale guest invitations.
- 4 accounts inactive for 90+ days or never used.
- hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026
- sophie.smith@northwindtraders.example: Licensed member, last signed in 21 Jan 2026
- thomas.clarke@northwindtraders.example: Licensed member, last signed in 2 Jun 2026
- g#EXT#@northwindtraders.example: Guest, never signed in, created ?
- 1 disabled account still licensed.
- robert.hughes@northwindtraders.example: Disabled, holding 1 licence
Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers. See the rows →
Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.
What Microsoft 365 can't show: Judged from sign-in activity in Microsoft Entra ID (needs Entra ID P1 for last sign-in dates). Describe the leavers process in the answer.
Change this answer
Email security
PartlyMail is filtered, the domains can't be spoofed, nothing forwards outside unnoticed, and payment changes are verified by voice.
Incoming email is filtered for spam, phishing and malicious links and attachments.
- Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).
Incoming email is filtered for spam, phishing and malware. Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).
What Microsoft 365 can't show: Microsoft 365 shows which mail gateway the domains route through, not its settings.
Change this answer
Every email domain publishes SPF, signs with DKIM and has a DMARC policy.
- 1 domain with SPF problems.
- parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing
- 1 mail domain without DKIM.
- northwindtraders.example: Microsoft 365 DKIM isn't set up (selector2 CNAME missing)
- 2 domains without DMARC enforcement.
- northwindtraders.example: DMARC is monitor-only (p=none); spoofed mail is still delivered
- parked.example: Doesn't receive mail but has no DMARC p=reject record
Fix: Publish one SPF record per domain ending in -all (or ~all while testing), e.g. "v=spf1 include:spf.protection.outlook.com -all". Domains that never send mail should publish "v=spf1 -all". See the rows →
SPF, DKIM and DMARC are not fully configured for the organisation's email domains. 1 domain with SPF problems. 1 mail domain without DKIM. 2 domains without DMARC enforcement.
What Microsoft 365 can't show: Judged from public DNS and Exchange Online for the tenant's domains.
Change this answer
Automatic forwarding of email to external addresses is blocked, and inbox rules that forward or hide mail are caught.
- The default outbound policy blocks automatic external forwarding.
- 4 external forwards.
- ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy)
- ann.patel@northwindtraders.example: Inbox rule "Copy to home" forwards to ann.patel.home@homemail.example
- grace.taylor@northwindtraders.example: Mailbox forwarding to grace.taylor@homemail.example (doesn't keep a copy)
- olivia.smith@northwindtraders.example: Inbox rule "Invoices to bookkeeper" forwards to bookkeeping@ledgerline.example
- 1 suspicious inbox rule.
- ann.patel@northwindtraders.example: ".": Moves to RSS Feeds mail mentioning invoice, payment; Rule name '.' looks deliberately blank
Fix: Remove forwarding to outside addresses unless the client has a documented business reason. Forwarding is the most common way attackers keep reading a mailbox after a password reset. See the rows →
Automatic forwarding to external addresses is restricted in Exchange Online, with exceptions. The default outbound policy blocks automatic external forwarding. But 4 external forwards found.
What Microsoft 365 can't show: Judged from the Exchange Online outbound spam policy, mailbox forwarding and inbox rules.
Change this answer
Requests to change bank details or make payments are verified with a known contact by phone.
Requests to change supplier bank details or make urgent payments are verified by calling the requester on a number already held on file, never one given in the request. Payments over [amount] need approval by [role].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Devices and patching
FailComputers are managed, encrypted, protected by EDR, on supported operating systems and patched within 14 days.
Endpoint detection and response is installed and monitored on all computers and servers.
[EDR product, for example Microsoft Defender for Endpoint] is installed on all [number] computers and servers. Alerts are monitored by [team or security provider] [24/7 or in business hours].
What Microsoft 365 can't show: Office Sentry doesn't read Microsoft Defender; answer from the EDR console.
Write this answer for Northwind Traders
Company devices are managed, encrypted and run operating systems that still get security updates.
