How to Take Your Clients Through Cyber Insurance
A practitioner guide for MSPs, MSSPs, and vCISO practices: what underwriters commonly check, when to raise it with clients, and where your role ends and a regulated broker's begins.
Clients Are Already Being Asked About This
Cyber insurance proposal forms now routinely ask about MFA, backups, and incident response — the same controls you already track for your clients. When a client's renewal comes up, many will ask their MSP first, before they ask a broker. This playbook is what to know before that conversation happens.
Cyber Insurance in Two Minutes
You don't need to be an insurance expert to have this conversation. Four terms cover most of what comes up.
First-party costs
Costs the client incurs directly from an incident — incident response, forensics, notification, and business interruption are commonly included.
Third-party liability
Claims from customers, partners, or regulators arising from the incident — for example a data breach affecting client data.
Exclusions
Specific scenarios a policy won't pay out for. Exclusions vary by insurer and often tie back to control gaps disclosed — or not disclosed — on the proposal form.
Proposal-form accuracy
What the client tells the insurer about its controls at application. Inaccurate answers are a common reason insurers dispute or reduce a claim later.
What Underwriters Commonly Check
Individual questions vary by insurer, but these six areas show up on most proposal forms. Track them and you're tracking what most renewal conversations will touch.
| Control | What underwriters ask | Evidence to keep | Claim risk if missing |
|---|---|---|---|
| Multi-factor authentication | Proposal forms commonly ask whether MFA is enforced on email, remote access (VPN/RDP), and admin accounts. | An export from the identity provider showing the MFA enforcement policy and the date it was switched on. | If MFA was missing on the account involved in an incident, insurers may treat the proposal-form answer as inaccurate — which can complicate a claim. |
| Endpoint detection and response (EDR/MDR) | Whether endpoints — not just servers — are covered by continuous monitoring, and whether alerts are actually triaged. | Coverage reports from the EDR/MDR console and a note on who reviews alerts and how quickly. | Underwriters commonly view unmonitored endpoints as a gap in reasonable care, which can affect how a claim is assessed. |
| Immutable or offline backups, with tested restores | Whether backups are isolated from the production network and whether restores have actually been tested. | Backup configuration showing immutability/air-gapping, plus dated records of restore tests. | A backup that ransomware could also encrypt is often not treated as an effective backup by underwriters or by the client when they need it. |
| A written, exercised incident response plan | Whether a documented IR plan exists, who owns it, and whether it has been tested — not just written and filed. | The IR plan document, sign-off from leadership, and dates of the last tabletop exercise. | Without a tested plan, insurers may argue response costs were higher than necessary, which can complicate a claim. |
| Patch and vulnerability management | How quickly known exploited vulnerabilities are patched, especially on internet-facing systems. | Patch cadence records and a vulnerability scan history for exposed systems. | A known, unpatched vulnerability that was exploited is a factor insurers may point to when disputing or reducing a claim. |
| Email security and phishing awareness | Whether email filtering (SPF/DKIM/DMARC), attachment controls, and staff phishing training are in place. | Email security configuration and training completion records. | Credential theft via phishing is a common entry point in the incidents underwriters review, so training gaps may be raised during a claim. |
Multi-factor authentication
- What underwriters ask
- Proposal forms commonly ask whether MFA is enforced on email, remote access (VPN/RDP), and admin accounts.
- Evidence to keep
- An export from the identity provider showing the MFA enforcement policy and the date it was switched on.
- Claim risk if missing
- If MFA was missing on the account involved in an incident, insurers may treat the proposal-form answer as inaccurate — which can complicate a claim.
Endpoint detection and response (EDR/MDR)
- What underwriters ask
- Whether endpoints — not just servers — are covered by continuous monitoring, and whether alerts are actually triaged.
- Evidence to keep
- Coverage reports from the EDR/MDR console and a note on who reviews alerts and how quickly.
- Claim risk if missing
- Underwriters commonly view unmonitored endpoints as a gap in reasonable care, which can affect how a claim is assessed.
Immutable or offline backups, with tested restores
- What underwriters ask
- Whether backups are isolated from the production network and whether restores have actually been tested.
- Evidence to keep
- Backup configuration showing immutability/air-gapping, plus dated records of restore tests.
- Claim risk if missing
- A backup that ransomware could also encrypt is often not treated as an effective backup by underwriters or by the client when they need it.
A written, exercised incident response plan
- What underwriters ask
- Whether a documented IR plan exists, who owns it, and whether it has been tested — not just written and filed.
- Evidence to keep
- The IR plan document, sign-off from leadership, and dates of the last tabletop exercise.
- Claim risk if missing
- Without a tested plan, insurers may argue response costs were higher than necessary, which can complicate a claim.
Patch and vulnerability management
- What underwriters ask
- How quickly known exploited vulnerabilities are patched, especially on internet-facing systems.
- Evidence to keep
- Patch cadence records and a vulnerability scan history for exposed systems.
