Every MSP has spent years getting good at answering one question: what’s broken? Patch management, EDR alerts, vulnerability scans, MFA rollouts, the entire security stack exists to surface gaps and close them.
That’s the job, and MSPs are good at it.
Cyber insurance underwriters are asking a different question: what can you prove? Not “is this client secure,” but “can you document that they’re insurable.” Those aren’t the same question. The gap between them is where MSPs are losing renewal conversations they should be winning.
The two questions
Security is a present-tense discipline. It asks whether something is broken right now, and it hands you a yes-or-no answer: patched or not, alerting or not, MFA on or off. That’s what makes it fast to act on and satisfying to fix.
Insurance isn’t asking a yes-or-no question. It wants a measurement and a document – a percentage, a formal plan, a disclosed cadence – not a status light. An underwriter doesn’t ask “is MFA on.” They ask what portion of your cloud access, remote access, endpoints, and privileged accounts actually have it enforced, and they ask for it broken out by category.
Security signals vs. insurance signals
Put them side by side and the pattern is obvious.
We pulled this directly from an actual insurability assessment questionnaire, not a secondary source. It’s worth being precise about what it doesn’t ask: it doesn’t demand MFA be attested for a specific number of days, and it doesn’t ask for a ransomware playbook as its own signed-off artifact, ransomware scenarios get folded into the general IR plan question. What it consistently asks for, across almost every category, is a number or a named document, not a checkbox.
Every security signal answers a state: on or off, patched or not. Every insurance signal answers a measurement or a formal artifact: what percentage, which document, how often. Same underlying control area in most cases. Completely different evidence standard.
Why the same control can pass one test and fail the other
This is why a client can clear every internal scan your team runs and still get flagged, re-priced, or pushed to a worse set of terms at renewal. The scan proves EDR is deployed. The questionnaire asks what percentage of endpoints, split out by category, with no room for “basically all of them” and “we’re pretty sure it’s most” doesn’t survive a claims review any better than it survives underwriting.
MSPs were trained on the left column. Every dashboard, every RMM view, every EDR console was built to answer “what’s broken.” Nobody built a system to answer “what can you prove,” because until recently, no one was asking.
Why this became an MSP problem, not a broker’s
A broker can read a renewal questionnaire out loud. They can’t tell an underwriter what percentage of a client’s privileged accounts actually enforce MFA, or how recently backups were restore-tested, that evidence lives inside the MSP’s own tools, not the broker’s inbox. The previous IT vendor can’t produce it either, if they’re even still involved.
Which leaves the MSP as the only party in the room who can actually answer the question being asked. That’s not an administrative inconvenience to hand off. It’s the reason cyber insurance readiness belongs on an MSP’s services menu instead of a broker’s desk.
The opportunity sitting inside the gap
Once you can see the distinction, the revenue opportunity is hard to unsee. Every insurance signal your clients can’t currently produce is a control you already understand, paired with a documentation gap you’re positioned to close: as a scoped assessment, a recurring monitoring engagement, or a renewal-cycle deliverable. You’re not learning a new discipline from scratch. You’re extending the one you already have, in a direction insurers are already paying attention to.
If you’re already having the “why did our premium jump” or “why did we get flagged” conversation with clients, you’re already doing the work underneath this. The only question left is whether you’re getting paid for it, or leaving it for the renewal season to surface as a surprise.
See how Inscora turns what your stack already knows into evidence an underwriter will accept.