Cyber insurance has become more common for small and midsize businesses.
But many companies are surprised by how technical the application questions can be.
Insurance providers may ask about multi-factor authentication, endpoint protection, backups, email security, patching, remote access, employee training, incident response, and administrator controls.
If your business is not prepared, these questions can be difficult to answer.
Here is a practical IT checklist to review before completing a cyber insurance application.
Many cyber insurance applications ask whether MFA is enabled.
MFA should be used for:
If MFA is not enabled, your business may face higher risk and possible insurance concerns.
Endpoint protection helps defend computers and servers from malware, ransomware, and suspicious activity.
Your business should know:
Unprotected devices create risk.
Email is a major attack path.
Cyber insurance may ask about phishing protection, spam filtering, malicious link protection, attachment scanning, and user training.
Your business should also review SPF, DKIM, and DMARC records where appropriate.
Insurance providers often ask whether backups exist and whether they are protected.
Review:
Backups should not be assumed. They should be verified.
Outdated software can create security risk.
Your business should have a process for applying updates to:
Patch management should not depend on someone remembering manually.
Remote access should be controlled and protected.
Review VPN, remote desktop, remote access tools, and third-party access.
Remote access should use MFA where possible and should be limited to users who actually need it.
Administrator access should be limited.
Not every user should be an admin on their computer or inside Microsoft 365.
Review local admin rights, domain admin rights, cloud admin roles, and vendor admin access.
Employees should know how to spot phishing emails, suspicious links, fake invoices, and unusual MFA prompts.
Training helps reduce preventable security incidents.
Your business should know what to do during a cyber incident.
An incident response plan should include:
MTech helps businesses prepare for cyber insurance questions by reviewing practical security controls.
We can help with MFA, endpoint protection, email security, backups, patching, remote access, admin controls, employee training, and incident response planning.
Cyber insurance is not only paperwork. It often reveals whether your business has the right security basics in place.
If you are unsure how to answer a cyber insurance application, MTech can help review your environment and identify what needs attention first.