Observed control coverage
One square per observed check · unavailable data is never scored as safe
Here's a scenario playing out in thousands of small businesses right now. The cyber insurance renewal arrives. It's fourteen pages of questions the owner can't answer, so it lands on whoever seems most technical, an office manager, a controller, sometimes the owner's nephew. That person does their best. Do all users have MFA? We use Microsoft, that comes with it, right? Check yes. Are backups tested regularly? Pretty sure the IT company handles that. Check yes. Sign, date, return.
Nobody lied. Everybody guessed. And now there's a legal document on file with an insurance carrier attesting to controls that may or may not exist.
I call the space between that signature and the tenant's actual configuration the attestation gap, and it's the most dangerous gap in small business right now, because it doesn't hurt anyone until the worst possible moment. The premium gets paid, the certificate gets issued, everything looks fine. Then there's an incident. A wire fraud loss, a ransomware event, a claim. And now, for the first time, the carrier actually verifies. Forensics pulls the logs. The application said MFA on all accounts. The logs show the compromised account never had it.
Carriers have gotten aggressive about this, and honestly, from their side of the table, who can blame them. Misrepresentation on the application is grounds to rescind coverage, and there are now well-documented cases of claims denied and policies voided over attestation gaps. The client paid premiums for years and discovers, mid-crisis, that they bought paper instead of protection.
For MSPs, this is both an obligation and an opening. The obligation part: if you're the IT provider and your client attested to controls you know aren't fully deployed, you're standing near a liability event, and "they never asked me" is a bad place to be standing. The opening part: you are the only party positioned to close the gap before it matters. The carrier can't see inside the tenant. The client can't read their own configuration. You can do both.
So make attestation verification a service. Before any client signs a renewal, run the scan, map findings to the application questions, and produce the honest answer sheet. Sometimes that means remediation projects before the renewal goes out. Sometimes it means correcting answers and accepting a premium adjustment. Either outcome beats the alternative, which is discovering the gap during a claim.
Being the honest broker between your client and their carrier is not glamorous work. It's also some of the highest-trust, highest-retention work an MSP can do. Anyone can sell fear of hackers. You're selling something rarer: the guarantee that the safety net is actually attached.