Guide · Checklist
Cyber-insurance readiness checklist
Twenty items. Tick them honestly before the renewal form arrives and there are no surprises on the premium. Print this page; it's designed to.
Technical controls
| # | Control | Evidence to keep | Done |
|---|---|---|---|
| 1 | MFA enforced on all email accounts, no exceptions | Tenant policy screenshot | ☐ |
| 2 | MFA on remote access (VPN / RDP) and all admin consoles | Config screenshots | ☐ |
| 3 | EDR / next-gen antivirus on every laptop, desktop and server | Console device count | ☐ |
| 4 | Full-disk encryption on every laptop | Asset register column | ☐ |
| 5 | Daily backups with one immutable or offline copy | Backup job report | ☐ |
| 6 | Restore tested in the last quarter | Restore-test log | ☐ |
| 7 | Critical patches applied within 14 days, incl. firewall / VPN firmware | Patch report | ☐ |
| 8 | No standard users with local admin rights | Access register | ☐ |
| 9 | Email filtering with external-sender banner and link scanning | Config screenshot | ☐ |
| 10 | Inactive accounts disabled after 45 days; leavers disabled on last day | Offboarding checklist | ☐ |
Documents and process
| # | Item | Evidence to keep | Done |
|---|---|---|---|
| 11 | Written security policies (minimum 8) approved and dated | Signed policy set | ☐ |
| 12 | Employee acknowledgement form signed by every user | HR file | ☐ |
| 13 | Incident response plan with named roles and 24h contacts | The plan, printed | ☐ |
| 14 | Tabletop exercise run in the last 12 months | Exercise record | ☐ |
| 15 | Hardware inventory with encryption and EDR status | Asset register | ☐ |
| 16 | Software / SaaS inventory with data class and MFA status | Asset register | ☐ |
| 17 | User access list reviewed in the last 6 months | Review date column | ☐ |
| 18 | Written rule: bank-detail changes verified by phone to a known number | Phishing / payments policy | ☐ |
| 19 | Security awareness briefing in the last 12 months | Attendance record | ☐ |
| 20 | Vendor register listing every third party holding company data | SaaS tab / vendor register | ☐ |
Scoring
Items 1 to 7 are what moves the premium; a "no" on any of them is what produces ransomware sub-limits and exclusions. Items 11 to 17 are what a claim adjuster asks for after the fact. If you're short on time, do the first seven this month and the paperwork next month; the question-by-question guide explains what each one is testing.
Want the documents done for you?The Small Business Cyber Compliance Kit is the written policy set, incident response plan and asset register described here, as editable Word and Excel files: CA$39, instant download. Get the complete kit