Cyber insurance questionnaires: script evidence MSPs can actually attach

Updated 2026-08-26

What insurers ask about privileged scripts, which Trustholm artifacts you can attach, and what never counts as “insurance approved.”

Cyber insurance questionnaires: script evidence MSPs can actually attach

Visual anchor before the full guide below.

Leadership workshop planning cyber insurance and audit evidence strategy

procurement

Cyber insurance questionnaires: script evidence MSPs can actually attach

What insurers ask about privileged scripts, which Trustholm artifacts you can attach, and what never counts as “insurance approved.”

  • Reproduce steps in trial
  • Export audit evidence
  • Attach to GRC binder
1session reproduction target
Start free trial

Published 2026-08-26 · Pillar: procurement

Insurers and brokers increasingly ask how MSPs control remote PowerShell, who approved a change, and whether execution history can be exported. Those questions are about artifacts, not about Trustholm (or any vendor) “getting you approved.” This guide maps questionnaire themes to files you can produce in a Govern trial. It does not claim that any carrier, binder, or wholesaler has certified Trustholm.

What you can attach

Start with objects you can regenerate on demand:

  1. Security Center screenshot following the screenshot guide in the lead pack.
  2. Audit export JSON/CSV from the operator portal (tenant-scoped).
  3. Assessor Package ZIP with honest trust-artifacts.json (no Type II claim).
  4. SIG Lite / questionnaire pre-fill as a draft, with Gap rows left as Gap.

Do not attach invented pentest PDFs, bridge letters, or SOC 2 reports. Trustholm does not hold SOC 2 Type I or Type II and does not claim an observation period.

What insurers usually mean by “script control”

Most forms collapse several controls into one cell: signing, approval, least privilege, logging, and tenant isolation. Split them in your response:

  • Signing: customer-held keys; the agent verifies locally. Trustholm is not the sole holder of mutate authority on the recommended path.
  • Approval: tenant policy before enqueue. Dual custody where you configured it.
  • Logging: security audit plane plus execution stdout/exit codes, not only RMM job history.
  • Isolation: schema-per-tenant, not a marketing slogan. Reproduce a 403 on JWT/tenant mismatch in trial.

If the form asks “is the RMM your only remote access tool,” answer with coexistence: the incumbent RMM stays; Trustholm gates privileged scripts beside it.

What never to write

Do not write “Trustholm is insurance approved,” “meets cyber insurer controls,” or “reduces premiums.” Premiums, endorsements, and binding are the carrier’s decision. Trustholm supplies technical evidence for your program.

Do not paste LabVerified language for Entra SSO, Stripe, or SMTP until the capability verification registry says LabVerified. CodeComplete is not live-signed-off.

Trial reproduction (sixty minutes)

  1. Provision or sign in to a Govern trial.
  2. Publish a signed script (or duplicate a platform example) and run it on one agent.
  3. Export audit for that window; confirm tenant identifiers only.
  4. Download Assessor Package; open trust-artifacts.json and the limitations appendix.
  5. Capture Security Center fields listed in the screenshot guide.
  6. Store the ZIP and screenshots in your GRC binder with a dated folder name.

Customer-operated remainder

Endpoint hardening (GPO/Intune AllSigned), patch cadence, EDR, backups, and insurance application narrative remain yours. Trustholm does not replace those programs.

Workshop notes for brokers

Bring the starter pack index (public) and the gated questionnaire files (work email). Walk the broker through one denied unsigned dispatch if RequireSigned is on. That demonstration is stronger than a slide claiming coverage.

Maintenance

Re-run the trial export after major platform upgrades. Questionnaire crosswalks drift. Treat this page as a map, not a living certificate.

Field notes (insurer questionnaires)

For brokers, attach only regenerable artifacts: Security Center screenshot, audit export, Assessor ZIP, and SIG Lite with Gap rows intact. Never write insurance approved, premium reduction, or carrier endorsement. If the form asks whether the RMM is the only remote access tool, answer coexistence: incumbent RMM plus Trustholm for privileged signed scripts.

Date the diligence folder YYYY-MM-DD and record the portal product version. Re-export after upgrades. Do not reuse last week's grant token. Public starter PDFs copy without email. Gated files need a live grant. If the Platform API is down, HubSpot may still capture the lead with no download buttons. Say that out loud so GRC does not think the trial is broken.

Walk one denied unsigned dispatch when RequireSigned is on. Capture a 403 from a mismatched tenant header. Export audit for one window and confirm no foreign tenant codes. Open the Assessor ZIP trust-artifacts.json and read the limitations appendix. Leave Gap rows as Gap. Do not paste LabVerified for Entra, Okta, Stripe, or SMTP until the capability verification registry says LabVerified.

Keep the incumbent RMM. Trustholm does not replace OS patching, remote takeover, or a NOC hero pitch. Probe and observe features are operator tools, not the reason a council or insurer should buy. Named design-partner logos stay off marketing pages until attestation exists.

Store ZIP files with access control. They hold tenant metadata even when secrets are stripped. Email security@trustholm.com only for Manual DPA or pentest summary. Do not invent those PDFs on www.

If someone asks to select all agents in a dropdown, stop and show catalog pagination. If someone asks for a second region or a single global edge FQDN, say Phase 1 Australia edge is current and global discovery is deferred.

Copy the trust hub sentence into the packet: we do not hold SOC 2 Type I or Type II and do not claim an observation period. Trustholm supplies technical artifacts for the customer's program. It does not automate customer SOC 2 Trust Services Criteria like a GRC product.

Assign an owner to refresh this packet quarterly or after a Shipped/Gap change. Workshops go stale. Prefer live reproduction over architecture slides. Prefer export files over screenshots alone, then keep both.

For brokers, attach only regenerable artifacts: Security Center screenshot, audit export, Assessor ZIP, and SIG Lite with Gap rows intact. Never write insurance approved, premium reduction, or carrier endorsement. If the form asks whether the RMM is the only remote access tool, answer coexistence: incumbent RMM plus Trustholm for privileged signed scripts.

Frequently asked questions

Does Trustholm get our cyber insurance approved?

No. Carriers decide. Trustholm provides exportable script and audit artifacts you may attach to a questionnaire.

Can we say we are SOC 2 certified because of this pack?

No. We do not hold SOC 2 Type I or Type II. We do not claim an observation period. Do not imply otherwise.

Which files are public versus gated?

One-pagers and regional summaries are public on the downloads hub. SIG Lite, diligence, and checklists need a work-email grant token.

Should we attach a pentest PDF from the website?

No self-serve pentest report exists. Cadence is documented. Request a summary via security@trustholm.com if your broker requires it.

Does this replace our RMM logging?

No. Keep RMM job history. Trustholm adds signing policy and tenant-scoped security audit export for privileged scripts.