Cyber insurance questionnaire: how to answer the email security questions

Applications vary. Use the carrier's actual wording, answer from controls you operate, and treat InboxGuards reports only as supporting monitoring records.

N°001sectionthe short answer

Section 01

The short answer

Cyber-insurance renewal questionnaires vary. Some include email-security questions about multi-factor authentication, monitoring, forwarding rules, suspicious sign-ins, logging, payment verification, or incident response. Answer only from controls you actually operate. InboxGuards provides monitoring records for $4 per user per month, but only your carrier can decide whether they are relevant to a requirement.

N°002sectionquestions an application may include

Section 02

Questions an application may include

Wording and requirements vary by carrier, policy, and business. Obtain the actual application; examples may include:

  • "Is multi-factor authentication (MFA) enforced for all email accounts?" — Answer from the tenant's actual configuration and ask the carrier how it defines enforcement.
  • "Do you monitor email accounts for unauthorized access or configuration changes?" — Describe the process you actually use and ask your broker how the carrier defines monitoring.
  • "Would you detect a mail forwarding rule sending copies of email outside your organization?" — External forwarding is a common business-email-compromise technique; answer based on the exact tools and audit events available in your tenant.
  • "Do you retain logs of sign-in activity?" — Answer from the provider edition, configured retention, and records your organization actually stores.
  • "Do you have a process for responding to a suspected email compromise?" — Describe your actual written process and confirm the carrier's requested details with your broker.
N°003sectionthe supporting evidence inboxguards gives you

Section 03

The supporting evidence InboxGuards gives you

InboxGuards connects read-only with customer-admin authorization and checks supported audit records at roughly 5-minute intervals for configured account-takeover indicators. These are examples of records it can provide; the carrier decides whether any record is relevant:

  • Monitoring email accounts → scheduled checks approximately every 5 minutes, with timestamped alerts for configured matches.
  • Detecting forwarding rules → supported external-forwarding and inbox-rule events are checked when the provider exposes them.
  • Detecting suspicious sign-ins → supported sign-in records are checked against configured location rules when required fields are available.
  • Producing evidence → downloadable activity reports and a printable certificate of monitoring, generated from your dashboard.
N°004sectionwhat monitoring does not do

Section 04

What monitoring does not do

Be accurate on your application; incorrect statements may affect underwriting or coverage, and only your broker, carrier, or counsel can advise on your policy. InboxGuards is monitoring and alerting software. It is not managed detection and response, does not remediate incidents, and cannot catch every attack. Describe only the controls you actually operate and let the carrier determine what satisfies its requirements.

N°005sectionget ready before your renewal

Section 05

Get ready before your renewal

Setup is self-serve and requires authorization from the customer's Microsoft 365 or Google Workspace administrator. Monitoring begins after a successful connection and scheduled check. Reports describe recorded InboxGuards activity only; ask the carrier before attaching them to an application.

N°006faqcommon questions

FAQ

Common questions.

Does InboxGuards satisfy my cyber insurance requirements?
No service can promise that — each carrier decides what qualifies under its own underwriting rules. InboxGuards provides automated email monitoring with timestamped alerts and downloadable reports you can share with your broker as supporting evidence.
What email security questions do cyber insurers ask?
Questions vary by carrier. Some applications ask about multi-factor authentication, email-security tools, logging or monitoring, payment-verification procedures, and incident response.
How fast can I get monitoring in place before a renewal?
Timing depends on customer-admin authorization and a successful provider connection. Monitoring begins on a later scheduled check cycle after connection; confirm recorded activity before relying on a report.

Get monitoring before your renewal

Customer-admin authorization · Timestamped monitoring records · $4/user/mo