- Computers managed by Intune
- 36
- Of which encrypted
- 32
- Windows computers out of support
- 5
- Reaching end of support within 90 days
- 20
- Not compliant
- 6
- 4 of 36 computers not encrypted.
- DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted
- LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows disk isn't encrypted
- LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Windows disk isn't encrypted
- LAPTOP-SMITH07 (olivia.smith@northwindtraders.example): Windows disk isn't encrypted
- 6 of 37 managed devices not compliant.
- DESK-ROBINSON12 (george.robinson@northwindtraders.example): Not compliant
- DESK-WRIGHT18 (leo.wright@northwindtraders.example): Not compliant
- LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Not compliant
- LAPTOP-SCOTT25 (alfie.scott@northwindtraders.example): Not compliant
- LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Not compliant
- and 1 more
- 5 of 36 Windows computers past end of support.
- LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-MARTIN22 (maya.martin@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-PATEL13 (hannah.patel@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-ROBERTS31 (george.roberts@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-TAYLOR04 (grace.taylor@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- and 20 more
Fix: Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data. See the rows →
Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.
What Microsoft 365 can't show: Judged for devices known to Intune or Entra ID. Servers, macOS and unmanaged devices aren't seen.
Change this answer
Critical security updates are installed within 14 days of release (some forms say 30).
- But: 3 devices haven't checked in for 30+ days.
Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].
What Microsoft 365 can't show: Intune shows when each device last checked in, not when updates were installed.
Write this answer for Northwind Traders
Backups and recovery
Your evidenceData is backed up separately and the restores are tested; there is a plan for an incident and for keeping the business running.
Backups are taken regularly, kept offline or immutable and separate from the main systems, and restores are tested.
Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
A business continuity and disaster recovery plan exists and is tested.
A business continuity and disaster recovery plan covers [key systems and services]. Recovery targets are [time to restore] to restore service and no more than [data loss window] of data loss. It was last tested on [date].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
A documented incident response plan says who does what.
A documented incident response plan sets out roles, contacts and the steps to contain and recover from a cyber incident, including notifying [the insurer and IT provider]. It was last reviewed on [date] and tested on [date].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Monitoring and data
FailActivity is logged, suspicious sign-ins are watched, and data only leaves through sharing and apps that are controlled.
Audit logging is enabled for email and user activity.
- Mailbox auditing is on for the organisation.
Mailbox audit logging is enabled in Exchange Online, recording access to and actions on mailboxes. Mailbox auditing is on for the organisation.
What Microsoft 365 can't show: Judged from Exchange Online mailbox auditing and the unified audit log.
Change this answer
Risky sign-ins and users are detected and acted on.
- Not checked: no accounts are at risk in Entra ID Protection (Risky users need Entra ID P2).
- Not checked: no risky sign-ins succeeded (Sign-in risk needs Entra ID P2).
Risky users need Entra ID P2.
Sign-ins are monitored for suspicious activity by [tool or service], and alerts are reviewed by [team or provider] [within one working day].
What Microsoft 365 can't show: Judged from Entra ID Protection (needs Entra ID P2 for the full detections).
Write this answer for Northwind Traders
Sharing files with people outside the organisation is restricted and guests are invited deliberately.
- Anyone, including anonymous links.
- SharePoint and OneDrive: Anyone links are allowed
- 3 files and folders shared with anyone.
- Campaign video.mp4 (Marketing / Documents): Anyone can edit
- Brand assets (Marketing / Documents): Anyone can view, link never expires
- holiday.jpg (OneDrive of ann.patel@northwindtraders.example): Anyone can view
- Anyone, including guests, can invite guests.
- Guests can invite other guests
Fix: Change SharePoint external sharing to "New and existing guests" so every external person signs in. If the client relies on Anyone links, set them to expire and to view-only. See the rows →
Sharing with anonymous and external users is not restricted in SharePoint and OneDrive. Anyone, including anonymous links. 3 files and folders shared with anyone. Anyone, including guests, can invite guests.
