Run Panthera on your own environment

Cyber insurance applications used to be a formality. A short form, a handful of yes-or-no boxes, a policy inthe mail. That is no longer how it works, and the change is sharper than most MSPs realize because ithappened while premiums were falling.The questions themselves are not new. MFA, backups, privileged accounts, offboarding. What changed is that theanswers are now treated as warranties. An underwriter who accepts your "yes" at binding can revisit it at claim time,and the difference between a control that exists and a control you can demonstrate is the difference between a paidclaim and a rescinded policy.For MSPs there is a second change on top of the first, and it is the reason this guide exists. Carrier forms have startednaming service providers directly. Your remote access tooling sits inside the scope of the MFA question. Your contactdetails are requested on the application. Your client base is underwritten in aggregate. The exposure is no longerpurely your client's.
What you will get out of it
- The real questions, quoted and dated
- Not paraphrases. The actual wording from Tokio Marine HCC's March 2026 NetGuard Plus form, Beazley's April 2023 applications and others, with form numbers so you can check us.
- A working understanding of privileged access management
- Most of what carriers ask about traces back to one root cause: accounts that hold elevated rights all the time. Section four explains how PAM addresses that in eight phases, and which application question each phase answers.
- The artifact that proves each answer
- For every control area, the specific export, log or report that satisfies an underwriter or a claims adjuster. Appendix A is an answer key you can work through before your next renewal.
- What happens when the evidence is not there
- Three documented cases, including one where the insurer paid the client and then sued the client's IT provider.
