Cyber Insurance Assessment: Do You Meet Insurer Requirements?

Cyber insurers keep raising the bar at every renewal. This quick check shows how your business measures up against what insurers now expect, so you know where you stand before they ask. It takes about 4 minutes. There are no wrong answers, just answer honestly to get a useful picture.

0 of 26 answered0%
1

Logins & Access

3 questions · 2 top priority
Do your administrators have to use a second step (like a code or app approval) to log in, on top of their password?Top priorityThis second step is called multi-factor authentication, or MFA.
Do your IT administrators use one account for day-to-day work and a separate account for admin tasks?Top priorityKeeping these separate limits the damage if an everyday account is compromised.
Is administrator-level access on computers limited to only the people who truly need it?Most staff should not be able to install software or change system settings.
2

Backups

4 questions · 3 top priority
Do you keep at least one copy of your backups disconnected from your network?Top priorityAn offline or air-gapped copy can't be reached and encrypted by ransomware.
Are your backups protected so that no one, even an administrator, can change or delete them?Top priorityThese are called immutable backups.
Have you actually tested restoring your data from a backup in the last 6 months?Top priorityA backup only counts if you've proven it works.
Are your backups encrypted and protected with a separate password from your other admin accounts?
3

Cloud & Email

4 questions · 2 top priority
Do you require that second login step (MFA) for the cloud systems that hold your sensitive data?Top priorityFor example your file storage, accounting, or CRM.
Do you require that second login step (MFA) to get into email?Top priorityEmail is the most common way attackers get in.
Does a tool scan incoming email for dangerous attachments and links before staff see them?
Has your email been set up to stop scammers from sending messages that look like they come from your company?This is done with settings called SPF, DKIM, and DMARC.
4

Your People

3 questions · 1 top priority
Before sending money or changing payment details, do you require a second person to approve it and a phone call to a known number to confirm?Top priorityThis is the single best defense against wire fraud and fake invoice scams.
Have you sent your staff a fake test phishing email in the last year to see who clicks?These safe simulations show where training is needed.
Do all employees get security awareness training at least once a year?
5

Devices

3 questions · 3 top priority
Is advanced security software installed on every single company device?Top priorityModern tools (often called EDR) detect threats traditional antivirus misses.
Have you replaced or removed all software and operating systems that no longer get security updates?Top priorityFor example old Windows versions that are no longer supported.
Is someone watching your systems for threats around the clock, 24 hours a day?Top priorityThis is usually a Security Operations Center, or SOC.
6

Network & Updates

3 questions · 3 top priority
When staff work remotely, do they connect through a secure connection that also requires that second login step?Top priorityA secure VPN with MFA.
Have you closed off the common remote-access doors that attackers scan for on the open internet?Top priorityLeaving these exposed is one of the top causes of breaches.
Do you install important security updates across your computers within a few days of release?Top priorityUnpatched systems are an easy target.
7

AI Security & Governance

6 questions · 3 top priority
Do you have a written policy telling staff which AI tools are approved and what company information is safe to put into them?Top priorityWithout this, employees often paste sensitive data into free AI tools without realizing the risk.
Do you know every AI tool your staff are actually using, including free ones they signed up for on their own?Top priorityUnapproved tools staff adopt quietly are often called shadow AI.
When you use business AI tools, have you confirmed your data is not being used to train their models and stays confidential?Top priorityConsumer and business versions of the same tool often handle your data very differently.
Have your employees been trained on how to use AI safely, including how to spot when its answers are wrong?AI can state false information confidently. Staff need to know what to double-check.
If AI helps make a decision that affects a customer or employee, can a person review and override it?Keeping a human in the loop protects you from automated mistakes and bias.
Is someone at your organization clearly responsible for overseeing how AI is used?A named owner keeps AI use accountable rather than accidental.
0out of 100
Your Cyber Insurance Score
Calculating

Want Help Closing the Gaps?

Book a free 30-minute review with an i-Tech advisor. We'll walk through your results in plain English, show you what to fix first, and answer any questions, no pressure and no obligation.

Your answers stay private and are only used to prepare your review.

Beyond Security

Securing AI Is Only Half the Job

Adoption is where AI value is won or lost, and it is the part most providers skip. Governance keeps you safe. The platform gives you access. Enablement is what turns it into results.

  • Governance: Policies, guardrails, and oversight that keep your data protected and your AI use compliant. This keeps you safe.
  • Platform: The tools and secure access your team needs to put AI to work day to day. This gives you access.
  • Enablement: Role-based training on how to prompt, what to trust, and where AI helps, tied to how your organization actually works. This is what turns access into results.

Most providers stop at governance and a login. We go further, because a platform nobody knows how to use is not a result. It is a cost.

Cloud icon overlaid on a digital circuit board background, symbolizing cloud computing and technology integration