The 12 checks in this quiz
Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.
Identity
-
Is MFA enforced on email, on remote access (VPN/RDP), and on admin accounts?
Enforce MFA on email, all remote access and admin accounts. It is the single most-asked question on cyber insurance applications, and often a hard requirement.
-
Are privileged/admin accounts separated from everyday accounts and limited to those who need them?
Separate admin accounts from daily-use accounts and limit who holds them. Insurers ask about privileged-access controls.
Endpoints & email
-
Do you run managed endpoint detection and response (EDR) on all computers?
Deploy EDR (not just basic antivirus) across all devices. Many insurers now require it or price it in.
-
Do you have email security filtering for phishing, spoofing and malicious attachments?
Add email security filtering on top of the mailbox default. Phishing is the most common claim trigger.
-
Are systems patched promptly, with end-of-life software and hardware removed?
Patch promptly and retire end-of-life systems. Insurers ask about your patch cadence and unsupported software.
-
Is remote access locked down, no Remote Desktop (RDP) exposed directly to the internet, VPN protected by MFA?
Close any internet-exposed RDP and put remote access behind a VPN with MFA. Open RDP is a top ransomware entry point and a common application question.
Backup & recovery
-
Are backups automated, kept offline or immutable (or off-site), and is recovery tested?
Automate backups, keep a copy offline or immutable, and test recovery. Insurers ask specifically about offline/immutable backups for ransomware.
-
Do you encrypt sensitive data and laptops?
Encrypt laptops and sensitive data. It limits breach liability and is a standard application item.
Response & governance
-
Do you have a written incident-response plan?
Write an incident-response plan covering who to call and the first steps. Applications ask whether you have one.
-
Do you have logging and monitoring, or a managed service (MDR/SOC), watching for threats?
Stand up monitoring or a managed detection service so threats are seen quickly. Better-prepared applicants get better terms.
-
Do employees get regular security-awareness and phishing training?
Run regular awareness and phishing training and keep records, insurers ask, and it lowers your actual claim risk.
-
Do you vet vendors and partners that have access to your systems or data?
Review vendors with access to your environment. Third-party risk is an increasing focus for underwriters.
Insurable and actually secure are the same checklist
The controls that get you a better premium, MFA, EDR, tested backups, email filtering, an incident plan, are the same ones that stop the incident in the first place. We help Canadian businesses put them in place, document them for the application, and keep them running so a claim actually pays.