Checklist · Insurance
Cyber-Insurance Readiness Checklist
Insurers have tightened the screws: the controls below now decide whether you get coverage, what you pay, and — critically — whether a claim is honored. A policy you can’t back with controls is a claim waiting to be denied.
The checklist
If you can check most of these, you’re in strong shape for underwriting. Gaps are where premiums rise — and claims get contested.
How to use it. Go through it before you fill in the application, not after. Insurers no longer take a yes at face value; several now scan your external attack surface independently and compare what they find to what you claimed. Answering optimistically is the single most expensive mistake on this page, because a control you said you had and did not is the ground on which a claim gets denied — after the incident, when you need the money.
Where applications usually fail. MFA that covers email but not remote access or admin accounts. Backups that exist but have never been restore-tested. No documented incident-response plan. Endpoint protection that is antivirus rather than EDR. Each is fixable in weeks, and each moves a premium. If you have a renewal coming, bring the questionnaire to the free 30-minute assessment and we will go through it line by line.
Identity & access
- MFA on email, remote access, and admin accounts — the single most-asked control on every application.
- Least-privilege access, with admin rights limited and reviewed.
- Offboarding that removes access the day someone leaves.
Endpoint & network
- EDR (endpoint detection & response) on every device — not just legacy antivirus.
- A managed firewall and segmented network.
- A patching program with a defined cadence you can evidence.
- Application allowlisting — only approved software can run, so an unapproved executable never starts.
- A vendor risk register — who touches your data, ranked by risk. Carriers now ask how you manage third parties.
Detection & response
- 24/7 monitoring or managed detection & response (MDR).
- Centralized logging (SIEM) so you can reconstruct an incident.
- A written, tested incident-response plan.
Backup & recovery
- Encrypted, immutable backups an attacker can't reach.
- Regular test-restores — insurers increasingly ask when you last did one.
- A documented recovery time and recovery point objective (RTO/RPO).
People & documentation
- Security-awareness training with phishing simulations.
- Written security policies you can produce on request.
- An asset inventory — you can't protect what you can't list.
Answering a renewal questionnaire and unsure how you’d score? We fill these out with clients all the time. See Secure IT →