Cyber Insurance Implementation Case Study

A 38-person property management firm, a renewal questionnaire that landed like a subpoena, and 90 days of unglamorous fixes that kept the policy bound.

By , CTO · Published · Last updated

TL;DR

  • A 38-person commercial property management firm in the Pacific Northwest got a renewal questionnaire demanding affirmative answers on 14 of 18 controls, or denial.
  • The MSP claimed coverage on most of it. The tenant audit said otherwise: 3 user MFA exclusions, admin accounts on app-password fallback, legacy auth wide open.
  • 90 days of work, roughly $22K total cost, organized into four arcs: triage, deeper fixes, tabletop, documentation.
  • Renewal bound at a 7% premium increase. The carrier said it would have been 38% or denial without the remediation. Deductible dropped from $25K to $10K.
  • Five things they would do differently next year, every one of them about timing, evidence, and treating the questionnaire as the new baseline rather than a one-time sprint.

A note on who this is

The firm in this case study is a composite. The shape of the company, the timeline, the dollar figures, the controls, and the missteps are drawn from real engagements, but the specifics have been blurred so no actual client is identifiable. Treat it as a representative arc rather than a single business. The point is the pattern.

The composite: a 38-person commercial property management firm in the Pacific Northwest. Roughly $14M in annual revenue. Two offices. M365 Business Premium licenses for everyone. One internal IT generalist who reports to the COO, plus a managed services provider (MSP) on a fixed monthly contract. They had been buying cyber insurance for four years on what amounted to a checkbox application. Last January, that ended.

The trigger: a questionnaire that did not fit on one page

On day one, the broker forwarded the renewal application from the carrier. It was 18 questions long, organized into six sections: identity and access, email security, endpoint, backups, logging and monitoring, and incident response. The cover note from the underwriter was direct: 14 of 18 questions had to come back as affirmative, with documentation, or the account would be non-renewed.

Last year's policy was issued on a four-question short form. This year the same carrier wanted granular evidence. MFA was no longer "yes or no." It was now: Is MFA enforced for all users including admins? Is it phishing-resistant? Are there exclusions and if so why? Can you produce a Conditional Access policy export?

The owner read the questionnaire twice and called the broker. The broker's reading: this carrier had taken several ransomware losses in the prior renewal cycle and was now using questionnaires the way a lender uses tax returns. Fudging answers was not a viable strategy. The carrier reserved the right to rescind coverage at claim time if the questionnaire turned out to be inaccurate.

That was the day the project started. The policy expired in 90 days. The full text of what underwriters now expect is in our cyber insurance requirements for 2026 guide. This case study is what it looks like when those requirements meet a real tenant for the first time.

Day 1 to 7: the gap analysis nobody enjoys

The owner's first move was to call the MSP. The MSP's first answer was reassuring: "We cover most of that." The owner asked for evidence. The MSP asked what kind of evidence. The owner forwarded the questionnaire.

A week of read-only auditing followed, with the MSP and an outside reviewer looking at the same tenant in parallel. The two reports did not match. The MSP's report said MFA was on. The outside review said MFA was on for 35 of 38 users, with three hard exclusions baked into a Conditional Access policy from 2023. One of the three was the company's outside controller. Another was a sales VP who had complained about the prompt and gotten a permanent pass. The third was a service account nobody could remember creating.

The pattern repeated across the questionnaire. Admin accounts: three of the four global admins had no separate sign-in, and two of them had been using app-password fallback to keep an old PowerShell script working. Legacy authentication: enabled. SMTP AUTH: enabled tenant-wide. DMARC: published at p=none, which is the same as not having DMARC for enforcement purposes. Audit log retention: 90 days, the default. The questionnaire wanted 365.

Stepping back from the specifics, the lesson was unambiguous. "We have MFA" did not survive a real audit. Nothing in the MSP's monthly report had ever lied. The report just answered narrower questions than the underwriter was now asking. The owner stopped asking the MSP for assurances and started asking for screenshots, exports, and policy IDs.

