Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Free Cyber Insurance Checklist:
Find Out If Your Business Would Qualify

Free 2-Minute Assessment

  • 9 quick questions
  • Takes about 2 minutes
  • No sign-up to see your result

Your top next moves

    Nothing critical flagged. Keep everything current and re-check yearly.

    Book a call

    Use the interactive cyber insurance checklist below to see where your business stands on the controls underwriters actually evaluate. 9 quick questions to get your readiness score in about 2 minutes, your risk level, the specific gaps to close, and a report you can hand to your IT team.

    No sign-up to see your result.

    What Underwriters Actually Check (The Short Version)

    Cyber insurance underwriting has changed. Carriers used to ask broad questions about firewalls and antivirus. Today most applications run a two-to-three page technical questionnaire, and a “no” or “not sure” on certain controls can trigger a coverage exclusion, a premium spike, or an outright denial before your application reaches a human reviewer.

    The controls underwriters now treat as baseline are specific and consistent across most carriers.

    The checklist below maps directly to the 9 assessment questions in the tool above:

    The Cyber Insurance Readiness Checklist

    Work through each control. Anything you can’t confirm with documentation is a gap, and if you can’t confirm it, your underwriter will find it.

    • 1. Multi-Factor Authentication (MFA) on all Accounts and Remote Access:

      MFA is enforced on every employee’s email account, not just a subset, not just executives.

      MFA is enforced on every remote access tool: VPN, Remote Desktop (RDP), remote-monitoring software, cloud admin portals.

      Partial MFA rollout counts as a gap on most applications. Underwriters check for “all accounts” coverage.

      Why it matters: Stolen credentials with no MFA were the initial access vector in 56% of investigated compromises, per Rapid7 Q1 2025 Incident Response Findings

    • 2. Managed Endpoint Detection and Response (EDR or MDR) on Every Device:

      An EDR or MDR solution, not just traditional antivirus, is installed and active on every company laptop, desktop, and server.

      The tool provides 24/7 monitoring coverage, not just scheduled scans or alerts that sit unread until morning.

      Coverage extends to servers. Carriers increasingly ask about server coverage explicitly.

    • 3. Offline or Immutable Backups with a Tested Restore:

      Backups are stored in a location ransomware cannot reach or delete: offline (air-gapped), immutable object storage, or a separate cloud tenant with write-once protections.

      A restore from backup has been successfully tested in the past 12 months, with the date and result documented. An untested backup does not count as a working backup on most applications.


      Why it matters: In 94% of ransomware attacks, threat actors attempted to compromise the victim’s backups before or during the attack, source: Sophos

    • 4. Advanced Email Filtering and DMARC Enforcement:

      An advanced email security tool (beyond the default spam filter bundled with your email platform) filters phishing emails and malicious links before they reach employee inboxes.

      Your domain’s DMARC record is set to quarantine or reject, not just monitoring mode (p=none). SPF and DKIM records are also in place.

      Spoofed email sent in your company’s name is blocked at the source. DMARC enforcement is one of the most common underwriter checkboxes.

    • 5. Written and Tested Incident Response Plan:

      A documented incident response plan exists that names who calls whom, what gets isolated, and who your outside counsel and cyber insurer contact numbers are, all reachable within the first two hours of an incident.

      The plan has been tested at least once, even informally (a tabletop walkthrough counts). An untested plan is better than nothing, but carriers ask whether it has been exercised.

      Most applications now require attestation that an IR plan exists; some ask for the date of the last test.

    • 6. Critical Patches Applied Within 14 Days:

      A defined patching policy requires critical and high-severity security patches to be applied within 14 days of release across operating systems, browsers, and internet-facing applications.

       Regular vulnerability scans run on a documented schedule to surface what is exposed. The results are acted on, not filed.

       Unpatched internet-facing systems are a leading initial-access vector; carriers increasingly set specific timelines rather than accepting “best effort.”

    • 7. Separated Administrator and Privileged Accounts:

      ✓ Administrator accounts are separate from everyday user accounts. IT staff use standard accounts for email and browsing, and a separate privileged account only for admin tasks.

       Someone can produce a current list of exactly who holds admin rights right now.

      ✓  Shared credentials on service accounts and local admin accounts** are stored in a password vault, not a shared spreadsheet or a sticky note.

       Compromise of one admin account should not provide access to every system. Carriers flag over-provisioned admin access and shared admin passwords as high-risk indicators.

    • 8. Documented Security Awareness Training and Phishing Simulations

      All employees complete cybersecurity awareness training at least annually, with completion records maintained.

      ✓ Simulated phishing tests run on a regular basis (quarterly is the carrier-favored cadence). Employees who click receive immediate re-training, not just a warning email.