What Microsoft 365 can't show: Judged from SharePoint and OneDrive sharing settings and links.
Change this answer
Users can't consent to third-party apps on their own, and apps with risky permissions are known.
- Users can consent to any app.
- Any user can grant any app access to their mail and files
- 1 app with access to mail, files or the directory.
- Mail Sync Pro: Mail.Read (application permission; unverified publisher)
Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. Consent phishing relies on this setting. See the rows →
Third-party application access to Microsoft 365 data is not controlled. Users can consent to any app. 1 app with access to mail, files or the directory.
What Microsoft 365 can't show: Judged from Entra ID consent settings and app permissions.
Change this answer
Network and people
Your evidenceA firewall between the network and the internet, no remote desktop open to it, and staff trained to spot phishing.
Firewalls sit between the network and the internet.
A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Remote desktop is closed to the internet, or only reachable through a VPN or gateway with MFA.
Remote desktop (RDP) is not reachable from the internet. Remote connections go through [VPN or remote desktop gateway] with multi-factor authentication. This was last confirmed on [date] by [external scan or firewall review].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Staff receive regular security awareness and phishing training.
All staff complete security awareness training [when they join and every year], through [training provider or platform]. Simulated phishing exercises run [monthly or quarterly] and the results are reviewed by [role].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Answers for the form
Cyber insurance proposalThe questions UK cyber insurance proposal and renewal forms usually ask. Wording differs between insurers, so match each answer to the question on the form.
Multi-factor authentication and access 7 questions
Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
MFA coverage: accounts with a gap → Microsoft 365 data from 11 Oct 2026.
Still to check: This covers Microsoft 365 sign-ins only. Add VPN, remote desktop and any other system people reach from outside the office.
Change this answer
Remote access to the network is only possible through [VPN or remote access product], which requires multi-factor authentication. Remote support tools ([product]) also require multi-factor authentication.
Why: Microsoft 365 can't show this. It sees Microsoft 365 sign-ins (see the MFA answer), not VPNs or remote desktop.
Write this answer for Northwind Traders
Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers Microsoft 365 and Entra ID admin roles. Add admin access to servers, firewalls, backup consoles and other cloud services.
Change this answer
Legacy authentication is allowed. No enabled policy blocks legacy sign-in for all users.
Legacy sign-ins: what each mailbox allows → Microsoft 365 data from 11 Oct 2026.
Change this answer
Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers Microsoft 365 admin roles. Add local administrator, server and domain admin accounts.
Change this answer
Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.
Admins and roles → Microsoft 365 data from 11 Oct 2026.
Still to check: Add administrators of servers, firewalls and other systems, and say how the list is kept.
Change this answer
Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.
Inactive accounts → Microsoft 365 data from 11 Oct 2026.
Still to check: Describe the leavers process: who tells IT, and how quickly accounts are disabled.
Change this answer
Email security 4 questions
Incoming email is filtered for spam, phishing and malware. Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).
Email domains → Microsoft 365 data from 11 Oct 2026.
Still to check: Office Sentry sees the mail routing and licences, not the filtering policies. Confirm Safe Links and Safe Attachments (or the gateway's equivalent) apply to every user.
Change this answer
SPF, DKIM and DMARC are not fully configured for the organisation's email domains. 1 domain with SPF problems. 1 mail domain without DKIM. 2 domains without DMARC enforcement.
Email domains → Microsoft 365 data from 11 Oct 2026.
Change this answer
Automatic forwarding to external addresses is restricted in Exchange Online, with exceptions. The default outbound policy blocks automatic external forwarding. But 4 external forwards found.
Mail forwarding → Microsoft 365 data from 11 Oct 2026.
Change this answer
Requests to change supplier bank details or make urgent payments are verified by calling the requester on a number already held on file, never one given in the request. Payments over [amount] need approval by [role].
Why: Microsoft 365 can't show this. It's a finance process.
Write this answer for Northwind Traders
Devices and patching 5 questions
[EDR product, for example Microsoft Defender for Endpoint] is installed on all [number] computers and servers. Alerts are monitored by [team or security provider] [24/7 or in business hours].
