47 controls · 17 categories

Cyber Insurance Application Checklist

Underwriters quietly raise premiums, or deny coverage outright, over controls most businesses never see coming. This checklist lays out the 47 controls carriers actually verify, sorted by what they require every time, what triggers a premium increase, and what can disqualify you entirely.

See exactly what you're buying before you pay, no email, no account. One-time purchase · instant download · 47 controls with verification & remediation steps.

What's inside

47 controls across 17 categories

Every control is plain-language, prioritized by severity, and paired with how to verify it and how to fix it. Organized into 4 sections.

Backups5
MFA4
Patching4
Email Security4
Network4
Incident Response3
Access Control3
Endpoint2
Vulnerability Management2
Vendor Access2
Awareness2
Data2
Application2
Logging2
Asset Management2
Policy2
Business Continuity2

Real sample controls

A look at the highest-severity controls

These are taken directly from the checklist, no paraphrasing.

  • CI-01CRITICALMFA

    Require multi-factor authentication on every email account.

  • CI-02CRITICALMFA

    Require MFA for all remote access, VPN, RDP, and SSH.

  • CI-03CRITICALMFA

    Require MFA for every privileged and administrator account.

  • CI-04CRITICALMFA

    Require MFA for all cloud service consoles (AWS, Azure, M365 admin).

Cyber Insurance Prep Checklist

$47one-time
  • 47 prioritized controls
  • Verify & fix steps for each control
  • 17 categories across 4 sections
  • Instant download · lifetime access

Upgrade to the Complete Bundle, save $285

Get all 6 checklists for $497 ($782 bought separately).

Add the bundle instead ›
Get the checklist ›

By purchasing you agree to our Terms. Digital products are non-refundable once accessed.

See it first, free

Preview the checklist before you pay

Open the first 10 controls in your browser, real, unredacted, exactly as they appear in the checklist. No login, no email, no card. See precisely what you're buying before you spend a cent.

Why teams buy with confidence

  • Instant access

    Pay and the download link lands in your inbox immediately, no waiting, no sales call.

  • Lifetime updates

    Frameworks change. When the controls do, you get the updated version at no extra cost.

  • Built by practitioners

    Controls drawn from CIS benchmarks, framework requirements, and real assessment findings.

  • Secure checkout

    Payment is processed by Stripe. We never see or store your card details.

Jason Dobbs, founder of Strondex

Built by practitioners, not a content mill

Built by Jason Dobbs, a technology leader and cybersecurity strategist with more than two decades of experience hardening Microsoft 365, Azure, and AWS for small and mid-sized businesses across regulated industries, healthcare, finance, law, real estate, energy, and the public sector. These controls are drawn from real assessments and the security questions cyber insurers actually ask.

Secured by StripeMapped to Cyber-insurer requirementsNIST CSFNo subscription · no upsell

We'll always make it right.

If a checklist isn't what you needed, email us, we'll get you to the right one or find a resolution that works.

Exactly 47 controls, no inflated counts. One-time purchase · digital product · non-refundable once accessed.

“Before we worked with Strondex, SOC 2 felt like a moving target. Jason simplified the entire process. His team performed a thorough assessment, developed clear action plans, helped us implement the controls, and made sure we had the evidence the audit required. They were responsive at every step. We completed our SOC 2 audit successfully and came away with a much stronger understanding of security governance.”
Rebecca · Divisional Head of Operations, SOC 2 Compliance
“We engaged Strondex to prepare for a PCI DSS assessment and expected guidance. What we received was a true partnership. Jason and his team helped us close longstanding compliance gaps, improve our documentation, validate technical controls, and prepare our staff for the auditor’s questions. By the time the audit arrived, everything was organized and ready. We passed with ease and earned positive feedback from the assessor on the maturity of our security program.”
Michael · CEO, PCI DSS Compliance

Frequently asked questions

What does a cyber insurance application checklist cover?

It maps the security controls underwriters review during application and renewal, multi-factor authentication, backups, patching, email security, incident response, and more, so you can self-assess before a carrier does.

Will this guarantee I get cyber insurance coverage?

No tool can guarantee an underwriting decision. This checklist shows you which controls carriers verify and which gaps commonly trigger premium increases or denials, so you can fix or disclose them ahead of time.

How is this different from a generic security checklist?

The 47 controls are organized around the underwriting process specifically: what carriers require every time, what raises premiums if missing, and what can disqualify coverage outright.