What your cyber insurer expects from your IT provider
A renewal questionnaire or a new proposal form has landed on your desk. Somewhere on page two it asks whether your backups are held offline, whether they are protected by multi-factor authentication, and whether critical security patches are installed within 30 days. Your IT is looked after by someone competent, and you still cannot say with confidence that the honest answer to each question is yes.
That discomfort matters. A cyber policy pays out on the basis of what you declared when you bought it. If a declaration turns out to have been wrong, the claim can be disputed at exactly the moment you need it most.
The questions are more answerable than they look. Each one is really asking something specific, and once you know what that is, you can put the right question to whoever runs your IT and get a straight answer back.
The three questions almost every UK cyber insurer now asks
The wording varies between insurers, but the substance has become remarkably consistent. A recent enquiry to us from a newly launched conveyancing practice listed these three conditions from its insurer, and they are representative of what regulated firms across legal, accountancy and financial services are being asked to confirm:
- Sensitive and critical data and critical business systems are backed up at least weekly, offline or on a separate network.
- Backups are appropriately protected through multi-factor authentication, encryption, separate credentials or offline storage.
- Critical and high-risk security patches are installed across the business within 30 days.
Each one deserves a plain-English explanation, because each one hides a common wrong answer.
Question one: backups held offline or on a separate network
Why insurers ask this
The reason is ransomware. A modern attack is not designed to encrypt your live files and leave your backups alone. It finds the backups first, encrypts or deletes them, and only then locks the live environment, so that paying is the only route back. When an insurer asks about separation, it is asking one question in disguise: if everything you use day to day is encrypted tonight, is there a copy the attacker could not reach?
The Microsoft 365 misconception
This is the single most common wrong answer on proposal forms, so it needs its own space.
Microsoft is responsible for keeping its own infrastructure running. It is not responsible for your data. Under what Microsoft calls the shared responsibility model, the mailboxes, SharePoint sites, Teams files and OneDrive folders inside your tenant remain yours to protect and to recover. The recycle bin and retention policies are useful, but they are not a backup in the sense your insurer means. A retention policy is a rule running inside the same tenant an attacker has just walked into. A compromised account with administrative rights can delete data past the point retention will bring it back, and nothing in a standard Microsoft 365 subscription will stand in the way.
Put bluntly: if you answered “yes, Microsoft backs it up” on your proposal form, that answer is very probably wrong.
What a compliant arrangement looks like
An independent copy of your tenant data, held outside the tenant, under credentials that do not belong to any day-to-day user. “Separate network” does not mean a second folder on the same server or a second SharePoint site. It means storage that someone inside your environment, using the access they have stolen, cannot reach. The National Cyber Security Centre’s guidance on offline backups in an online world puts it well: a backup that is permanently connected to the live environment is not offline, however far away it is physically stored.
Question two: backups protected by MFA, encryption or separate credentials
Why insurers ask this
Because a backup an attacker can log into is not a backup. The scenario the underwriter has in mind is specific. A member of staff clicks a convincing link, hands over their password, and an attacker is now inside that person’s account. The insurer wants to know whether that one compromised login also opens the door to the backups. If the same credentials administer both, it does.
What good looks like
Backup administration should sit under an identity that nobody uses for email or daily work, with multi-factor authentication enforced on it, and with the backup data encrypted both while it is stored and while it is being copied. None of this is exotic. It is one of the cheapest controls on the whole form to put right, and one of the most frequently missed, because in most small firms the backup was set up once, years ago, by whoever happened to be around, and nobody has looked at who can log into it since.
Question three: critical patches within 30 days
Why insurers ask this
A large share of successful attacks exploit a vulnerability for which a fix already existed. The attacker did not need to be clever; they needed the victim to be a few weeks behind. Thirty days is the insurer’s way of asking whether you have a process at all.
Why “we have automatic updates on” is not the answer
Automatic updates on individual laptops is not a patch management process. It gives you no visibility of which machines are current, no way to handle the laptop that has sat closed in a drawer for a fortnight, and, most importantly, no evidence. The insurer is not really asking whether you are patched. It is asking whether you can prove it. For most firms of this size the answer is centrally managed deployment through Microsoft Intune, Microsoft’s device management platform, which pushes updates to every managed device on a schedule and reports back on which ones have taken them. The report is the point.
What your insurer will want if you ever claim
At claim stage, months or years after you signed the form, a loss adjuster will ask you to demonstrate that the declarations were true on the day of the incident. “We patch within 30 days” is a statement of intent. A dated report showing every device and its patch status is evidence. Only one of those will help you.
The question behind all three: can you evidence it?