Why: Microsoft 365 can't show this. Office Sentry doesn't read Microsoft Defender for Endpoint or other EDR consoles.
Write this answer for Northwind Traders
Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.
Devices: operating systems → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers Windows computers known to Intune or Entra ID. Add servers, macOS, phones, network devices and other software.
Change this answer
Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].
Why: Microsoft 365 can't show this. Intune shows which Windows version each computer runs (see the supported systems answer), not when updates were installed.
Still to check: Some forms ask about 30 days. Answer to the timescale on the form.
Write this answer for Northwind Traders
Company computers managed in Microsoft Intune are not all encrypted. 4 of 36 computers not encrypted.
Devices: managed devices → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers computers managed by Intune. Add any computers that aren't.
Change this answer
Company devices are not all managed centrally. 1 of 37 joined computers not in Intune. 6 of 37 managed devices not compliant.
Devices: managed devices → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers devices joined to Entra ID. Add any company devices that aren't.
Change this answer
Backups and recovery 3 questions
Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].
Why: Backups aren't visible in Microsoft 365 data. Answer from the backup product's records.
Write this answer for Northwind Traders
A business continuity and disaster recovery plan covers [key systems and services]. Recovery targets are [time to restore] to restore service and no more than [data loss window] of data loss. It was last tested on [date].
Why: Microsoft 365 can't show this.
Write this answer for Northwind Traders
A documented incident response plan sets out roles, contacts and the steps to contain and recover from a cyber incident, including notifying [the insurer and IT provider]. It was last reviewed on [date] and tested on [date].
Why: Microsoft 365 can't show this.
Write this answer for Northwind Traders
Monitoring and data 4 questions
Mailbox audit logging is enabled in Exchange Online, recording access to and actions on mailboxes. Mailbox auditing is on for the organisation.
Audit logging control → Microsoft 365 data from 11 Oct 2026.
Still to check: How long audit logs are kept depends on the Microsoft 365 licence; confirm the retention period.
Change this answer
Sign-ins are monitored for suspicious activity by [tool or service], and alerts are reviewed by [team or provider] [within one working day].
Why: Sign-in risk needs Entra ID P2.
Write this answer for Northwind Traders
Sharing with anonymous and external users is not restricted in SharePoint and OneDrive. Anyone, including anonymous links. 3 files and folders shared with anyone. Anyone, including guests, can invite guests.
Guests and sharing: external access settings → Microsoft 365 data from 11 Oct 2026.
Change this answer
Third-party application access to Microsoft 365 data is not controlled. Users can consent to any app. 1 app with access to mail, files or the directory.
Apps and consents → Microsoft 365 data from 11 Oct 2026.
Change this answer
Network 2 questions
A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.
Why: Microsoft 365 can't show this. Firewalls aren't part of Microsoft 365.
Write this answer for Northwind Traders
Remote desktop (RDP) is not reachable from the internet. Remote connections go through [VPN or remote desktop gateway] with multi-factor authentication. This was last confirmed on [date] by [external scan or firewall review].
Why: Microsoft 365 can't show this. It's a firewall setting.
Write this answer for Northwind Traders
People 1 question
All staff complete security awareness training [when they join and every year], through [training provider or platform]. Simulated phishing exercises run [monthly or quarterly] and the results are reviewed by [role].
Why: Training isn't visible in Microsoft 365 data. Answer from the training provider's records.
Write this answer for Northwind Traders
About this pack
Scope: insurers ask about the whole business, not one cloud service. A Pass here covers Microsoft 365; the answer should say what covers the rest.
Most forms are signed as a warranty: a wrong answer can void the policy, so a Partly should be declared, not rounded up.
Requirements: UK cyber insurance proposal forms as commonly worded in 2026. Questions drawn from the proposal and renewal forms of UK cyber insurers and brokers, in their typical wording; no insurer's form is copied.
Pass and Fail are judged from Microsoft 365 settings and accounts read with read-only access; accepted risks count as documented exceptions. Oldest data used: .