Day 7 to 30: the triage list

With a real gap list in hand, the team built a triage. Not everything could be fixed before renewal, and trying to do it all at once was a recipe for breaking the business. The rule of thumb: fix the controls that, if missing, would cause an outright denial. Defer the controls that would only affect pricing.

Four items moved into the must-fix-this-month bucket. First, MFA on the three excluded users. The controller agreed in 24 hours. The service account was retired (it had not been used in eight months). The sales VP refused. He told the IT generalist that he was "the reason the company has revenue" and was not interested in a six-second prompt. The IT generalist escalated to the owner. The owner overruled the VP in a five-minute conversation and the exclusion came off that afternoon. Worth flagging: the technical fix was trivial. The political fix was the actual blocker, and it almost always is.

Second, blocking legacy auth. The MSP set up a Conditional Access policy in report-only mode for a week, then enforced it. Two scanners broke immediately. They were the older ones in the back office, sending scan-to-email via SMTP AUTH with a shared mailbox password. The fix was an SMTP relay connector with IP allow-listing. Total elapsed time, including testing: four days. The teardown of how to do this without breaking line-of-business apps is in our companion piece on M365 security implementation, which walks the deployment from the technical side rather than the insurance side.

Third, separating admin accounts. Four new admin sign-ins were created, each tied to a daily-driver account but with its own credentials, its own MFA registration, and PIM eligibility for the sensitive roles. The daily-driver accounts had their global admin roles stripped. The transition took an afternoon plus a week of "wait, my admin center isn't loading" tickets, which all turned out to be people forgetting which account they were signed in as.

Fourth, documenting an incident response plan. They started from a 12-page template, customized it to the actual business in two days, and printed copies for the leadership team. It was not a great IR plan. It was a real one, with names, phone numbers, decision authority, and a simple flow: who calls whom in the first hour, the first day, the first week. Good enough for the questionnaire and good enough to test in the tabletop later.

Day 30 to 60: the deeper fixes

With the denial-class items closed, the team turned to the controls that would shape pricing rather than approval. These took longer because they touched outside vendors and end-user behavior, not just tenant settings.

Defender for Office 365 came first. Safe Links and Safe Attachments rolled out in the standard preset. Anti-phishing thresholds were raised to "aggressive" for the executive group and "standard" for everyone else. The aggressive setting generated three false positives in the first week, all from a vendor whose marketing emails had spoofy headers. The fix was a tenant allow-list entry for that sender domain. After two weeks the queue stabilized.

DMARC was the slowest single project of the 90 days. The firm had three third-party senders: a property-listing platform, a payroll vendor, and a CRM that sent appointment confirmations. Each one had to be onboarded into DMARC alignment with its own SPF includes and DKIM signing. The CRM vendor took two weeks to respond to support tickets. The full sequence is in our writeup on the cyber insurance compliance checklist for property and casualty exposures. Total elapsed time to move from p=none through p=quarantine: four weeks.

Audit log retention was extended from 90 days to 365 days at the tenant level. This is a single setting, but it changes what is provable after a breach. If an attacker dwells for 120 days before being detected, a 90-day retention window means the early activity is gone. The carrier's questionnaire was specific: 365 days minimum, with the ability to export.

Sensitivity labels rolled out for "Confidential" content with auto-classification on contract documents stored in the leasing SharePoint site. The auto-classify rule used keyword matches on the standard property management contract templates. It worked on 80% of documents on the first pass and required tuning for the rest. By day 60, the rollout was about 70% complete, which would matter at submission time.

The phishing simulation was the most uncomfortable part for the staff. A baseline run on day 35 produced a 32% click rate. The leadership group's number was 41%. After 60 days of biweekly simulations and short, targeted training tied to each person's clicks, the click rate dropped to 8%. The aggregate number was the one the carrier wanted to see. The per-person trend was what the leadership team kept on their own dashboard. MFA's role in containing a successful click is covered separately in the worksheet on how to answer the MFA section of a 2026 questionnaire, which is also why the questionnaire weighted MFA so heavily even though phishing is the dominant attack path.

