The insurance and Cyber Essentials evidence pack
What the six pages of the evidence pack measure, what "attested" and "cannot measure" mean, and how the verify link lets a broker or auditor confirm it without seeing your data.
Cyber insurers and Cyber Essentials assessors ask the same handful of questions in almost every form: is MFA on for email, remote access and privileged accounts; is every device protected; are backups in place; is there an incident-response plan; is staff trained. The evidence pack answers each one from this platform's own records — a count, the moment it was checked, and a hash — so you have a real answer ready instead of guessing on the day the form arrives.
Where to find it
Compliance > Evidence pack in the console. It is on every plan — generating the pack manually costs nothing and needs no add-on. Choose Download to open a print-ready page you can save as a PDF, or Copy verify link to hand a broker or auditor a link that confirms the pack's hash without giving them access to your console.
The six pages
| Page | What it answers | Built from |
|---|---|---|
| Multi-factor authentication | Privileged accounts and email/cloud accounts with a second factor of any kind. Remote access (VPN/RDP) is answered cannot measure — this platform does not monitor on-premises remote access. | Your users, their MFA/passkey enrolment, and who holds access-changing permissions. |
| Endpoint detection and response | Devices with an active sensor checked in within the last 24 hours, against every device this platform knows about. | Sensor check-ins and the endpoint inventory. |
| Backups | Attested, never measured: whoever runs your backups records who attested it and when it expires. | The attestation you record on this page. |
| Incident-response plan | Attested, from the plan drafted and attested on the incident response plan page. | The IR plan's own attestation, read here, not duplicated. |
| Security-awareness training | Whether at least one active account completed a course in the last 12 months, and how many. | Academy course completions. |
| Cyber Essentials: MFA everywhere | Every connected cloud service (SSO/federated identity provider), and whether a tenant-wide rule requiring a second factor covers all of them. | Connected identity providers and your sign-on policy rules. |
A page whose module is not on your plan reads cannot measure with that reason stated — never a fabricated gap, and never silently hidden.
What the labels mean
- Yes
- Full coverage, measured just now. A partial result is never rounded up to yes — 2 of 3 accounts covered reads as no, with the real count shown.
- No
- Measured, and the answer is no (or partial, or nothing is currently attested).
- Cannot measure
- This platform does not have the data to answer — either the module is not on your plan, or there is nothing to measure against. Always comes with a stated reason.
- Attested
- A named person vouched for it with an expiry. Backups and the incident-response plan are always attested, never "measured", because this platform cannot directly observe either one.
Attesting backups
Open the Backups panel
On the evidence pack page, choose Attest backups.
Enter who is attesting, and an expiry
The expiry cannot be more than about 13 months out — an attestation with no practical end date is not a real check-in.
Add a note if it helps
For example, which vendor and whether a restore has been tested. Optional, but it is what a reader sees alongside "attested by".
An expired attestation reads no again until someone attests again — it is never shown as valid past the date its own attester gave it.
The verify link
Every time the pack is downloaded — as JSON or as the printable document — it gets a fresh pack ID and hash, printed in the document's footer. Anyone with that pack ID and hash can visit the verify link and get back exactly one thing: whether they match, and if so, when the pack was generated. Nothing else — no organisation name, no counts, no way to guess a valid pack ID from a wrong one.
What to read next
- Your incident response plan — the plan this pack's IR page reads its attestation from.
- Evidence-bound drafts — the insurer notice and NIS2 early warning drafted from the same kind of records.
- Plans and what each includes — which modules unlock which pages of this pack.