In This Article
The cyber insurance questionnaire on your desk is not a checkbox exercise anymore. Before a carrier binds or renews coverage for a bank, credit union, or mortgage company, it scores your security posture control by control, then prices the policy against what it finds. Miss a required control and you face a higher premium, a coverage sublimit, or a flat declination.
This shift happened fast. For years, cyber coverage was cheap and easy to buy. Then ransomware losses spiked, carriers tightened, and the application grew from one page into a multi-page controls audit. Today the questionnaire reads like an examiner checklist: multi-factor authentication, endpoint detection and response, immutable backup, privileged access management, logging, and a written incident response plan.
If your institution runs Microsoft 365, most of those controls are already sitting in your tenant, waiting to be configured. This guide maps the security controls a carrier scores to the specific Microsoft product that satisfies each, and it is honest about the one place Microsoft 365 falls short. That place is backup, it is where a bank, credit union, or mortgage company most often gets tripped up at renewal, and it is fixable.
Cyber Coverage Became a Controls Exam, Not a Checkbox
Cyber premiums actually fell in 2024, but do not read that as the market going soft on requirements. The opposite happened. Carriers cut prices for institutions that could prove strong controls and walked away from the ones that could not. The share of insurance clients electing cyber coverage climbed from 26 percent in 2016 to 47 percent in 2020, according to the U.S. Government Accountability Office, and it has kept rising since. More buyers, more competition, and far more scrutiny of the controls behind each application.
For a financial institution, the stakes are concrete. The average data breach in financial services costs $5.56 million, the second highest of any industry and about 25 percent above the $4.44 million global average, according to the IBM Cost of a Data Breach Report 2025. A carrier writing that risk wants evidence that you have made the controls that prevent those losses real and enforced, not aspirational.
The Shift Most Institutions Miss
Underwriting moved from actuarial tables to posture scoring. The controls you can demonstrate are now the single biggest input into whether you get bound, what you pay, and how much of a loss the carrier will actually cover. The questionnaire is the audit. Answering "in progress" on a required control reads, to an underwriter, the same as answering "no."
That reframing is the whole game. Once you treat the application as a controls audit rather than paperwork, the question stops being "how do we fill this out" and becomes "which of these controls do we actually have, and where is the evidence." For a Microsoft 365 shop, the answer to most of the list is closer than you think.
What Cyber Insurance Carriers Actually Require Now
There is no single national standard for cyber insurance requirements for financial institutions, but the industry has converged on a common list. Marsh, one of the largest insurance brokers, published twelve key controls that cyber insurers look for, and most carrier questionnaires now track closely to it.
- Multi-factor authentication for remote access and for privileged or administrator accounts
- Email filtering and web security
- Secured, encrypted, and tested backups, with at least one copy kept offline and disconnected
- Privileged access management
- Endpoint detection and response
- Patch and vulnerability management, with high-severity fixes in days rather than months
- A written incident response plan
- Cybersecurity awareness training and phishing testing
- Remote Desktop Protocol mitigation and hardening
- Logging and monitoring
- Replacement or protection of end-of-life systems
- Digital supply chain and vendor cyber risk management
Multi-factor authentication is control number one, and it is effectively mandatory. Carriers expect it enforced on remote and VPN access, on Remote Desktop Protocol, on administrator accounts, and on access to sensitive data. They increasingly want phishing-resistant MFA rather than text-message codes, because attackers have learned to intercept and social-engineer their way around one-time passcodes. If your questionnaire has hardened from "do you use MFA" to "what type of MFA," that is why, and it is worth understanding how phishing-resistant MFA works for financial institutions before you answer.
Not all twelve controls carry equal weight in the eyes of a carrier. When the Marsh McLennan Cyber Risk Intelligence Center analyzed which of those twelve industry-tracked controls actually reduce breach-driven insurance claims, in its August 2025 study, a clear top tier emerged.
Four controls were associated with the largest reductions in breach-driven insurance claims: endpoint detection and response, logging and monitoring, staff awareness training, and incident response planning. In the same analysis, phishing-resistant MFA was associated with institutions being 9 percent less likely to suffer a cyber event than those on weaker MFA, each 25 percent increase in EDR deployment correlated with a 10 percent lower breach probability, and running incident response tabletop exercises correlated with a 13 percent lower chance of a material event.
