Does the Applicant use a cloud provider, and which provider stores the largest quantity of sensitive records?
This question is about the carrier's portfolio as much as about yours. They are modelling what happens if one platform has a very bad day.
What the carrier is actually asking
The carrier is asking whether you use cloud providers and which one holds the largest quantity of sensitive records. It is a concentration question, and it usually extends to the major software-as-a-service platforms rather than only infrastructure providers.
Why it is underwritten
Cyber carriers hold correlated exposure: a systemic event at a major platform would produce claims across a large part of their book simultaneously. Understanding where each insured's data sits lets them model that aggregation. For you, the answer also determines who your critical dependency actually is.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Which providers hold your data is measurable for the platforms Insurance Posture reads, and attested for the rest.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Azure | Storage accounts and databases holding regulated data, with their regions | Where structured and unstructured sensitive data resides |
| Microsoft 365 | Content discovery across mail, SharePoint, and OneDrive | The collaboration footprint, which frequently holds more sensitive records than anyone expects |
| AWS | Storage and database services holding regulated data | The AWS footprint where present, since multi-cloud estates split this answer |
| Vendor register | Software-as-a-service platforms holding customer or employee data | The customer platform, the human resources platform, and the support tool, which collectively often exceed the infrastructure footprint. Attested |
| Data map | Record counts per platform | An estimate with a stated method, since the question asks about quantity |
Organisations name their infrastructure provider because the question says cloud provider. The platform holding the most sensitive records is frequently the customer relationship system or the human resources platform. Naming the real one is more useful to the underwriter and more useful to you.
What a defensible yes requires
- The answer reflects where records actually are rather than where infrastructure runs.
- Software-as-a-service platforms are included in the comparison.
- Record quantities are estimated with a describable method.
- Regions and residency are known for each major holding.
- Concentration is understood, including providers that depend on the same underlying platform.
How this answer goes wrong
The infrastructure provider is named because it is the recognisable cloud brand, while the largest holding of personal data sits in a customer platform nobody mentioned. The carrier's aggregation model is then wrong, and so is your own understanding of your critical dependency.
Frequently asked
Does using a major cloud provider count against us?
Not usually at the individual level. It matters to the carrier portfolio modelling and rarely to your own pricing.
What if we are multi-cloud?
Say so and give the split. Multi-cloud reduces single-platform dependency and adds complexity, and carriers assess both.
Should SaaS platforms be included?
Yes. They hold most of the sensitive records in most modern organisations, and excluding them produces an answer that misses the point of the question.
How precise should record counts be?
An order of magnitude with a method. The carrier wants relative concentration rather than an exact figure.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture