Skip to content

Free tool · 8 controls · Private to your browser

Would your renewal answers survive a claim?

Cyber-insurance carriers now require enforced MFA, EDR, and tested backups — and a wrong answer can void a claim. Score your real environment against the 8 controls they ask about. Nothing is sent anywhere; the math runs on this device.

For each control, pick the honest answer for your business today. "Enforced & documented" means you could show a carrier evidence; "partial or unsure" is scored as the risk it is.

  1. First-checked MFA is enforced on every email account, with legacy sign-in protocols disabled.

    The single most common application question — and the one most often answered "yes" when it is only partly true.

  2. First-checked MFA is required for remote access (VPN, remote desktop) and every privileged / admin account.

    Everyday-user MFA is not enough. Carriers ask specifically about remote paths and admins, because that is where ransomware gets in.

  3. First-checked Modern EDR (behavioral detection + response) runs on every endpoint — not legacy antivirus.

    A named requirement on most applications. "Antivirus" is not EDR, and the difference is checked.

  4. First-checked Backups are separated / offline / immutable — reachable ransomware cannot encrypt them.

    A backup the attacker can delete with the same stolen credentials is not a backup a carrier credits.

  5. First-checked Backups are tested with documented restores on a schedule.

    A green checkmark is not a test. Carriers mean periodic, documented restore tests you can show.

  6. Patching runs on a managed, described cadence across OS and third-party software.

    You should be able to describe the timeline for critical vulnerabilities, not just "we update sometimes."

  7. Staff get recurring security-awareness training and phishing simulations.

    A one-time onboarding video no longer satisfies the question on newer applications.

  8. A written incident-response plan exists, names who does what, and is reachable when systems are down.

    The plan has to exist before the incident, and somewhere you can still open it during one.

Reading this without JavaScript?

The list above is a complete renewal checklist on its own. Any control you cannot answer with a documented "yes" is a control worth closing before you sign an application. The cyber-insurance readiness page decodes exactly what each carrier question means, and the free IT Health Check walks your actual environment against all eight.

Want the gaps closed before your renewal?

Book the free IT Health Check

An honest word on what this is

This is a self-check, not underwriting advice, and we are not an insurance broker. It will not fill out your application or quote your premium. What it does is show you, privately, which technical answers your environment can defend today — so the "yes" you sign is one a claim investigation can't take back. If a control isn't in place, we'd rather you know now than after an incident.

Straight answers

Is this the same as filling out my insurance application?

No. This is a private self-check that shows you where your real environment stands against the controls carriers ask about. It is not underwriting advice and we are not an insurance broker — your broker owns the policy conversation. What this does is tell you which answers you could defend today, before you sign a document that says otherwise.

Why three answers instead of yes/no?

Because "partially" is the dangerous answer. The most common way a claim gets rescinded is an "aspirational yes" — answering yes because MFA is mostly on, or backups probably restore. If a post-incident investigation finds the answer was wrong on the day you signed, the carrier can rescind the policy. "Partial or not sure" is scored as the risk it actually is.

Which controls should we fix first?

Enforced MFA with legacy authentication disabled, then EDR, then separated and tested backups. Those appear on every application we have seen and are the three most often misstated. This check flags any of them that is not a documented yes, no matter your overall score.

Does a good score mean my claim is guaranteed?

No — nothing guarantees a claim, and coverage terms are between you and your carrier. A strong score means the technical answers on your application are ones your environment can back up with evidence, which is exactly what a claim investigation looks for. Treat it as readiness, not a promise.

Renewal coming up?

Bring the application. In a free 30-minute IT Health Check we'll walk every question against your real environment and tell you, in writing, which answers are defensible today and which need work first.