Every one of these conditions is really a question about documentation. At proposal stage you sign a declaration. At claim stage the loss adjuster asks you to demonstrate that it was true. Firms rarely fail because they lied on the form. They fail because they believed something nobody had checked, and could not show otherwise when it mattered.
The practical answer is simple. Ask whoever manages your IT for a written statement of controls, mapped line by line to your insurer’s questions, and keep it with the policy. Any competent provider should produce this without being asked, because it summarises work they are already doing. A provider who will not put it in writing has told you something useful. Notification timing matters too: most policies require early notice, which is one of the calls covered in our guide to what to do in the first hour after a suspected security breach.
Where Cyber Essentials fits
Cyber Essentials is a UK government-backed certification covering five basic technical controls: firewalls, secure configuration, access control, malware protection and patch management. It overlaps substantially with what insurers now ask, so the work to satisfy your insurer and the work to gain the certificate are largely the same work.
Some insurers price it in. For regulated firms it is increasingly requested by clients, lenders and panel managers regardless of insurance, so it tends to pay for itself in tenders as well as in premiums. It is not, however, universally required for cover, and requirements vary between insurers, so check your own policy wording rather than assuming either way.
What to do before you sign the proposal form
You do not need to understand the technology to get to the truth. You need to ask six questions of whoever runs your IT and listen carefully to the answers:
- Is there a backup of our Microsoft 365 data held outside Microsoft 365, and when was it last tested by restoring something?
- Who can log in to the backups, and does that account use multi-factor authentication?
- How do we know every laptop has this month’s critical updates, and can you show me?
- What is our documented process when a critical vulnerability is announced?
- If our insurer asked for evidence tomorrow, what would you send them?
- Do we hold Cyber Essentials, and if not, what is the gap?
The last question is the one that most often gets a vague answer. A vague answer is itself the finding.
Talk to us about your insurer’s questions
Or call 020 7123 4910
How Lanmark handles this
Everything above holds whether or not you ever speak to us. For firms that would rather have it dealt with, the pieces fit together as one managed service, priced per user per month with no per-device or per-incident charges.
We hold an independent copy of your Microsoft 365 data outside the tenant, under separate protected credentials, and we test restores rather than assuming they work. Patching is deployed and reported through Intune, so the evidence exists before anyone asks for it. Your environment is watched around the clock by our 24x7x365 managed detection and response service, which answers the “documented response capability” question that often appears further down the same form. We support firms through Cyber Essentials certification, and we provide a written statement of controls mapped to your insurer’s exact wording so that it can sit alongside the policy.
For law firms and other regulated practices, this is now one of the most common reasons a first conversation with us starts. One plain caveat: your policy is a contract between you and your insurer, and meeting these controls does not guarantee a claim will be paid. What it does is put you in a position to answer the form truthfully and prove it later.
If you would rather start with licensing, our free Microsoft 365 licence review is the lower-friction option and usually surfaces the backup gap on its own.
Get a written statement of controls for your insurer
Or call 020 7123 4910
Frequently asked questions
Does Microsoft 365 back up my data?
Not in the sense a cyber insurer means. Microsoft protects its own infrastructure, but under the shared responsibility model the data inside your tenant, including email, SharePoint, Teams and OneDrive, is yours to protect and recover. Retention policies and the recycle bin run inside the same tenant an attacker would have access to, so they do not count as an offline or separate backup. You need an independent copy held outside the tenant under separate credentials.
What backup does my cyber insurer require?
Most UK cyber insurers now ask for sensitive and critical data to be backed up at least weekly, held offline or on a separate network, and protected by multi-factor authentication, encryption or separate credentials. The underlying question is whether a copy of your data would survive an attacker who is already inside your live environment. Check your own policy wording, because exact conditions vary between insurers.
What does “backups held offline or on a separate network” mean?
It means the backup copy is stored somewhere an attacker inside your live environment cannot reach with the access they have stolen. A second folder on the same server, or a second site inside the same Microsoft 365 tenant, does not qualify. A separate storage location with its own credentials, not permanently connected to your day-to-day systems, does.
How quickly do critical security patches need to be installed for cyber insurance?
The common condition on UK proposal forms is that critical and high-risk security patches are installed across the business within 30 days of release. Insurers expect a managed process with reporting, so you can show which devices were updated and when, rather than automatic updates on individual machines with no record.
Do I need Cyber Essentials to get cyber insurance?
Not always. Cyber Essentials is a UK government-backed certification covering five basic technical controls, and its requirements overlap substantially with what insurers ask about. Some insurers price it in or ask for it; others do not require it. Regulated firms benefit from holding it because clients and panel managers increasingly ask, but check your own policy rather than assuming it is mandatory.