General Security

Cyber Insurance Readiness Checklist for Small Businesses

A plain-language guide to checking your safeguards, gathering evidence, and preparing to answer a cyber insurance application.

Before you answer an application question, check what is actually in place. This guide helps you gather proof, spot gaps, and decide what to ask your broker.

Before you start

Cyber insurance applications ask about safeguards such as multifactor authentication (MFA), backups, and incident response. Before answering, check the systems and people each question covers. A product subscription or planned fix alone is not proof that a safeguard is working.

Applications and policies differ. Use your insurer's wording, and ask your broker or insurer when a question is unclear or your answer is not a clear yes or no. This guide helps you prepare; it is not an insurance application or advice about what a policy covers.

Seven things to check

Keep the application nearby and review these areas with whoever manages your technology. For each one, note what you checked, what evidence you found, and what still needs attention. These are prompts, not universal insurance requirements.

  • What is covered—and what is not?
  • What evidence can you keep, and when was it checked?
  • Who will follow up on any gaps?

1. Check sign-in protection

Check whether MFA is required—not just available—for email, administrator accounts, remote access, and important services such as payroll and banking. Include outside providers and shared accounts. Ask your IT provider to identify any accounts or sign-in methods that are exceptions.

  • Keep a dated list of accounts checked and the MFA settings or report you reviewed.
  • Record exceptions and how they are protected. A user having an authenticator app does not prove MFA is enforced.

2. Check computers and alerts

Compare your list of business computers and servers with the devices shown in your protection software. Buying a product does not prove that it is installed and working—or that anyone responds to alerts.

  • Ask who checks alerts, when they do so, and what happens if a device needs to be isolated.
  • Keep a recent device-coverage report and note unsupported or unprotected equipment. For equipment that cannot run standard protection software, ask the equipment vendor about alternatives.

3. Check updates

Operating systems are only part of the picture. Ask who updates business applications, browsers, network equipment, and remote-access tools, and how they check that important fixes were installed.

  • Keep a current system list and a recent update report.
  • Note overdue or unsupported systems, who is fixing them, and when you will check again. A scheduled update is not a completed fix.

4. Test your backups

A successful backup job does not prove you can recover your files. Check what is backed up, how often, and how long copies are kept. Cloud file syncing alone may not protect you from unwanted deletion or changes.

  • Include important cloud services and business records in your review.
  • Ask when someone last restored files in a safe test, what was restored, and how long it took. Keep the test results and follow up on any failures.

5. Prepare employees

Make sure employees know how to report a suspicious message and verify a payment change. Use examples they see at work, such as a supplier sending new bank details.

  • Keep training and attendance records, plus your written payment-change procedure.
  • Verify changes using a phone number or contact method already on file—not details in the new request.

6. Review outside access

Your IT provider, bookkeeper, or equipment vendor may have access to business systems. Know which accounts and remote-support tools they use, and how to remove access when it is no longer needed.

  • Keep a list of outside users, the tools they use, and the access they need.
  • Ask who approves access, how often it is reviewed, and who can turn it off. Keep access reviews or account-removal records.

7. Know who to call

Keep an incident contact list somewhere you can reach if business email is unavailable. Check your policy for how and when to report an incident; do not assume that contacting your broker alone meets the notice instructions.

  • List your incident lead, IT provider, insurer's reporting contact, and bank-fraud contact.
  • Note any policy instructions about approved response providers or getting approval for expenses.
  • Keep the policy section or page number and review the plan with your team.

Make a short action list

For each gap, write down what needs to change, who will handle it, and a target date. Keep evidence and exceptions with the application, and revisit the list before renewal. Do not mark planned work as complete.

  1. If MFA covers email but not a remote-support account, note the difference rather than treating all accounts as covered.
  2. Ask your broker or insurer how to answer if the application only offers yes or no.
  3. Update your notes when a fix is finished and verified.

Questions for your broker

Your security controls and insurance coverage are related, but they are not the same thing. Ask your broker:

Do not assume that an email-related loss, cargo theft, or payment to a scammer is covered. Ask which policy terms apply to your situation.

  • What incidents and costs are covered, and what exclusions or limits should we understand?
  • How does the policy treat fraudulent payment instructions or funds-transfer fraud?
  • How and when must we report an incident? Do we need approval before hiring responders or spending money?
  • How should we report a safeguard that is only partly in place?

Find guidance for your industry

For guidance tailored to your business, see our pages for:

Sources

These guides offer general preparation advice. Your insurer's application and policy wording govern your answers and coverage.

Know what your business can prove

The Business Security Baseline checks internal safeguards within an agreed scope. It is $1,995 for businesses with up to 25 employees; larger businesses receive a confirmed quote. It does not determine insurance eligibility or coverage.

Ask About the Business Security BaselineSee what the free public-signal review checks