JJC SystemsBook a Consultation
Microsoft Defender · Small & Mid-Market

The insurability of the mid-market

Insurers have quietly become the most effective security auditors in the mid-market. This paper examines what they ask, why, and what it means for how you prioritise.

PublishedJuly 5, 2026
Length13 pages · 14 min read
SectorSmall & Mid-Market
PlatformMicrosoft Defender
Service areaManaged IT & Security
Abstract

The insurability of the mid-market

Summary

A cyber insurance renewal used to be a form and a premium. It is now a technical questionnaire with binary questions where answering one incorrectly changes the price or removes the cover.

For mid-market organizations without a security function, this has had an unintended and largely positive consequence: the insurer has become the de facto security architect, and the list they ask about is a better prioritisation than most internal risk registers. This paper examines that list, why it looks the way it does, and how to work it.

Key findings

Four things this paper argues

If you read nothing else, read these. The analysis that follows sets out the evidence for each.

01

The underwriting list is actuarially weighted, which internal risk registers rarely are

Insurers ask about the controls that correlate with claims. That is a different and more useful basis than a risk register built from a framework.

02

Answering aspirationally is the expensive mistake

A claim declined because a control was represented as present and was not costs considerably more than a higher premium.

03

A substantial share of the list is already licensed and undeployed

Conditional access, device compliance and endpoint protection commonly sit unconfigured inside a subscription being renewed annually.

04

Identity controls cover more attack paths than any other category

Sequencing by estate coverage rather than by severity score puts identity first, and it is where the largest single reduction is available.

Analysis

The argument in full

What they actually ask, and why

The questions vary by carrier and converge on a short list. Multi-factor authentication on every account including administrators. Endpoint detection and response across the estate. Backups that are tested, immutable and unreachable from the production domain. Privileged access separated from daily accounts. Email filtering with impersonation protection. A documented and rehearsed incident response plan.

There is nothing exotic there, and that is the point. These are the controls that correlate with claims not being made. An actuary has no interest in a control's theoretical elegance and a considerable interest in whether organizations that lack it file claims more often.

Why the mid-market position is structurally different

Large organizations have a security function whose job is to build a programme. Mid-market organizations have somebody who also does IT, and the question is not what a good programme looks like but what to do first with limited time.

That makes an externally imposed, evidence-weighted priority list unusually valuable. It is not a substitute for a security strategy. It is a better starting point than most organizations of this size would construct unaided.

The second structural difference is licensing. Microsoft 365 Business Premium and the E3 and E5 tiers include a substantial part of this list, and mid-market organizations routinely hold entitlements they have not deployed. Establishing what is already paid for is usually the first and cheapest piece of work, and it frequently funds the rest.

Working the list rather than answering it

Take the questions you answered no to and order them by how much of the estate they cover rather than by severity score.

Identity first, because multi-factor authentication and conditional access close more attack paths than any other single control available to an organization of this size. Then endpoint coverage, including the devices nobody has looked at in two years. Then backup validation — not whether backups run, but whether a restore has been rehearsed at scale. Then privileged access separation, which is cheap and consistently deferred. Then the incident response plan, rehearsed rather than written.

  • Identity: MFA without exceptions, legacy authentication blocked, conditional access applied
  • Endpoints: detection deployed and reconciled against a real inventory, encryption verified
  • Backup: immutable, isolated from the production domain, and restore-rehearsed at scale
  • Privileged access: separate accounts, just-in-time elevation where licensed
  • Response: a plan that has been rehearsed, with somebody authorised to act out of hours
Framework

Something you can apply without us

Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.

Framework

The underwriting-led sequence

Five steps, in the order that reduces exposure fastest for an organization without a security function.

1

Answer honestly

Complete the questionnaire as the position genuinely is. The gaps are your assessment.

2

Audit entitlements

Establish what your existing licensing already covers. It is usually more than expected.

3

Close identity first

MFA, legacy authentication and conditional access, in that order, with no exemptions.

4

Prove recovery

Rehearse a restore at full scale. An untested backup is an assumption, not a control.

5

Rehearse response

A written plan nobody has practised is a document. Run the exercise.

Implications

What this means, depending on your seat

The same argument lands differently across an executive team. These are the three versions worth separating.

For the managing director

For whoever owns IT

For the finance director

References

Where to check this for yourself

Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.

01
Multifactor authentication in Microsoft Entra ID
02
Block legacy authentication with Conditional Access
03
Microsoft Defender for Endpoint onboarding
04
Microsoft 365 Business Premium security features
05
Privileged Identity Management

On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.

Recognise the situation?

Send us your current questionnaire and your licence position. We will map which gaps are already covered by entitlements you hold and what the remainder would take, before you commit to anything.

Discuss this paper Run the related checklist We reply to every message within one business day.
Keep reading

Related papers

business-central
small-mid-market11 pages

The mid-market ERP decision

Nobody outgrows their accounting package on a particular Tuesday. It happens through a series of individually sensible workarounds until the workarounds are the process.

February 22, 2026 · 11 pages · 12 min readRead
intune
small-mid-market11 pages

Build or buy the IT function

The instinct is to hire. It is not always right, and the reasoning matters more than the conclusion.

January 11, 2026 · 11 pages · 12 min readRead
sharepoint
small-mid-market10 pages

The cost of not finding things

The cost is invisible because it is distributed: a few minutes per person per day looking for things, and nobody adds it up.

January 4, 2026 · 10 pages · 11 min readRead
Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.