How MSPs should respond to client cyber insurance questionnaires

Insurers are asking harder questions of MSPs. What they look for, which answers get better terms, and how to build a reusable evidence pack for renewal season.

Cyber insurance questionnaires have become the defining commercial moment for UK MSPs. Your client's broker sends across a 60-question form, asks you to fill out the security side, and then either signs the renewal or doesn't.

The questionnaire isn't a friendly favour any more. It's the proof gate. This is how MSPs should handle it without burning evenings, losing deals, or giving away free unbillable work.

Why are clients asking MSPs to fill in cyber insurance questionnaires now?

Three things changed in the last two years.

First, insurer loss ratios on UK SME cyber policies got ugly enough that most carriers tightened underwriting. Beazley, Hiscox, AIG, Travelers all rewrote their proposal forms in 2023 and 2024 to ask sharper, more technical questions. Your client used to get a 10-question form. Now they get 50 to 80.

Second, the questions stopped being check-box and became evidence-led. "Do you have MFA?" became "What percentage of privileged accounts have phishing-resistant MFA, and how is that measured?" That's not a question a non-technical CEO can answer.

Third, the broker market consolidated, and the broker now has commercial pressure to verify the answers. If they accept a wrong answer and the client claims, the broker is on the hook. So the broker pushes the questionnaire to the MSP.

That's why the questionnaire arrived in your inbox. It's the broker outsourcing the underwriting work because they don't have the technical knowledge in house. Treating it as anything else gets you the wrong answer.

(This is what the Assurix Trustmark does at the platform level. It provides a live, dated, third-party verified record that maps directly to the kinds of evidence insurers ask for, so you and your client can hand it over once and be done. Assurix chases the per-insurer answers each year so you don't have to.)

What does a typical cyber insurance questionnaire actually ask for?

Most questionnaires now cluster into 6 areas. Get familiar with all 6 because they show up everywhere with slight rewording.

  1. Identity and access controls. MFA on email, VPN, RMM, PSA, admin accounts, customer admin accounts. Phishing-resistant MFA is increasingly asked for separately. Privileged Access Management. Joiner-mover-leaver process timing.
  2. Endpoint protection and EDR. Coverage percentage, vendor name, alert response SLA, who responds, whether it's monitored 24/7.
  3. Patching and vulnerability management. Critical patch SLAs, internal vs perimeter scanning frequency, exception management.
  4. Backup and recovery. Immutable backups, offsite copies, last test date, RTO and RPO, segregation of backup admin from production admin.
  5. Email and phishing controls. SEG, DMARC enforcement (not monitor), simulated phishing, training programme.
  6. Incident response and governance. Documented IR plan, last tabletop exercise, breach notification process, supplier risk register.

You won't see every category in every questionnaire, but you'll see most. Build your master answer library around these 6 buckets and 80% of any future questionnaire is already drafted.

The trick is structure. The first MSP to learn this lesson the hard way ends up with a 40-page Word document that nobody can find anything in. The MSP that does it right keeps the answers in a single source of truth, mapped to the evidence that backs each one.

(The Assurix platform organises this for you. Every control answer is linked to the specific live evidence behind it, pulled from your existing PSA, RMM, and security tools. So the answer to "what's our patching SLA" is a current number with the underlying data attached.)

Score your insurance answer readiness

12 questions. 5 minutes. See where your MSP stands.

Score your insurance answer readiness

How do you build a master answer library that doesn't rot by year 2?

Most MSPs build the library wrong the first time. They take the first big questionnaire that lands, save the completed Word doc into a SharePoint folder labelled "client questionnaires," and reuse it. Six months later the answers are out of date, the technician who wrote them has left, and the new technician adds a slightly different answer to a new questionnaire because they couldn't find the old one.

Three rules to avoid this.

Rule 1: One library, one structure

The library lives in one place, organised by the 6 question categories above. Not 40 client folders with 40 versions. One canonical source of truth, owned by one named person.

Rule 2: Every answer has a date and an owner

"Patching SLA: 14 days for critical, last reviewed 2026-04-15 by Sam Lewis." If the answer is older than 6 months and unreviewed, it gets flagged. If the owner has left the business, the next owner has to confirm the answer before it goes out.

Rule 3: Answers reference evidence

Don't write "we have MFA on all admin accounts." Write "MFA enforced on all admin accounts via Conditional Access policy CAP-007, evidence: M365 Conditional Access export from 2026-04-12." When a sceptical broker pushes back, you don't have to dig. The evidence reference is right there.

The brief from a senior security buyer at a London architectural practice last year was specific: "I don't want a marketing answer. I want the date the policy was last tested and the name of the person who tested it." That's the bar.

(The Assurix platform is built around this exact pattern. The policies, the evidence, the date stamps, the owners are the unit of work in the platform, not a thing you bolt on. Any control answer carries its own audit trail.)

Should MSPs charge clients for filling in their questionnaire?

