← Strondex

Cyber Insurance Prep Checklist

Free preview. You're seeing the first 10 of 47 controls. 47 controls underwriters actually check — know exactly where you stand before renewal.
Controls Underwriters Require Every Time 10 controls
CRITICAL CI-01 MFA

Require multi-factor authentication on every email account.

How to verify / fix

Turn on MFA for all mailboxes (in Microsoft 365, enforce it via a Conditional Access policy or Security Defaults; in Google Workspace, enforce 2-Step Verification). Evidence: export the per-user MFA registration report and keep a screenshot of the enforcement policy showing it applies to all users.

CRITICAL CI-02 MFA

Require MFA for all remote access — VPN, RDP, and SSH.

How to verify / fix

Place every remote-access path behind MFA (VPN client, RDP gateway, SSH bastion or jump host). Evidence: capture the MFA configuration screen for each gateway and a sample authentication log showing the second factor being challenged.

CRITICAL CI-03 MFA

Require MFA for every privileged and administrator account.

How to verify / fix

Enforce MFA on all admin roles — domain admins, M365 Global Admins, server local admins, and SaaS admin consoles. Evidence: list your privileged accounts and show MFA is registered on each; a Conditional Access policy scoped to admin roles is the cleanest proof.

CRITICAL CI-04 MFA

Require MFA for all cloud service consoles (AWS, Azure, M365 admin).

How to verify / fix

Enable MFA on every cloud root/owner and admin login — AWS root and IAM users, Azure/Entra admins, M365 admin center. Evidence: screenshot each console's MFA status page (e.g. AWS IAM credential report showing mfa_active, Entra authentication-methods report).

CRITICAL CI-05 Backups

Take offline or immutable backups at least weekly.

How to verify / fix

Confirm backups run at minimum weekly to media that ransomware can't reach — immutable cloud storage, object lock, or offline media. Evidence: keep the backup schedule configuration and a recent job-success report showing the cadence and the immutability/offline setting.

CRITICAL CI-06 Backups

Store backups separately from production — offsite or in the cloud.

How to verify / fix

Ensure at least one backup copy lives outside the production environment so a single breach can't destroy both. Evidence: document the backup architecture (the "3-2-1" copy showing the offsite/cloud location) and capture the storage configuration confirming separation.

CRITICAL CI-07 Backups

Test backup restoration at least once in the last 12 months.

How to verify / fix

Perform an actual test restore — recover a file set or system and confirm it works; a backup you've never restored is not a backup. Evidence: keep a dated restore-test record noting what was recovered, by whom, and the outcome. Underwriters frequently ask for the date of your last successful test.

HIGH CI-08 Backups

Define and document a recovery time objective (RTO).

How to verify / fix

Decide and write down how quickly each critical system must be back online after an outage. Evidence: a short documented RTO (per system or business-wide) in your continuity or backup policy is enough to satisfy the application question.

HIGH CI-09 Endpoint

Deploy Endpoint Detection & Response (EDR) on all endpoints.

How to verify / fix

Install a modern EDR agent (e.g. CrowdStrike, SentinelOne, Microsoft Defender for Endpoint) on every server and workstation — not just legacy antivirus. Evidence: export the EDR console's device-coverage report and note the deployment percentage against your total asset count.

HIGH CI-10 Endpoint

Actively manage EDR — alerts are monitored, not just installed.

How to verify / fix

Ensure EDR alerts go to a person or a managed service (MDR/SOC) who reviews and responds, around the clock if possible. Evidence: name who monitors alerts (internal team or MDR provider) and keep the service contract or an example of an investigated/closed alert.

37 more controls — unlock the full checklist

The full Cyber Insurance Prep Checklist has 47 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.

Not ready to buy? Try the free Cyber Insurance Readiness Score.