Cyber Insurance Prep Checklist
Controls Underwriters Require Every Time 10 controls
Require multi-factor authentication on every email account.
How to verify / fix
Turn on MFA for all mailboxes (in Microsoft 365, enforce it via a Conditional Access policy or Security Defaults; in Google Workspace, enforce 2-Step Verification). Evidence: export the per-user MFA registration report and keep a screenshot of the enforcement policy showing it applies to all users.
Require MFA for all remote access — VPN, RDP, and SSH.
How to verify / fix
Place every remote-access path behind MFA (VPN client, RDP gateway, SSH bastion or jump host). Evidence: capture the MFA configuration screen for each gateway and a sample authentication log showing the second factor being challenged.
Require MFA for every privileged and administrator account.
How to verify / fix
Enforce MFA on all admin roles — domain admins, M365 Global Admins, server local admins, and SaaS admin consoles. Evidence: list your privileged accounts and show MFA is registered on each; a Conditional Access policy scoped to admin roles is the cleanest proof.
Require MFA for all cloud service consoles (AWS, Azure, M365 admin).
How to verify / fix
Enable MFA on every cloud root/owner and admin login — AWS root and IAM users, Azure/Entra admins, M365 admin center. Evidence: screenshot each console's MFA status page (e.g. AWS IAM credential report showing mfa_active, Entra authentication-methods report).
Take offline or immutable backups at least weekly.
How to verify / fix
Confirm backups run at minimum weekly to media that ransomware can't reach — immutable cloud storage, object lock, or offline media. Evidence: keep the backup schedule configuration and a recent job-success report showing the cadence and the immutability/offline setting.
Store backups separately from production — offsite or in the cloud.
How to verify / fix
Ensure at least one backup copy lives outside the production environment so a single breach can't destroy both. Evidence: document the backup architecture (the "3-2-1" copy showing the offsite/cloud location) and capture the storage configuration confirming separation.
Test backup restoration at least once in the last 12 months.
How to verify / fix
Perform an actual test restore — recover a file set or system and confirm it works; a backup you've never restored is not a backup. Evidence: keep a dated restore-test record noting what was recovered, by whom, and the outcome. Underwriters frequently ask for the date of your last successful test.
Define and document a recovery time objective (RTO).
How to verify / fix
Decide and write down how quickly each critical system must be back online after an outage. Evidence: a short documented RTO (per system or business-wide) in your continuity or backup policy is enough to satisfy the application question.
Deploy Endpoint Detection & Response (EDR) on all endpoints.
How to verify / fix
Install a modern EDR agent (e.g. CrowdStrike, SentinelOne, Microsoft Defender for Endpoint) on every server and workstation — not just legacy antivirus. Evidence: export the EDR console's device-coverage report and note the deployment percentage against your total asset count.
Actively manage EDR — alerts are monitored, not just installed.
How to verify / fix
Ensure EDR alerts go to a person or a managed service (MDR/SOC) who reviews and responds, around the clock if possible. Evidence: name who monitors alerts (internal team or MDR provider) and keep the service contract or an example of an investigated/closed alert.
37 more controls — unlock the full checklist
The full Cyber Insurance Prep Checklist has 47 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.
Not ready to buy? Try the free Cyber Insurance Readiness Score.