The incident response plan is worth a second look. It is control number seven, it is one of the four the data says matters most, and it is the one institutions most often treat as a document to write once and file. A carrier reads it differently: they want a plan you have tested, with defined roles and defined recovery steps. Building one where your controls and your evidence already live is the practical move, and a Microsoft 365 incident response plan keeps the plan and the tooling in the same place.
The Control to Microsoft 365 Map
Here is the part that saves banks, credit unions, and mortgage companies weeks of questionnaire work. If you run Microsoft 365, most of the controls above map directly to a Microsoft product you either already own or can license. The table pairs each of the core technical controls with the specific Microsoft tool that satisfies it, using the current 2026 product names an examiner or an underwriter will recognize. A few items on the carrier list, such as security awareness training and a tested incident response process, are program practices rather than a single product, and they are covered in the sections around this table.
| Carrier control | Microsoft product that satisfies it | What it does |
|---|---|---|
| Multi-factor authentication | Microsoft Entra Conditional Access | Enforces MFA by user, app, location, and sign-in risk |
| Phishing-resistant MFA | Microsoft Entra authentication strengths | Requires FIDO2 keys, passkeys, or certificate-based sign-in |
| Endpoint detection and response | Microsoft Defender for Endpoint (part of Microsoft Defender XDR) | Detects and responds to threats on every managed device |
| Privileged access management | Microsoft Entra Privileged Identity Management | Just-in-time admin access and least standing privilege |
| Email filtering and anti-phishing | Microsoft Defender for Office 365 | Safe Links, Safe Attachments, and anti-phishing policies |
| Logging and monitoring (SIEM) | Microsoft Sentinel | Cloud-native SIEM that correlates signals across the tenant |
| Audit logging and retention | Microsoft Purview Audit | Standard retains audit logs 180 days, Premium one year, with a 10-year add-on |
This map is not just tidy, it is aimed at the losses that actually happen. The controls carriers weight most heavily are the ones that stop the claims they pay most often, and the claims data is blunt about where the money goes.
Ransomware is the other major driver, and its entry point is telling. In 2025, 87 percent of ransomware claims entered through remote access, up from 80 percent the year before, according to the At-Bay 2026 InsurSec Report, corroborated by Help Net Security in April 2026. That is exactly the surface Conditional Access, phishing-resistant MFA, and Remote Desktop Protocol hardening are meant to close, which is why carriers press so hard on them. Ransomware was also the costliest claim type, with average severity of $508,000, even though business email compromise was the more frequent one. Frequency and cost tell different stories, and a good ransomware protection posture for financial institutions has to answer both.
Where Microsoft 365 Falls Short: The Backup Gap
Microsoft 365 satisfies most of the carrier checklist natively. There is one control where it does not, and it is the one that trips up banks, credit unions, and mortgage companies most often at renewal: backup.
Start with Microsoft's shared responsibility model. In a software-as-a-service environment like Microsoft 365, the customer always owns their data. Microsoft keeps the service running and resilient, but recovering your data after accidental deletion, a malicious insider, or a ransomware event is your responsibility, not Microsoft's. Insurers know this, which is why the questionnaire asks about backup as a control you own rather than a feature you rent.
The common misread is that Microsoft 365's built-in retention, versioning, and recycle bins count as backup. They do not. Retention policies and recycle bins are designed to hold recently deleted items for a limited window, not to give you a clean, restorable, tamper-proof copy after an incident.
Microsoft 365 Backup is a real, first-party service, and it helps. It provides fast restore for Exchange, OneDrive, and SharePoint at about $0.15 per gigabyte per month, and it is a genuine improvement over relying on recycle bins. But read the fine print before you answer a questionnaire with it. Microsoft's own documentation is explicit that Microsoft 365 Backup uses append-only storage with a fixed one-year retention and does not block deletion of the backups. So it is not multi-year, and it is not the write-once read-many, deletion-proof copy an insurer means when the questionnaire says "immutable." If you want the full picture of what native tooling does and does not cover, our guide to Microsoft 365 backup for financial institutions walks through it.
Put the two options side by side and the distinction the questionnaire cares about is clear. One gives you fast recovery of day-to-day data. The other gives you the locked, tamper-proof copy an insurer will actually credit as immutable.