- Claim risk if missing
- A known, unpatched vulnerability that was exploited is a factor insurers may point to when disputing or reducing a claim.
Email security and phishing awareness
- What underwriters ask
- Whether email filtering (SPF/DKIM/DMARC), attachment controls, and staff phishing training are in place.
- Evidence to keep
- Email security configuration and training completion records.
- Claim risk if missing
- Credential theft via phishing is a common entry point in the incidents underwriters review, so training gaps may be raised during a claim.
Sources: CISA #StopRansomware Guide (backups, MFA, patching, EDR, and incident response planning); ICO guidance on reporting a personal data breach. Individual insurer requirements vary — always confirm specifics with New Dawn Risk or the client's insurer.
A Renewal Timeline You Can Reuse
Renewal season doesn't have to be a scramble. Working backward from the renewal date gives every client the same predictable checklist.
90 days before renewal
Run a readiness check
Pull the client's current posture against the controls underwriters commonly ask about. Flag gaps early — there's still time to close them before the proposal form is due.
60 days before renewal
Close the gaps that matter most
Prioritise fixes with the client — MFA and backup gaps are usually quicker to close than a full IR-plan rebuild. Document what changed and when.
30 days before renewal
Prepare the evidence pack
Gather the evidence for each control so the proposal form can be answered accurately. Introduce the client to New Dawn Risk if they want to discuss cover or a review.
After renewal
Keep the evidence current
Posture drifts between renewals. A short quarterly check keeps the evidence pack ready for next year instead of a scramble the week before.
Starting the Conversation With Clients
You don't need a sales pitch. Four questions open the topic naturally, at the point in the relationship where it's most useful.
"When does your cyber policy renew, and who's completing the proposal form?"
Opens the door without pitching anything — most clients don't know their renewal date offhand, and it puts you in the room for the next step.
"Have your controls changed since the last renewal?"
Prompts the client to think about MFA, backups, and IR plan status — the areas most likely to have drifted.
"Do you know what your current policy actually excludes?"
Many clients have never read their exclusions. This is also the natural lead-in to mentioning a silent review.
"If an insurer asked for evidence tomorrow, could you produce it?"
Surfaces whether evidence is scattered across tools and people, or ready to hand over — usually the real gap.
Your Role vs. the Broker's Role
Being useful in this conversation means knowing exactly where your part ends. New Dawn Risk, an FCA-regulated Lloyd's broker, picks up everything regulated.
Your role as the MSP
- Track and evidence the controls underwriters commonly ask about across your managed clients.
- Help clients close control gaps ahead of renewal, with dated evidence of what changed.
- Introduce clients to New Dawn Risk when they want to discuss new cover or a review of existing cover.
- Stay out of regulated advice — no quoting, arranging, or binding. That line belongs to the broker.
New Dawn Risk's role as the broker
- Give regulated advice on cover, exclusions, and suitability for the client's risk profile.
- Arrange and place policies across the Lloyd's market as an FCA-regulated broker.
- Run silent reviews of existing policies without notifying the incumbent insurer.
- Support clients through the claims process when something goes wrong.
What a Silent Review Actually Is
Not every client is shopping for new cover — many already have a policy. A silent review is an independent look at that existing policy by New Dawn Risk, checking whether the coverage still matches the client's current risk profile, without notifying the incumbent insurer. It's a useful option to mention for clients who haven't reviewed their cover in a while, or whose environment has changed materially since they last bought it.
GetCybr + New Dawn Risk
In partnership with
This playbook covers the controls-readiness side of the conversation. Regulated insurance advice and policy placement is handled by New Dawn Risk, our FCA-regulated Lloyd's broker partner.

GetCybr is an introducer only and is not authorised or regulated by the Financial Conduct Authority. GetCybr does not provide regulated insurance advice and does not quote, arrange, or bind policies. Insurance services are provided by New Dawn Risk, an FCA-regulated Lloyd's broker. All regulated advice and policy arrangement is carried out by New Dawn Risk.
Help Center
FAQs have moved to the Help Center
Find current answers for the topics covered on this page in our consolidated FAQ.
Introducer disclaimer: GetCybr is an introducer only and is not authorised or regulated by the Financial Conduct Authority. GetCybr does not provide regulated insurance advice and does not quote, arrange, or bind policies.
Insurance provider: Insurance services are provided by New Dawn Risk, an FCA-regulated Lloyd's broker. All regulated advice and policy arrangement is carried out by New Dawn Risk.
General disclaimer: This page is for informational purposes only and does not constitute insurance advice, a quote, or a guarantee of cover. Insurance eligibility is determined by New Dawn Risk and its underwriting partners.
Stay Ahead of Renewal Season
Get weekly vCISO and insurance-readiness insights for MSPs — control mapping tips, underwriter checklists, and renewal-prep guidance.
No spam. Unsubscribe anytime.
Ready to Run This With Your Clients?
See how GetCybr tracks the controls in this playbook across your managed clients, so the evidence is ready before renewal season starts.