Cyber Insurance Evidence Pack SaaS for SMBs and MSPs
Software that pulls real MFA, endpoint, and backup evidence out of Microsoft 365 and Google Workspace and turns it into the dated proof pack carriers now demand at cyber insurance renewal.
The problem
Cyber insurance applications ask small businesses to attest that multi-factor authentication is enforced everywhere, that endpoint detection covers every device, and that backups are immutable and tested. Carriers increasingly want evidence, not a tick box: exported sign-in logs, conditional access configuration, backup test records. The owner or their IT provider assembles this by hand every renewal, screenshot by screenshot, and if the attestation turns out not to match reality on the day of a loss, the claim can be challenged as a material misrepresentation.
Why now
Carrier underwriting has tightened materially and the evidence bar has moved from written attestation toward exported proof. Renewal is annual and dated, which gives the product a hard, recurring trigger. At the same time Microsoft Graph and Google Workspace admin APIs expose exactly the signals needed (sign-in logs, conditional access policies, device compliance state), so a small team can build the collection layer without inventing anything.
Who pays
Two buyers. Primary: managed service providers and small IT consultancies in the US, UK, Canada, and Australia who run renewals for dozens of SMB clients. Secondary: 20 to 250 seat SMBs with an internal IT lead, especially in regulated or contract-heavy sectors such as professional services, healthcare adjacent, and manufacturing suppliers.
How it makes money
Per-tenant subscription billed to the MSP with volume tiers, plus a higher direct price for single SMBs. Annual renewal cycle makes an annual prepay natural. Optional add-on for the remediation checklist and gap tracking between renewals, and a one-time onboarding fee for messy tenants.
Market & demand
Order-of-magnitude: the addressable base is SMBs that buy cyber insurance in four English-speaking markets, reached mostly through MSPs. Even a few hundred MSPs at tens of tenants each puts you in the thousands of billable tenants, which at modest per-tenant pricing is a solid bootstrapped software business rather than a venture outcome.
Underwriters have moved from questionnaire trust toward evidence and, in some cases, direct telemetry. Security posture tooling exists in abundance for enterprises but the SMB and MSP end of the market still assembles renewal evidence manually. Brokers are becoming a distribution channel for readiness tooling because a better-prepared applicant is easier to place.
Verify before you commit:
- Cyber insurance take-up rates among SMBs (broker and carrier market reports, for example Marsh and Aon cyber market commentary)
- Carrier application forms and control requirements, which are public on most broker sites
- MSP market sizing and average tenants per MSP (Datto/Kaseya and CompTIA industry surveys)
- Microsoft Graph and Google Workspace admin API documentation for what evidence is retrievable
SWOT
Strengths
- Hard annual deadline creates a recurring, non-optional trigger
- Evidence is machine-retrievable, so the product can be genuinely automated
- MSP channel gives many tenants per sale
Weaknesses
- Requires privileged API access to customer tenants, a high trust bar for a new vendor
- Carrier requirements vary and change, so the mapping layer needs constant maintenance
- You are adjacent to insurance without being an insurer, which limits what you can promise
Opportunities
- Broker partnerships as a referral and distribution channel
- Extend to other attestation-driven forms: vendor security questionnaires, client due diligence
- Continuous monitoring between renewals rather than a once-a-year snapshot
Threats
- Microsoft or the RMM vendors shipping equivalent reporting natively
- Established posture management vendors moving down-market
- A softening cyber insurance market reducing evidence pressure
Competition & the gap
Security posture and compliance platforms such as Vanta and Drata (aimed at SOC 2 and up-market), MSP stack reporting inside tools like Datto and Kaseya, broker-provided readiness portals, and a lot of manual spreadsheet and screenshot work.
The wedge: Nothing cheap and narrow sits between a manual screenshot folder and a full compliance automation platform. A tool that does one job, produce a dated, carrier-shaped evidence pack per tenant, is a much easier first purchase for an MSP than a compliance suite.
Go-to-market
Sell through MSPs, not to SMBs directly. Lead with a free single-tenant readiness scan that outputs a real gap list, then charge for the multi-tenant dashboard and the exportable pack. Co-market with independent cyber insurance brokers who want cleaner applications.
First 10 customers: Recruit 5 to 10 MSPs from communities such as r/msp and regional MSP peer groups, onboard them free for one renewal season in exchange for weekly feedback, then convert them to paid per-tenant pricing before the next season. Ask each for one broker introduction.
How to set it up
- 1Interview 15 MSPs and 5 brokers and collect real carrier application forms to build the requirements mapping
- 2Build read-only connectors for Microsoft 365 via Microsoft Graph and Google Workspace admin APIs
- 3Ship the evidence pack export first: dated, sourced, and formatted for an underwriter
- 4Add the multi-tenant gap dashboard and remediation checklist
- 5Complete a security review and publish your own posture, since you are asking for privileged access
- 6Onboard 5 to 10 design-partner MSPs through one renewal season, then price and convert
How to validate it
MSPs connecting a second and third tenant without prompting, packs actually submitted to carriers, brokers referring inbound, renewal-season retention above 80 percent, and time-to-pack dropping from days to under an hour.
Key risks
- Handling privileged tenant credentials makes you a security target and a liability if breached; you need real security engineering, not a side project
- Never state or imply that using the product guarantees coverage, a lower premium, or that a claim will be paid; that is regulated territory and a legal exposure
- Carrier requirement drift means ongoing maintenance cost you cannot avoid
- Platform risk if Microsoft ships equivalent native reporting
Your moats
- The maintained mapping between carrier questions and retrievable evidence
- MSP switching cost once dozens of tenants are onboarded
- Broker referral relationships that are slow for a competitor to rebuild
Tools & inspiration
Companies in this space: Vanta, Drata, Datto, Kaseya
FAQ
Found your idea? Here's how to build & launch it
The two steps most founders get stuck on, made simple.
Build your MVP without a developer
Form your US company
Not quite your fit?
Answer a few questions and we'll match you to vetted ideas for your budget, skills, and country.
Find my idea