Day 60 to 80: the tabletop nobody scheduled until late

The tabletop exercise was originally on the schedule for day 85. It got moved up to day 65 because the IR plan needed to be tested before the questionnaire was submitted. In hindsight it should have been day 5.

The format was modest: 90 minutes, leadership team plus the MSP plus an outside IR vendor on a flat-fee retainer. The scenario was a credible one for the firm: a tenant compromise that exfiltrates lease documents and sends extortion emails to two of the firm's biggest property owners. The facilitator walked the group through the first 24 hours.

Three gaps surfaced that the IR plan had not addressed. There was no playbook for who notifies customers, and whether the notification went over email, phone, or letter. There was no decision authority for ransom payments. The IR plan said "the executive team decides" without naming who held the actual authority if the CEO was unreachable. And there was no documented escalation when the IT contact was on vacation, which was a real scenario since the IT generalist took two weeks off every August.

The fixes were three pages added to the IR plan and one offline contact list printed for the leadership team's home use. The bigger lesson was sequencing. Running the tabletop earlier would have changed the remediation priority: the team would have spent less time on Defender tuning and more time on customer-notification templates. Worth keeping in mind for next year.

Day 80 to 90: building the evidence package

The questionnaire was due on day 90. The submission package came in at 47 pages. It was assembled in a single shared folder and exported as a PDF for the broker.

The contents, in order:

  • A cover letter from the owner attesting to the answers.
  • The completed questionnaire with section-by-section references to the supporting evidence.
  • Conditional Access policy exports for MFA and legacy auth (12 pages).
  • A sign-in audit showing zero successful legacy auth sign-ins in the prior 30 days.
  • Admin role assignments showing separation.
  • DMARC TXT records and a one-week aggregate report from the DMARC monitoring tool.
  • Training completion records by user.
  • The phishing simulation trend.
  • The IR plan and the tabletop summary.
  • Backup configuration and the most recent restore test result.
  • Sensitivity label deployment status, with the gap noted explicitly.

One control was incomplete at submission: the sensitivity-label rollout was at 70% rather than the 100% the questionnaire implied. The broker arranged a 20-minute pre-call with the underwriter. The owner walked through what was done, what remained, and the timeline (full rollout by day 120). The underwriter accepted an "intent to remediate" letter for the gap, on the condition that proof of completion be submitted within 60 days of binding. That condition went into the binder as a warranty.

The pre-call mattered. Submitting a 47-page package without context invites adversarial reading. Submitting it after a conversation invites a cooperative one. The broker understood this. The owner did not, until the broker explained it on day 78. Worth doing again next year, even if the answers are all clean.

For the underwriter-facing version of this story (the controls listed in the order carriers ask about them), see our cyber insurance renewal checklist. It is the artifact this firm wished they had on day one instead of day 60.

The outcome: bound, with conditions

The renewal was approved on day 95, five days after submission, with the warranty on the sensitivity-label completion. The premium went up 7%. The carrier's note in the binder said the increase reflected the firm's risk profile relative to the prior year and that, absent the remediation, the carrier had been prepared to either non-renew or quote at 38% above expiring with a $50K retention.

Sub-limits moved in the firm's favor. The deductible came down from $25K to $10K because of the MFA enforcement and the documented IR plan. Social engineering coverage went up from $100K to $250K in sublimit. Business email compromise, which had been a flat exclusion the prior year, was added back at $250K.

Total cost of the 90-day project: roughly $22K. About $8K of that was MSP labor billed against the existing contract's flex-time bank. Roughly $14K was deferred-deployment work (DMARC onboarding, sensitivity labels, phishing simulation tooling, the outside IR vendor's tabletop fee) that had been on the IT roadmap for two years and finally got pulled forward by the renewal pressure. None of it was wasted spend. Most of it would have been spent in the next 12 months anyway. The renewal just compressed the timeline.

Five things they would do differently next year

The owner and the IT generalist did a 30-minute debrief in week 14. Five lessons came out of it. None of them are surprising in hindsight. All of them were surprising on day one.