Microsoft 365 Backup
- Fast restore for Exchange, OneDrive, and SharePoint
- Append-only storage
- Fixed one-year retention
- Deletion of the backups is not blocked
- Not WORM, not deletion-proof
Azure Backup Immutable Vaults
- Can be locked to an irreversible WORM state
- Once locked, deletion and shortened retention are blocked
- Long, configurable retention beyond one year
- Runs in your institution's own Azure subscription
- Satisfies an "immutable backup" questionnaire requirement
Where a carrier demands immutable, WORM-locked, longer-retention, or segregated backups, the answer is a backup that writes your data into immutable storage. Azure Backup immutable vaults provide exactly that target, WORM-locked and segregated and lockable to an irreversible state, run inside your institution's own Azure subscription. Closing the gap for Microsoft 365 data means pairing a backup of Exchange, OneDrive, and SharePoint with an immutable target like that vault, rather than assuming the built-in tools already do it. This is the precise line to walk on the application: Microsoft 365 Backup for fast operational restore, and a backup that lands your Microsoft 365 data in an immutable Azure vault for the WORM, long-retention requirement. Claiming Microsoft 365 Backup is immutable when it is not is the kind of misstatement an insurer can point to when they contest a claim, so accuracy here protects the coverage you are paying for.
The Questionnaire and the Exam Are One Job
Here is the good news for a compliance officer. The controls a cyber carrier scores are, almost line for line, the controls your regulator already expects. Do the work once and it satisfies both, which turns an insurance cost into examination readiness you were going to need anyway.
For mortgage lenders and other non-bank financial institutions, the FTC Safeguards Rule, 16 CFR 314.4, is the clearest example. It mandates the same control spine the insurance questionnaire asks about: multi-factor authentication, a written incident response plan, access controls, encryption of data at rest and in transit, and monitoring and logging of authorized-user activity.
The rule requires multi-factor authentication for any individual accessing any information system, unless the institution's qualified individual has approved in writing the use of a reasonably equivalent or more secure access control.
Read the rest of 314.4 and the overlap keeps going: 314.4(h) requires the written incident response plan, 314.4(c)(1) requires access controls, 314.4(c)(3) requires encryption at rest and in transit, and 314.4(c)(8) requires monitoring and logging of authorized-user activity. Most of those map to a Microsoft product in the table above: access controls to Microsoft Entra and Privileged Identity Management, and monitoring and logging to Microsoft Sentinel and Microsoft Purview Audit. Encryption is built into Microsoft 365 at rest and in transit, and the written incident response plan is the program practice those controls support. For the full mapping of that regulation to your tenant, see how the FTC Safeguards Rule maps to Microsoft 365 for mortgage companies.
Banks and credit unions live under parallel expectations from the FFIEC, the OCC, the FDIC, and the NCUA. The specifics differ by regulator, but the direction is the same: identity, monitoring, response, and recovery. When you configure Microsoft 365 to pass the cyber questionnaire, you are also building the evidence an examiner will ask for. The insurance renewal and the IT examination are the same underlying work, produced once and pointed at two audiences.
How ABT Closes the Questionnaire
Knowing which Microsoft product satisfies which control is one thing. Configuring all of them correctly, keeping them from drifting out of compliance, and producing the evidence at renewal is another. That is the work Access Business Technologies does for more than 750 financial institutions.
M365 Guardian is ABT's managed Microsoft security operating model. It configures the Microsoft controls a carrier scores, including Microsoft Entra Conditional Access, phishing-resistant authentication strengths, Microsoft Defender for Endpoint, Microsoft Entra Privileged Identity Management, Microsoft Defender for Office 365, Microsoft Sentinel, and Microsoft Purview Audit, to a hardened baseline. Then it monitors your tenant continuously, so a control that gets switched off or drifts out of policy surfaces before your carrier or your examiner finds it. Many institutions already own most of these capabilities and simply never turned them on, which is a recurring theme in the Microsoft 365 E5 security features that go unused at financial institutions.
That distinction matters on the questionnaire. Carriers increasingly separate having a SIEM from watching one, and a growing number of questionnaires ask specifically about managed detection and response or 24 by 7 monitoring. A Microsoft Sentinel workspace that no one is watching does not satisfy that line item. Microsoft Defender XDR and Microsoft Sentinel produce the detections; M365 Guardian tunes them and watches for the configuration drift that quietly turns a passing answer into a false one. For institutions whose carriers require continuous human-led investigation, that coverage is available as a managed detection and response add-on rather than something you have to staff a security operations center to provide.
For the backup gap, ABT designs and runs a backup that lands your Microsoft 365 data in Azure Backup immutable vaults inside your institution's own Azure subscription, locked to the WORM state that satisfies an immutable backup requirement. ABT manages your Microsoft 365 tenant and runs the Azure environment behind it, so the fast-restore layer and the immutable layer are both covered and both documented. One partner produces both the questionnaire answers and the exam evidence.
