Skip to main content

Cyber-insurance readiness check

Cyber-insurance applications ask the same handful of questions every year, and "not sure" is not an answer a carrier accepts. Walk the list, see where you stand, and leave with something you can act on.

Nothing you type here leaves your browser. This page is static and has no server behind it — your answers are never sent, stored, or seen by us. Close the tab and they are gone.

01Is multi-factor authentication required for email and remote access?

Carriers ask this first, and a "no" here is the single most common reason an application gets declined or surcharged.

02Is multi-factor authentication required on administrator accounts?

Asked separately from staff MFA on most applications, because admin accounts are what ransomware operators go after.

03Is endpoint protection running on every company computer?

Applications ask for coverage across all endpoints, not most of them — one unmanaged laptop is what the question is trying to find.

04Are backups kept somewhere ransomware cannot reach them?

Offline, immutable, or otherwise isolated from the network. A backup drive plugged into the server does not count.

05Have you tested restoring from backup in the last twelve months?

A backup job that reports "success" is not a tested restore, and this is the question most owners answer optimistically.

06Is inbound email filtered for phishing and spam?

Most claims start with an email somebody opened.

07Are SPF, DKIM, and DMARC configured on your domain?

These stop someone sending mail that looks like it came from you. Increasingly asked about directly.

08Do departing employees lose access the same day they leave?

Accounts, files, and devices — applications ask about the process, not the intention.

09Do you have a written incident response plan?

Who gets called, in what order, and what happens in the first hour.

10Do you have a written security policy your staff have actually seen?

One page counts. Nothing written down does not.

11Does your team get security awareness training at least once a year?

Usually phrased as phishing-awareness training on the application form.

0 of 11 answered