Free Check

Cyber insurance readiness check

13 questions on the controls insurers ask about at quote and renewal. See where you stand and what to fix first.

0 of 13 answered
Is multi-factor authentication (MFA) switched on for every user's email and cloud apps?

1.Is multi-factor authentication (MFA) switched on for every user's email and cloud apps?

Is MFA required for remote access (VPN, remote desktop) and for all administrator accounts?

2.Is MFA required for remote access (VPN, remote desktop) and for all administrator accounts?

Do all laptops, desktops and servers run managed endpoint protection (EDR), not just basic antivirus?

3.Do all laptops, desktops and servers run managed endpoint protection (EDR), not just basic antivirus?

Do you keep at least one backup that ransomware can't reach (offline or immutable), and have you tested restoring it?

4.Do you keep at least one backup that ransomware can't reach (offline or immutable), and have you tested restoring it?

Are critical and high-risk security updates applied within 14 days?

5.Are critical and high-risk security updates applied within 14 days?

Is email filtered for phishing, malicious links and attachments before it reaches staff?

6.Is email filtered for phishing, malicious links and attachments before it reaches staff?

Has every member of staff completed security awareness training in the last 12 months?

7.Has every member of staff completed security awareness training in the last 12 months?

Do you have a written incident response plan that names who to call, including your insurer's breach helpline?

8.Do you have a written incident response plan that names who to call, including your insurer's breach helpline?

Do admins use separate admin accounts (not their everyday login), with access limited to what each person needs?

9.Do admins use separate admin accounts (not their everyday login), with access limited to what each person needs?

Is everything on your network still supported by its vendor (no end-of-life systems, e.g. Windows 10 devices without paid updates)?

10.Is everything on your network still supported by its vendor (no end-of-life systems, e.g. Windows 10 devices without paid updates)?

Do you have an up-to-date inventory of devices, software and cloud accounts?

11.Do you have an up-to-date inventory of devices, software and cloud accounts?

Do you hold a current Cyber Essentials (or Cyber Essentials Plus) certificate?

12.Do you hold a current Cyber Essentials (or Cyber Essentials Plus) certificate?

Do you review which suppliers and third parties can access your systems or data?

13.Do you review which suppliers and third parties can access your systems or data?