Cyber insurance renewal coming up? Review the controls behind the answers before you complete the questionnaire.
Mycelium's Cyber Insurance Controls Implementation Project aligns practical security controls to common cyber insurance expectations — reducing risk, improving readiness, and giving your business a clearer security baseline.
Twelve practical control areas aligned to the questions cyber insurers actually ask.
Audit MFA coverage across every user, service account and admin role — close gaps insurers and underwriters expect to see closed.
Review and tighten Conditional Access policies: block legacy auth, enforce device compliance, restrict risky sign-ins.
Confirm every endpoint is encrypted, enrolled in management, and reporting healthy security signals to your central tooling.
Validate Defender for Endpoint or third-party EDR coverage, alert routing, and managed detection-and-response workflows.
Benchmark your tenant against Microsoft and CIS security baselines for identity, email, collaboration and admin settings.
Verify OS, browser and third-party application patching cadence, Intune rings, and unpatched vulnerability exposure.
Confirm Microsoft 365, server and SaaS backups are immutable, off-tenant where required, and restorable on demand.
Review your phishing simulation programme, training cadence, and reporting against insurance and compliance expectations.
Develop or refresh a documented IR plan with escalation contacts, communications templates, and tabletop scenarios.
Audit Global Admin and high-privilege roles, enforce PIM/JIT activation, and remove standing administrative privilege.
Validate SPF, DKIM, DMARC, Defender for Office 365 policies, anti-phishing and impersonation protection.
Receive a documented evidence pack mapping your controls to common insurer questionnaires for renewal discussions.
Every review delivers documented evidence across the five control domains insurers focus on most at renewal.
Entra ID + MFA
Defender / MDR
Exchange / Defender for O365
Microsoft 365 + Servers
Policies + Response