Insurers now underwrite on controls rather than intent. The application asks what you actually enforce, meaning multi-factor authentication, privileged access and logging, and then asks where. 'Everywhere' turns out to be broader than most teams assume.
Email and the admin console are the obvious ones. The application also reaches your VPN, your cloud root accounts, your build pipeline, your backups and your domain registrar. A single service account or break-glass login outside that perimeter is the difference between an accurate answer and an inaccurate one.
We check the places we can reach: your email, your admin console, your cloud accounts, your code and your DNS. Then we show you where coverage stops, per account rather than per policy. Where it stops, agents prepare the change and make it once you approve, so by the time you sign the application the answer you are giving is the true one.
A control attestation is part of the contract. In 2022 an insurer rescinded a policy from inception after discovering multi-factor authentication had been deployed on the firewall only, contrary to the application. That is rare, and it is not the common case. But it is a bad way to discover the gap.
You are not trying to look good on the form. You are trying to be able to sign it.