This walks through the questions small firms actually see, what an honest yes requires for each, and what to do when the honest answer is no. We are not insurance agents; this is the IT side of the form, which is most of the form.
Multi-factor authentication
What the form asks: Is MFA enforced on email, remote access, and administrator accounts?
The first question on nearly every application, and the one carriers care about most. The key word is enforced. Plenty of firms have MFA available in Microsoft 365 and switched on for some people, and that is not a yes.
An honest yes means a tenant policy requires the second step for every user, with no exception for the partner who finds it annoying.
An honest yes requires
- A tenant-wide policy, not per-user opt-in
- Covers email, remote access, and admin accounts
- You can export the policy as proof
The trap one attorney who can still sign in with a password alone. That is a not-yet, not a yes.
Backups you have actually tested
What the form asks: Do backups exist, are they separated from what they protect, and have you tested a restore?
Carriers ask three things, and the trap is in the second and third. Files that live only in OneDrive sync are not separated, because ransomware that encrypts the desktop syncs the damage upward.
A backup nobody has restored from is a hope, not a control. An honest yes means separate, versioned copies and a restore you have actually performed, with a note of when.
An honest yes requires
- Separate, versioned copies off the systems they protect
- A restore you have performed, not just scheduled
- A dated note recording that test
The trap counting sync as backup. Sync protects against a lost laptop, not a deletion or an encryption.
Patching, and the machines nobody mentions
What the form asks: Are operating systems and software updated on a schedule? Is anything past end of support?
Applications increasingly ask whether anything in the office runs software its maker no longer fixes. The trap machine is the old PC in the corner that runs one thing, because that is exactly what the question is about.
An honest yes means updates apply on a schedule you can describe, and nothing on the network is past end of support.
An honest yes requires
- A schedule you can state out loud
- An inventory that includes the odd single-purpose machine
- Nothing on the network past end of support
The trap the unmanaged box running scanning, billing, or a legacy case tool.
Endpoint protection
What the form asks: Is antivirus or endpoint detection on every machine, managed centrally?
Free consumer antivirus installed machine by machine is technically an answer. Managed means someone sees the alert when a machine flags something, rather than the alert dying on a screen nobody watches.
If each computer fends for itself, say so to your agent rather than rounding up to yes.
An honest yes requires
- Coverage on every machine, including laptops off-site
- One console, one place the alerts are reviewed
- Alerts that reach a person the same day
The trap per-machine free antivirus with nobody monitoring it.
Email security: SPF, DKIM, DMARC
What the form asks: Do you have SPF, DKIM, and DMARC records published for your domain?
This is the control small firms most often fail without knowing. SPF, DKIM, and DMARC are three DNS records that tell the world which servers may send email as your firm.
Without them anyone can send an invoice from an address that looks exactly like yours, and wire fraud aimed at law firms starts exactly there. The records are checkable from outside your office in about a minute, which is why it is the first thing our free Security Check looks at.
An honest yes requires
- All three records published, not just SPF
- DMARC set to a real policy, not p=none forever
- Every sending service accounted for
The trap assuming Microsoft 365 sets these up for you. It does not set DMARC.
Access control and departures
What the form asks: Who holds administrator rights, and are accounts removed when someone leaves?
The honest yes here is procedural: day-to-day work happens in accounts without admin rights, and there is a written step that closes accounts on the day a person departs.
The firm that fails this question usually finds out during the claim, when the intrusion traces back to a paralegal account nobody closed two years ago.
An honest yes requires
- Daily work in non-admin accounts
- A written offboarding step, same day
- A current list of who holds admin rights
The trap the dormant account of someone who left years ago.
Score your firm before the form does
Answer the way you could prove it on a claim, not the way you hope it is. Nothing is sent anywhere.
MFA enforced for every user
Tenant policy, no exceptions, exportable
Separated backups with a tested restore
Versioned, off-system, restore documented
Everything patched, nothing past end of support
Including the single-purpose machine in the corner
Centrally managed endpoint protection
One console, alerts someone actually reads
SPF, DKIM, and DMARC published
Checkable from outside in about a minute
Least privilege and same-day offboarding
Written step, current admin list
Answer the 6 above to see where you stand
Score it the way you could prove it on a claim. Nothing leaves this page.
When the honest answer is no
A no on the questionnaire is a fixable problem. A yes the records do not support is not. Every control above is achievable at a small firm, and there is a usual order, cheapest and most protective first.
- 01MFA first. Cheapest to do, blocks the most, and it is the question carriers weigh heaviest.
- 02Backups with a tested restore. Then write down the date you tested it.
- 03Patching and endpoint protection. Retire or isolate anything past end of support while you are in there.
- 04The DNS records. Fast, cheap, and the one outsiders can already see.
Tell your agent what is in progress; agents deal in trajectories more comfortably than they deal in surprises. Then keep the evidence as you go: the exported MFA policy, the restore test note, the patch schedule. The renewal comes back every year, and the difference between a scramble and paperwork is whether the records already exist.
FAQ
Do we need a managed plan to get help with the questionnaire?
No. Work for businesses not on a plan is billed at $125 per hour, and larger projects are quoted up front so you approve the number before the work starts.
What does a questionnaire mean by multi-factor authentication?
A second step at sign-in, such as an app prompt, enforced for every user on email and remote access. Carriers mean enforced, not available: if one attorney can still sign in with only a password, the honest answer is not yet yes.
Do OneDrive or SharePoint count as backup?
Usually not on their own. Sync protects against a lost laptop, but a deletion or ransomware encryption syncs too. Carriers generally mean separate, versioned copies that you have actually tested restoring from.
What happens if we answer yes and it is not accurate?
That is a question for your insurance agent, but carriers investigate after a claim, and answers you cannot back up put the coverage itself at risk. The safer route is making the answer true before you sign.
About the author
Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.
Want the answers to be yes before the renewal arrives?
That is the core of what we do for law firms: set the controls up so the honest answer is yes, and keep the records that show it. Pricing is published in what IT support costs a small law firm in Florida. Seeing where you stand costs nothing and commits you to nothing.
