Skip to main content
[MSP Playbook]_

How to Take Your Clients Through Cyber Insurance

A practitioner guide for MSPs, MSSPs, and vCISO practices: what underwriters commonly check, when to raise it with clients, and where your role ends and a regulated broker's begins.

Why It's Your Conversation Now

Clients Are Already Being Asked About This

Cyber insurance proposal forms now routinely ask about MFA, backups, and incident response — the same controls you already track for your clients. When a client's renewal comes up, many will ask their MSP first, before they ask a broker. This playbook is what to know before that conversation happens.

The Basics

Cyber Insurance in Two Minutes

You don't need to be an insurance expert to have this conversation. Four terms cover most of what comes up.

First-party costs

Costs the client incurs directly from an incident — incident response, forensics, notification, and business interruption are commonly included.

Third-party liability

Claims from customers, partners, or regulators arising from the incident — for example a data breach affecting client data.

Exclusions

Specific scenarios a policy won't pay out for. Exclusions vary by insurer and often tie back to control gaps disclosed — or not disclosed — on the proposal form.

Proposal-form accuracy

What the client tells the insurer about its controls at application. Inaccurate answers are a common reason insurers dispute or reduce a claim later.

Step 1

What Underwriters Commonly Check

Individual questions vary by insurer, but these six areas show up on most proposal forms. Track them and you're tracking what most renewal conversations will touch.

Multi-factor authentication

What underwriters ask
Proposal forms commonly ask whether MFA is enforced on email, remote access (VPN/RDP), and admin accounts.
Evidence to keep
An export from the identity provider showing the MFA enforcement policy and the date it was switched on.
Claim risk if missing
If MFA was missing on the account involved in an incident, insurers may treat the proposal-form answer as inaccurate — which can complicate a claim.

Endpoint detection and response (EDR/MDR)

What underwriters ask
Whether endpoints — not just servers — are covered by continuous monitoring, and whether alerts are actually triaged.
Evidence to keep
Coverage reports from the EDR/MDR console and a note on who reviews alerts and how quickly.
Claim risk if missing
Underwriters commonly view unmonitored endpoints as a gap in reasonable care, which can affect how a claim is assessed.

Immutable or offline backups, with tested restores

What underwriters ask
Whether backups are isolated from the production network and whether restores have actually been tested.
Evidence to keep
Backup configuration showing immutability/air-gapping, plus dated records of restore tests.
Claim risk if missing
A backup that ransomware could also encrypt is often not treated as an effective backup by underwriters or by the client when they need it.

A written, exercised incident response plan

What underwriters ask
Whether a documented IR plan exists, who owns it, and whether it has been tested — not just written and filed.
Evidence to keep
The IR plan document, sign-off from leadership, and dates of the last tabletop exercise.
Claim risk if missing
Without a tested plan, insurers may argue response costs were higher than necessary, which can complicate a claim.

Patch and vulnerability management

What underwriters ask
How quickly known exploited vulnerabilities are patched, especially on internet-facing systems.
Evidence to keep
Patch cadence records and a vulnerability scan history for exposed systems.
Claim risk if missing
A known, unpatched vulnerability that was exploited is a factor insurers may point to when disputing or reducing a claim.

Email security and phishing awareness

What underwriters ask
Whether email filtering (SPF/DKIM/DMARC), attachment controls, and staff phishing training are in place.
Evidence to keep
Email security configuration and training completion records.
Claim risk if missing
Credential theft via phishing is a common entry point in the incidents underwriters review, so training gaps may be raised during a claim.

Sources: CISA #StopRansomware Guide (backups, MFA, patching, EDR, and incident response planning); ICO guidance on reporting a personal data breach. Individual insurer requirements vary — always confirm specifics with New Dawn Risk or the client's insurer.

Step 2

A Renewal Timeline You Can Reuse

Renewal season doesn't have to be a scramble. Working backward from the renewal date gives every client the same predictable checklist.

1

90 days before renewal

Run a readiness check

Pull the client's current posture against the controls underwriters commonly ask about. Flag gaps early — there's still time to close them before the proposal form is due.

