Bitweb
Guide · Checklist

Cyber-insurance readiness checklist

Twenty items. Tick them honestly before the renewal form arrives and there are no surprises on the premium. Print this page; it's designed to.

By a working IT technician supporting 400+ users · Updated September 2026 · Printable

Technical controls

#ControlEvidence to keepDone
1MFA enforced on all email accounts, no exceptionsTenant policy screenshot
2MFA on remote access (VPN / RDP) and all admin consolesConfig screenshots
3EDR / next-gen antivirus on every laptop, desktop and serverConsole device count
4Full-disk encryption on every laptopAsset register column
5Daily backups with one immutable or offline copyBackup job report
6Restore tested in the last quarterRestore-test log
7Critical patches applied within 14 days, incl. firewall / VPN firmwarePatch report
8No standard users with local admin rightsAccess register
9Email filtering with external-sender banner and link scanningConfig screenshot
10Inactive accounts disabled after 45 days; leavers disabled on last dayOffboarding checklist

Documents and process

#ItemEvidence to keepDone
11Written security policies (minimum 8) approved and datedSigned policy set
12Employee acknowledgement form signed by every userHR file
13Incident response plan with named roles and 24h contactsThe plan, printed
14Tabletop exercise run in the last 12 monthsExercise record
15Hardware inventory with encryption and EDR statusAsset register
16Software / SaaS inventory with data class and MFA statusAsset register
17User access list reviewed in the last 6 monthsReview date column
18Written rule: bank-detail changes verified by phone to a known numberPhishing / payments policy
19Security awareness briefing in the last 12 monthsAttendance record
20Vendor register listing every third party holding company dataSaaS tab / vendor register

Scoring

Items 1 to 7 are what moves the premium; a "no" on any of them is what produces ransomware sub-limits and exclusions. Items 11 to 17 are what a claim adjuster asks for after the fact. If you're short on time, do the first seven this month and the paperwork next month; the question-by-question guide explains what each one is testing.

Want the documents done for you?The Small Business Cyber Compliance Kit is the written policy set, incident response plan and asset register described here, as editable Word and Excel files: CA$39, instant download. Get the complete kit
The cyber-insurance questionnaire, question by question12 questions, what "yes" needs, which document proves itAn incident response plan a small business will actually useRoles, severity levels, first-hour checklist, three playbooksWhat an IT asset inventory needs to track (and what it can skip)The columns insurers and auditors look for