The underwriting list is actuarially weighted, which internal risk registers rarely are
Insurers ask about the controls that correlate with claims. That is a different and more useful basis than a risk register built from a framework.
Insurers have quietly become the most effective security auditors in the mid-market. This paper examines what they ask, why, and what it means for how you prioritise.
A cyber insurance renewal used to be a form and a premium. It is now a technical questionnaire with binary questions where answering one incorrectly changes the price or removes the cover.
For mid-market organizations without a security function, this has had an unintended and largely positive consequence: the insurer has become the de facto security architect, and the list they ask about is a better prioritisation than most internal risk registers. This paper examines that list, why it looks the way it does, and how to work it.
If you read nothing else, read these. The analysis that follows sets out the evidence for each.
Insurers ask about the controls that correlate with claims. That is a different and more useful basis than a risk register built from a framework.
A claim declined because a control was represented as present and was not costs considerably more than a higher premium.
Conditional access, device compliance and endpoint protection commonly sit unconfigured inside a subscription being renewed annually.
Sequencing by estate coverage rather than by severity score puts identity first, and it is where the largest single reduction is available.
The questions vary by carrier and converge on a short list. Multi-factor authentication on every account including administrators. Endpoint detection and response across the estate. Backups that are tested, immutable and unreachable from the production domain. Privileged access separated from daily accounts. Email filtering with impersonation protection. A documented and rehearsed incident response plan.
There is nothing exotic there, and that is the point. These are the controls that correlate with claims not being made. An actuary has no interest in a control's theoretical elegance and a considerable interest in whether organizations that lack it file claims more often.
Large organizations have a security function whose job is to build a programme. Mid-market organizations have somebody who also does IT, and the question is not what a good programme looks like but what to do first with limited time.
That makes an externally imposed, evidence-weighted priority list unusually valuable. It is not a substitute for a security strategy. It is a better starting point than most organizations of this size would construct unaided.
The second structural difference is licensing. Microsoft 365 Business Premium and the E3 and E5 tiers include a substantial part of this list, and mid-market organizations routinely hold entitlements they have not deployed. Establishing what is already paid for is usually the first and cheapest piece of work, and it frequently funds the rest.
Take the questions you answered no to and order them by how much of the estate they cover rather than by severity score.
Identity first, because multi-factor authentication and conditional access close more attack paths than any other single control available to an organization of this size. Then endpoint coverage, including the devices nobody has looked at in two years. Then backup validation — not whether backups run, but whether a restore has been rehearsed at scale. Then privileged access separation, which is cheap and consistently deferred. Then the incident response plan, rehearsed rather than written.
Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.
Five steps, in the order that reduces exposure fastest for an organization without a security function.
Complete the questionnaire as the position genuinely is. The gaps are your assessment.
Establish what your existing licensing already covers. It is usually more than expected.
MFA, legacy authentication and conditional access, in that order, with no exemptions.
Rehearse a restore at full scale. An untested backup is an assumption, not a control.
A written plan nobody has practised is a document. Run the exercise.
The same argument lands differently across an executive team. These are the three versions worth separating.
Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.
On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.
Send us your current questionnaire and your licence position. We will map which gaps are already covered by entitlements you hold and what the remainder would take, before you commit to anything.
Nobody outgrows their accounting package on a particular Tuesday. It happens through a series of individually sensible workarounds until the workarounds are the process.
The instinct is to hire. It is not always right, and the reasoning matters more than the conclusion.
The cost is invisible because it is distributed: a few minutes per person per day looking for things, and nobody adds it up.
Describe the situation in your own words.