2

60 days before renewal

Close the gaps that matter most

Prioritise fixes with the client — MFA and backup gaps are usually quicker to close than a full IR-plan rebuild. Document what changed and when.

3

30 days before renewal

Prepare the evidence pack

Gather the evidence for each control so the proposal form can be answered accurately. Introduce the client to New Dawn Risk if they want to discuss cover or a review.

4

After renewal

Keep the evidence current

Posture drifts between renewals. A short quarterly check keeps the evidence pack ready for next year instead of a scramble the week before.

Step 3

Starting the Conversation With Clients

You don't need a sales pitch. Four questions open the topic naturally, at the point in the relationship where it's most useful.

"When does your cyber policy renew, and who's completing the proposal form?"

Opens the door without pitching anything — most clients don't know their renewal date offhand, and it puts you in the room for the next step.

"Have your controls changed since the last renewal?"

Prompts the client to think about MFA, backups, and IR plan status — the areas most likely to have drifted.

"Do you know what your current policy actually excludes?"

Many clients have never read their exclusions. This is also the natural lead-in to mentioning a silent review.

"If an insurer asked for evidence tomorrow, could you produce it?"

Surfaces whether evidence is scattered across tools and people, or ready to hand over — usually the real gap.

Know the Boundary

Your Role vs. the Broker's Role

Being useful in this conversation means knowing exactly where your part ends. New Dawn Risk, an FCA-regulated Lloyd's broker, picks up everything regulated.

Your role as the MSP

  • Track and evidence the controls underwriters commonly ask about across your managed clients.
  • Help clients close control gaps ahead of renewal, with dated evidence of what changed.
  • Introduce clients to New Dawn Risk when they want to discuss new cover or a review of existing cover.
  • Stay out of regulated advice — no quoting, arranging, or binding. That line belongs to the broker.

New Dawn Risk's role as the broker

  • Give regulated advice on cover, exclusions, and suitability for the client's risk profile.
  • Arrange and place policies across the Lloyd's market as an FCA-regulated broker.
  • Run silent reviews of existing policies without notifying the incumbent insurer.
  • Support clients through the claims process when something goes wrong.
For Existing Policyholders

What a Silent Review Actually Is

Not every client is shopping for new cover — many already have a policy. A silent review is an independent look at that existing policy by New Dawn Risk, checking whether the coverage still matches the client's current risk profile, without notifying the incumbent insurer. It's a useful option to mention for clients who haven't reviewed their cover in a while, or whose environment has changed materially since they last bought it.

Insurance Partner

GetCybr + New Dawn Risk

In partnership with

This playbook covers the controls-readiness side of the conversation. Regulated insurance advice and policy placement is handled by New Dawn Risk, our FCA-regulated Lloyd's broker partner.

GetCybrNew Dawn Risk — FCA-regulated Lloyd's broker

GetCybr is an introducer only and is not authorised or regulated by the Financial Conduct Authority. GetCybr does not provide regulated insurance advice and does not quote, arrange, or bind policies. Insurance services are provided by New Dawn Risk, an FCA-regulated Lloyd's broker. All regulated advice and policy arrangement is carried out by New Dawn Risk.

Help Center

FAQs have moved to the Help Center

Find current answers for the topics covered on this page in our consolidated FAQ.

Introducer disclaimer: GetCybr is an introducer only and is not authorised or regulated by the Financial Conduct Authority. GetCybr does not provide regulated insurance advice and does not quote, arrange, or bind policies.

Insurance provider: Insurance services are provided by New Dawn Risk, an FCA-regulated Lloyd's broker. All regulated advice and policy arrangement is carried out by New Dawn Risk.

General disclaimer: This page is for informational purposes only and does not constitute insurance advice, a quote, or a guarantee of cover. Insurance eligibility is determined by New Dawn Risk and its underwriting partners.

Cyber Intelligence Digest

Stay Ahead of Renewal Season

Get weekly vCISO and insurance-readiness insights for MSPs — control mapping tips, underwriter checklists, and renewal-prep guidance.

No spam. Unsubscribe anytime.

Ready to Run This With Your Clients?

See how GetCybr tracks the controls in this playbook across your managed clients, so the evidence is ready before renewal season starts.