1. Start six months out, not 90 days. The 90-day window made every decision tactical. A six-month window would have allowed the tabletop to drive the remediation priority instead of the other way around. It would also have given the DMARC vendor onboarding time to finish without rushing third-party senders.

2. Make the MSP demonstrate evidence, not assert it. Every "we have it" claim needs a screenshot, a policy export, or a sign-in log entry behind it. The MSP was not lying. The MSP was answering an easier question than the carrier was asking. Closing that gap is the single highest-value habit to establish before next renewal.

3. Document in real time. Most of the 47-page evidence package was reconstructed in the last 10 days. Roughly 30% of those 10 days went to "where did we save the screenshot of the Conditional Access policy on day 22?" A simple shared folder labeled by control, populated as work happens, would have saved a week.

4. Run the tabletop first, not last. The tabletop on day 65 surfaced gaps that, had they been known on day 5, would have changed which Defender features got tuned and which IR contacts got documented. The tabletop is not a victory lap. It is a discovery tool, and discovery tools belong at the start.

5. Treat this as the new baseline, not a one-time sprint. The questionnaire next year will likely add three to five new questions, drop none, and want fresher evidence on the existing ones. The internal calendar now has quarterly checkpoints: legacy auth audit, admin account review, DMARC reports, phishing simulation, tabletop refresher. Whether to handle that drumbeat in-house or contract for it is its own decision. We have a side-by-side on managed M365 security versus DIY that lays out the tradeoffs at this size.

Common questions

Was the 7% premium increase a good outcome?

In the broker's read, yes. The mid-market book at this carrier saw an average renewal increase of 14% in the same quarter, and roughly 1 in 5 accounts received a non-renewal notice. The 38-person firm landed below the average increase, with no sublimit reductions and an improved deductible. A flat renewal would have been better, but an increase below market with sublimit improvements was the best realistic outcome given where the controls started.

Why didn't the MSP catch these gaps before the questionnaire arrived?

The MSP's contract was scoped to keep the tenant running, not to answer underwriter questions. Their monthly reports tracked uptime, ticket volume, patch compliance, and license counts. None of those reports asked "is MFA enforced for every sign-in including admins?" or "is legacy auth blocked at the tenant level?" The questions are different, so the answers are different. After this engagement the firm asked the MSP to add an annual insurance-readiness audit to the contract. The MSP agreed at a small fee bump.

How much of this depends on having M365 Business Premium versus a lower SKU?

Most of it depends on Business Premium or above. Conditional Access requires Entra ID P1, which is bundled in Business Premium. Defender for Office 365 Plan 1, sensitivity labels, and Intune are all in the same SKU. A firm on Business Standard would have to add per-user add-ons to reach feature parity, and the math usually pushes them to Business Premium anyway. The questionnaire does not care which SKU you bought. It cares whether the controls are running.

What if our policy renewal is in 30 days, not 90?

Talk to the broker first about a short extension. Carriers will sometimes grant 30 to 60 days on a current policy if the broker can show a credible remediation plan in writing. If an extension is not available, focus on the four denial-class controls in the day 7 to 30 section: MFA on every user, separated admin accounts, legacy auth blocked, IR plan documented. Submit those with evidence and an "intent to remediate" letter for the rest. It is a worse outcome than a full 90-day plan, but it is a much better outcome than letting the policy lapse.

Did the firm consider switching carriers instead of remediating?

Yes, briefly. The broker shopped three other carriers in week 2. Two of them had functionally identical questionnaires. The third had a shorter questionnaire but a higher base premium and a $50K retention. The math came out the same: the controls had to be deployed regardless of which carrier wrote the policy. Switching carriers to avoid remediation is increasingly not an option in the small-business market. The question is which carrier's submission process is least painful, not whether there is a carrier that does not ask.

Get the free Insurance Readiness Checklist

No spam. Unsubscribe anytime.

See If Your Tenant Is Coverage-Ready

Run the free risk check. The output is the same kind of evidence the firm in this case study wished they had on day one: which controls are in place, which are gaps, and which questions on the renewal questionnaire would come back affirmative today.

Check My Risk