ABT configures and manages the Microsoft 365 security controls cyber carriers score for more than 750 banks, credit unions, and mortgage companies. Because ABT runs a pure Microsoft stack, the same controls that answer the insurance questionnaire also produce the audit evidence regulators expect, delivered and maintained by one partner instead of four.
The renewal deadline is a hard date, and the questionnaire rewards institutions that can prove their posture rather than promise it. Walking into that conversation with your controls configured, monitored, and documented is the difference between negotiating on price and scrambling to explain a gap.
See exactly where your Microsoft 365 tenant stands before your next renewal
ABT maps your current Microsoft 365 configuration against the controls your cyber carrier and your examiner ask about, closes the gaps, and hands you the evidence to answer the questionnaire with confidence. Start with a free security grade or talk it through with a specialist.
Frequently Asked Questions
Yes, for the control itself. Microsoft Entra Conditional Access enforces multi-factor authentication by user, application, location, and sign-in risk, which covers the remote access, administrator, and sensitive-data scenarios carriers ask about. The newer requirement is phishing-resistant MFA, and Microsoft Entra authentication strengths satisfies that by requiring FIDO2 security keys, passkeys, or certificate-based sign-in instead of text-message codes. If your questionnaire distinguishes between MFA and phishing-resistant MFA, you need the authentication strengths configuration, not just Conditional Access with a passcode app.
No. Microsoft 365 Backup is a real first-party service that gives you fast restore for Exchange, OneDrive, and SharePoint, but Microsoft's own documentation states it uses append-only storage with a fixed one-year retention and does not block deletion of the backups. That means it is not multi-year and not the write-once read-many, deletion-proof copy an insurer means by "immutable." When a questionnaire demands immutable, WORM-locked, or longer-retention backups, the answer is a backup that writes your Microsoft 365 data into an immutable target such as Azure Backup immutable vaults, which can be locked to an irreversible state and run in your own Azure subscription.
Microsoft Defender for Endpoint, which is part of the broader Microsoft Defender XDR platform, is the product that satisfies an endpoint detection and response requirement. It runs on every managed device, detects threats, and enables investigation and automated response. Carriers weight EDR heavily because the claims data backs it up: Marsh McLennan found that each 25 percent increase in EDR deployment correlated with a 10 percent lower breach probability. On the questionnaire, name Microsoft Defender for Endpoint specifically rather than a generic "antivirus," because underwriters distinguish between traditional antivirus and true EDR.
They mean limiting who holds administrator rights and for how long. The goal is least standing privilege, where no one carries permanent admin access and elevated permissions are granted just in time and expire automatically. In Microsoft 365, Microsoft Entra Privileged Identity Management delivers this: admins request elevation when they need it, the access is time-boxed, and every elevation is logged. This matters to carriers because compromised administrator credentials turn a routine intrusion into a tenant-wide event, and it maps directly to the access-control expectations regulators hold as well.
Largely, yes. The FTC Safeguards Rule, 16 CFR 314.4, mandates the same control spine the insurance questionnaire asks about: multi-factor authentication, a written incident response plan, access controls, encryption at rest and in transit, and monitoring and logging of authorized-user activity. Banks and credit unions face parallel expectations from the FFIEC, OCC, FDIC, and NCUA. The practical result is that configuring Microsoft 365 to pass the cyber questionnaire also builds the evidence an examiner will request, so you produce the work once and use it twice.
Check your Purview Audit tier first. Microsoft Purview Audit Standard retains audit logs for 180 days, and Purview Audit Premium extends that to one year, with an add-on that reaches up to 10 years. If a carrier or examiner wants retention beyond what your tier provides, or centralized correlation across systems, Microsoft Sentinel is the cloud-native SIEM that ingests, retains, and analyzes that log data over longer windows. The combination of Purview Audit for the native audit trail and Sentinel for long-retention monitoring covers the logging and monitoring control most questionnaires include.
Justin Kirsch
Co-Founder & CEO, Access Business Technologies
Justin Kirsch has helped financial institutions run secure, compliant Microsoft environments since 1999. As Co-Founder and CEO of Access Business Technologies, the largest Tier-1 Microsoft Cloud Solution Provider primarily dedicated to financial services, he leads the team that configures and manages the Microsoft 365 controls cyber carriers and examiners scrutinize for more than 750 banks, credit unions, and mortgage companies.