       Training completion records are kept and available for audit. Carriers have started requesting them at renewal.

    How to read your gaps?

    Most of the technical items above (MFA, encryption, audit logging, tested backups) live in your IT setup, not a policy binder, which is the half of HIPAA a managed IT partner operates for you.

    • 0 – 1 Gaps No Missing Critical Controls

      Your controls match what most carriers look for on a standard SMB application, document your evidence now so you can answer each question with specifics.

    • 2 – 4 Gaps or One Missing Critical Control (MFA, EDR, or Backups)

      You likely face a coverage exclusion on ransomware or a premium increase. Most gaps are fixable in 30 to 60 days.

    • 5+ Gaps or Two or More Missing Critical Controls

      Submitting an application now risks outright denial. Quick action before your renewal deadline changes the outcome. The four critical controls in this checklist are the ones where a “no” most often triggers automatic adverse action.

    Cyber Insurance Checklist FAQ

    What do underwriters look for on a cyber insurance application?

    Underwriters have moved away from broad security questions to specific, verifiable controls. The items that appear on nearly every current carrier application are: MFA enforced on all accounts and remote access tools; EDR or MDR with 24/7 coverage on every endpoint and server; offline or immutable backups with a documented, tested restore in the past year; advanced email filtering with DMARC enforcement at quarantine or reject; a written and tested incident response plan; a defined patch-management timeline (usually 14 days for critical patches); separated administrator and privileged accounts; and documented security awareness training with phishing simulations. The checklist above covers each of these.

    What is the difference between cyber insurance eligibility and compliance?

    Eligibility is about satisfying your carrier’s underwriting controls, the security hygiene questions that determine whether they will insure you and at what price. Compliance (HIPAA, PCI DSS, FTC Safeguards, CMMC) is about meeting a regulatory framework and is assessed by an auditor or assessor. These overlap significantly, many of the same technical controls appear in both, but they are different processes with different timelines and different consequences for gaps. Your IT provider helps you close the technical gaps that affect both.

    What happens if I answer “no” on a cyber insurance application?

    It depends on which control. Critical controls, MFA, backups, EDR, often trigger automatic adverse underwriting action: denial, a ransomware exclusion, or a significant premium increase. Other gaps (patching cadence, training documentation) are more commonly flagged for follow-up or rated into the premium. The practical answer is to know your gaps before you submit the application, not after. The tool above gives you that read in two minutes.

    How long does it take to close cyber insurance gaps?

    The critical controls, MFA, EDR deployment, immutable backups with a tested restore, DMARC enforcement, can typically be addressed in 30 to 60 days with a focused effort. Training programs and written IR plans are often faster, because they are documentation and process work rather than technical rollouts. The timeline depends heavily on your current IT setup and whether you have an IT partner managing implementation. LeadingIT has addressed these gaps for Chicagoland businesses in time for their renewal deadlines since 2010.

    Do small businesses need all of these controls to get cyber insurance?

    Yes. Carrier requirements do not scale down for small businesses the way some compliance frameworks do. The controls above are the minimum underwriters expect regardless of company size. Small businesses are more frequently targeted precisely because they are perceived as less protected, and carriers know this. That said, small businesses with fewer employees and simpler IT environments can typically complete a remediation sprint faster than larger organizations.

    Is this tool a formal cyber insurance assessment?

    No. This is a fast self-assessment based on the controls most commonly evaluated during the underwriting process. It is designed to give you a clear read on where your gaps are before your application goes to a carrier, not to certify readiness or replace the carrier’s own questionnaire. For a formal assessment that produces documentation a carrier or broker can work from, schedule a readiness review with LeadingIT.

    How do cyber insurance requirements differ from HIPAA or PCI compliance?

    The controls overlap significantly, MFA, encryption, access control, audit logging, and training appear in all three frameworks, but the drivers are different. HIPAA is a federal law with OCR enforcement and mandatory breach notification; PCI DSS is enforced through your merchant agreement by card brands; cyber insurance eligibility is enforced through your policy terms and at renewal. Failing one does not automatically mean failing the others, but closing your technical gaps improves your posture across all three at once.

    Ready to close your gaps before renewal?

    If your result flagged two or more controls as missing or uncertain, those gaps are addressable, most in 30 to 60 days. LeadingIT helps Chicagoland businesses implement the security controls underwriters require: MFA, EDR, immutable backups, email security, patch management, and documented training programs. We have supported roughly 200 organizations and 2,500+ users from our Woodstock and Manteno offices since 2010.

    We are not a cyber insurance carrier or broker, we operate the security controls that get you to the “yes” column on your application and keep you there at renewal. Book a call or call us at 815-788-6041 to understand what we manage day to day.