A client of ours got a security questionnaire from their largest customer. Twenty-two questions, most of them fine. Then question nine: “Provide evidence that multifactor authentication is enforced for all users with access to customer data.” Not “do you have it.” Provide evidence. The owner’s first instinct was to write back “yes, we do that.” Ten years ago that would have closed the item. It does not anymore.
Insurers, enterprise customers, and auditors have all landed in the same place at roughly the same time. Attestation is cheap, so it has stopped being persuasive. What they want is a screenshot, a report, a signed sheet, a log entry, something with a date on it. The good news is that almost every business already produces this material and simply throws it away. Quick note before we continue: this article is general information, not legal or compliance advice. What evidence a particular auditor, insurer, or contract requires varies, and a qualified advisor has to confirm what applies to you.
Why “We Do That” Stopped Working
Put yourself on the other side of the desk. An underwriter reviewing a renewal has a stack of applications, all of which claim multifactor authentication, backups, and training. The claims that later turn into losses came from that same stack. So the questions got sharper, and the burden of proof moved.
There is a quieter reason too. Reconstructing the past is genuinely hard. Ask a business to prove its backups were tested nine months ago and you get a thoughtful pause followed by a search through email. Ask about last Tuesday and the answer takes thirty seconds. Evidence is not hard to produce. It is hard to produce late.
What Actually Counts as Evidence
Evidence is anything a system generated or a person signed showing a control was operating on a specific date. Here is what that looks like for the controls that come up most often.
- Multifactor authentication coverage. A report showing how many users are actually covered, not a policy saying they should be. If you run Microsoft 365, Microsoft Learn documents an Authentication Methods Activity dashboard in Microsoft Entra ID that “enables admins to monitor authentication method registration and usage across their organization.” Its registration view reports users capable of multifactor authentication, meaning people both registered for a strong method and enabled by policy to use it. Its usage view reports sign-ins by authentication requirement, separating single-factor from multifactor sign-ins. Screenshot the summary, date it, file it.
- Backup restore tests. The result, with a date, naming what was restored and whether it opened. CISA’s Cyber Essentials Starter Kit tells businesses to “Periodically test your ability to recover data from backups,” and NIST’s Cybersecurity Framework 2.0 Small Business Quick-Start Guide emphasizes regularly backing up data and testing those backups. A one-paragraph note with a date and a name is enough.
- Security awareness training completion. The completion list from whatever platform you use, exported at the end of the campaign. Names and dates. If you did training in a conference room instead, a sign-in sheet with the date and the topic works.
- Endpoint protection deployment. A report from your security console showing how many machines are protected and, more usefully, how many are not. The gap is the interesting number.
- Access reviews. A list of accounts, who reviewed it, what changed, and when. Sign-off can be a name typed at the bottom of a spreadsheet. It does not need to be notarized.
- Asset inventory. Both CISA and NIST put this near the front. CISA advises maintaining inventories of hardware and software assets, and NIST’s small business guide puts it plainly: “Before you can protect your assets, you need to identify them.” A dated export of your device list qualifies.
One practical warning about cloud dashboards. Some reports lag behind reality. Microsoft Learn notes that the Entra authentication methods report is not updated in real time and may reflect a latency of up to 36 hours, and it lists specific roles required to view it. If you just made a change, wait before capturing the picture, and make sure whoever collects evidence has read access.
Organize by Control, Not by Chaos
The filing structure matters more than it should. We have watched businesses that genuinely had every piece of evidence still take two weeks to answer a review, because it was scattered across four inboxes and a folder named “security stuff.”
Make one folder per control, not one folder per year. Inside each folder, start every file name with the date in year-month-day order so the files sort themselves chronologically. A folder called “MFA coverage” holds files named for the dates they were captured. A folder called “Backup restore tests” does the same. When someone asks for the last twelve months of anything, you open one folder and grab the top files.
Add one plain text file at the top level listing each control and where its evidence lives. Six lines. That file is what lets someone other than you answer a question while you are on vacation.
Capture It as You Go
This is the whole trick, and it is unglamorous. Evidence collection should be the last step of the task, not a separate project you do later under pressure.
- Finish the restore test, then write the note. Two sentences while the result is on your screen. Later, you will not remember which file you restored.
- Finish the training campaign, then export the list. Platforms change, licenses lapse, and last year’s completion data is not always retrievable.
- Review access, then save the reviewed list. The list you looked at, not a fresh one pulled six months later showing a different state.
- Attach the capture step to a recurring calendar item. Same reminder, same person, same month, every time.
Reconstructing evidence after the fact is not just slow. It is sometimes impossible, and it occasionally produces something misleading, which is a worse outcome than an honest gap.
What This Saves You
We will not put a number on it, because every review is different. But the shape is consistent. A business with organized evidence answers an insurance questionnaire or a customer security review in one sitting, mostly by attaching files it already had. A business without it spends days chasing screenshots, sends partial answers, gets follow-up questions, and repeats the cycle. Same underlying security. Wildly different experience.
Collecting evidence monthly also makes you notice when a control quietly stopped working. The month your coverage report shows a drop is the month you find out someone was excluded from a policy. Far better to learn it then than during a claim, and it is one more reason security has become a normal operating function rather than a one-time purchase.
The Bottom Line
You are probably doing the work already. What is missing is the thirty seconds at the end where you save the proof with a date on it. Build the folders, assign the capture step to a person, and let it accumulate. Six months from now, a request that would have ruined a week becomes an email with attachments. If you are still choosing which authentication method to standardize on, our comparison of hardware keys, passkeys, and app-based MFA is a reasonable starting point.
As we said at the outset, this is general information and not legal or compliance advice. What evidence you need, in what form, and how long you keep it should be confirmed by a qualified attorney or compliance professional familiar with your contracts and your industry.
If you would rather not build and maintain this yourself, that is a fair choice and a normal part of what we do for businesses across Denton County. We can set up the folders, produce the monthly reports, and hand you a package when a review lands. Contact us today.
Sources:
Comments are closed