Yes, with one exception.

Big-picture, the answer is yes for new business and yes for renewal-driven questionnaires that arrive outside your standard service description. The work is non-trivial. A 60-question proposal form done properly takes 4 to 8 hours of senior engineering time, plus review. If you're not charging, you're absorbing roughly £500 to £1,200 per client per year in unbillable work.

The exception is the first questionnaire after onboarding a new client, where you cover the cost as part of the win. Anything after that, you bill.

The way to bill it without friction is to scope it as a defined, named line item in your service description. "Annual cyber insurance evidence pack: included for clients on the Premium tier, £750 fixed fee for clients on Standard." Now it's a fee with a named output, not a surprise invoice.

The dual benefit: the named line item also frames the evidence pack as a thing of value, which makes the Premium tier look better. Two MSPs we work with at Assurix moved 30 to 40 percent of their book up a tier on the back of including the evidence pack as the differentiator.

What does good look like when a broker pushes back?

The broker push-back arrives roughly 30 percent of the time on a properly completed questionnaire. It's usually a single email that says "your client's underwriter has a follow-up question on point 17."

There are three response levels.

Level 1: The answer is in the library and current

Reply within one working day. Quote the answer. Attach the evidence reference. Done.

Level 2: The answer was correct when written but the policy has shifted

Update the library, reply within 2 working days with the new answer, flag the change to the client so they know what was updated. This is normal. The library is supposed to evolve.

Level 3: The answer reveals a gap

This is the meaningful one. The questionnaire surfaces a control you don't currently have or aren't currently enforcing. There are two correct moves: don't lie, and don't panic. Be honest about the current state, explain the remediation timeline (4 to 12 weeks for most controls), and turn the gap into a billable improvement project.

The gap conversation is one of the highest-return commercial moments an MSP gets. The broker exposed a weakness, the client now knows about it, and you can scope a project to close it. That's not a problem, that's a deal.

(The Assurix Trustmark gives you the gap analysis ahead of time, so you find the weakness before the questionnaire does. Continuous monitoring catches drift between annual audits, which is when most gaps actually open up.)

How often should the answer library be reviewed?

Quarterly is the floor, monthly is realistic for any answer that ties to a metric that moves.

The four metric-linked categories that move every month:

Rev them monthly. Park the rest on a quarterly cycle. Schedule a 30-minute review meeting between the head of operations and the head of security. Two of you, calendar locked, no agenda surprise.

If those reviews keep slipping, the questionnaire library will rot, and you'll find out when the next big questionnaire lands and you have to start from scratch. The rot is silent until it's not.

How do you turn the questionnaire process into a sales tool?

Most MSPs see the questionnaire as a tax. Reframe it.

A completed, current, evidence-backed answer library is a sales asset. It demonstrates operational maturity, it's specific, it's defensible, and it's something most of your competitors don't have.

The play is simple. When a prospect mentions cyber insurance in a sales conversation, and after 2024 they all do, pull up your answer library on screen. Walk them through one section. Show them how an answer connects to live evidence. The implicit message: "This is what working with us looks like. Your insurer questions become our problem."

That single 3-minute walkthrough closes more deals on price than any other piece of sales theatre we've seen at Assurix.

For a first-meeting hook, you can also offer the prospect a free review of their existing insurance questionnaire response. Most of them have a thin one and they know it. The review is short, it's high-value, and it surfaces gaps that make your replacement bid easy to defend.

(The Proof Gap Scorecard gives you a shorter version of the same play. 12 questions, takes a prospect 2 minutes, surfaces a benchmark score and a one-page report. Try it: take the free scorecard)

Frequently asked questions

Should we sign a non-disclosure before sharing our questionnaire library with a prospect?

No. Non-disclosure on a sales asset means it's not really an asset. Share confidently. The library is a competitive advantage you should be using actively.

What if a prospect's broker uses a non-standard questionnaire format?

Map it back to your 6-category structure and answer per category. Most non-standard questionnaires are a different layout of the same questions.

Do we have to answer every question?

No. If a question doesn't apply, say so and explain. "Not applicable, client environment is fully cloud-based, evidence on request" is a legitimate answer.

What if the client asks us to lie?

Don't. The MSP is named on the proposal form. If the policy is invoked and the answer was wrong, the insurer will take it up with the MSP, not the client. There's no upside.

How much does a full evidence pack take to build the first time?

Around 40 to 80 hours over 4 to 6 weeks for a 50-client MSP, depending on how mature the existing documentation is. After that, 4 to 8 hours per quarter for upkeep.

The closing principle

Either way, the principle is the same. Build the library. Anchor every answer to live evidence. Charge for the work. The fastest path is to stop building it yourself, and let a Trustmark do the answering for you. That's what Assurix is for.

Score your insurance answer readiness

12 questions. 5 minutes. See where your MSP stands.

Score your insurance answer readiness

Related reading