UM-SA-001 · Revision 4.0The evidence behind Fernleaf’s insurance answers
The renewal form asks about MFA, laptops, backups and email. Here’s what’s true today and what changes before the renewal, with the evidence for each.
Who it’s for
What we checked
MFA on staff accounts, endpoint protection on laptops, backups and restores, and email authentication for fernleaf.example.
The form’s questions
- MFA
- Partly. On for the people who deploy, and on every account after the Identity fix.
- Laptops
- Yes. Managed and encrypted, with endpoint protection.
- Backups
- Partly. Nightly and kept 14 days. A documented restore test comes with the Backups and recovery fix.
- Yes. DMARC at reject, so no one can send as fernleaf.example.
What we found
- MFA covers the people who deploy, not every staff account.
- Backups run nightly but have never been restored in a test.
- Laptops and email already meet what the form asks.
In place now
- Staff laptops managed, encrypted and running endpoint protection.
- SPF, DKIM and DMARC at reject for fernleaf.example.
- Nightly database backups, kept for 14 days.
Planned
- Identity: MFA on every staff account3 to 4 weeks
- Backups and recovery: immutable copies and a documented restore test1 week
Evidence
Every answer on this page points at an item in the evidence index on page 24: exports, policy files, restore logs.
Questions
Want the detail behind a line? Ask Fernleaf for the finding pages, and we’ll walk you through them.
Fictional sample. The company, systems and data are invented; no real client was assessed.