Skip to content
CyberTECTDigital operations control
All resources

Cyber Insurance Checklist for Small Businesses

Before answering a cyber-insurance application, verify the organization’s actual controls and evidence. Do not answer from assumption, marketing language, or an old policy document.

The short answer

Before applying for or renewing cyber insurance, confirm what coverage the organization is seeking, complete the insurer’s current questions accurately, and collect evidence for the controls represented in the application. Common readiness areas include MFA, backups and restore testing, endpoint and email protection, patching, access control, staff training, incident response, vendor access, sensitive data, and prior events. Requirements vary by insurer and policy.

Key takeaways

  • The broker and insurer—not a cybersecurity provider—determine the application, underwriting decision, wording, conditions, exclusions, limits, and premium.
  • Use current evidence. A written policy or purchased product does not prove that the control is enabled, complete, monitored, or tested.
  • Be precise about scope: which users, systems, locations, devices, accounts, and vendors are covered by each answer.
  • Resolve contradictions before submission, and disclose uncertainty rather than converting an assumption into a ‘yes.’
  • Insurance transfers some financial risk; it does not replace cybersecurity, continuity, or incident preparation.

The Insurance Bureau of Canada describes its small-business assessment as similar in nature to questions a business may see during a cyber-insurance application, while stressing that readiness tools do not provide an actual risk assessment and that insurance is not a replacement for cyber resilience.

NIST’s CSF 2.0 Small Business Quick-Start Guide includes assessing whether cybersecurity insurance is appropriate within the Govern function. It also asks small businesses to understand requirements, suppliers, assets, identities, protection, response, and recovery as connected business responsibilities.

CyberTECT’s role is to help the organization establish what is actually in place and assemble defensible evidence. It is not to interpret insurance wording, advise on coverage, or predict whether a claim will be paid.

The 12 areas to review before the insurance conversation

01 Coverage objectives and business context

Discuss with the broker what operations, information, revenue dependencies, services, events, and costs the business wants the policy to address. Record legal entities, locations, revenue, employees, industry, online services, and critical technology accurately.

02 Sensitive information and records

Identify personal, client, employee, financial, payment, health, professional, proprietary, and regulated information. Record approximate volumes and locations carefully; do not invent precision the organization cannot support.

03 Multi-factor authentication

Confirm MFA coverage for email, remote access, cloud administration, privileged accounts, backups, finance, critical applications, and vendor access. Record exceptions, authentication method, conditional policies, and evidence.

04 Administrative access and account lifecycle

Review named administrators, separate privileged accounts, least privilege, joiner/mover/leaver processes, stale accounts, service accounts, shared access, emergency access, and periodic review.

05 Endpoint, email, network, and DNS protection

Inventory managed devices and the actual status of endpoint security, firewalls, email protections, filtering, monitoring, and response ownership. Avoid using product names as substitutes for deployment evidence.

06 Patching and vulnerability management

Document operating-system and application update processes, supported software, external exposure, vulnerability findings, remediation ownership, exceptions, and vendor responsibilities.

07 Backup coverage and restore testing

Identify protected systems, backup separation, retention, monitoring, administrators, and the most recent representative restore tests. State exclusions and untested platforms plainly.

08 Staff security awareness and reporting

Record onboarding and recurring training, phishing or scenario exercises where used, attendance, content, reporting instructions, and management follow-up. A training subscription alone is not evidence of participation.

09 Incident response and external contacts

Maintain an approved response plan with decision roles, internal and external contacts, insurer or breach-coach notification requirements where applicable, legal and privacy escalation, evidence preservation, communications, and recovery priorities.

10 Vendors, cloud services, and remote access

List critical providers, information access, integrations, remote tools, privileged roles, contractual security and notification terms, offboarding, concentration risk, and the provider’s role during an incident.

11 Prior incidents, claims, and known weaknesses

Coordinate with the broker, insurer, and appropriate advisors to answer historical and known-circumstance questions accurately. Do not omit a known issue because it was inconvenient, informal, or handled by a provider.

12 Application evidence and sign-off

Assign an accountable owner, retain the final questions and answers, record evidence and contributors, resolve discrepancies, and obtain the required organizational sign-off before submission.

A practical evidence matrix

Readiness area Examples of evidence
MFA Identity reports, configuration screenshots, covered users and systems, exception register, review date.
Backups Protected-object list, job or policy records, failure monitoring, restore-test record, exclusions.
Endpoint and email Managed-device inventory, active policy status, alert ownership, investigation or service reports.
Patching Update policy, device reports, vulnerability results, exception and remediation records.
Training Content, dates, attendance, reporting process, exercises, and follow-up actions.
Incident response Approved plan, contacts, roles, exercise record, provider and insurer notification instructions.
Vendors Vendor inventory, access, contracts, security terms, remote-access records, offboarding evidence.
Governance Owner, review dates, risk decisions, unresolved gaps, action plan, and approval record.

Questions for the broker or insurer

  • Which entities, systems, locations, events, costs, and service providers are included or excluded?
  • Which application answers become warranties, conditions, or material representations under the proposed policy?
  • What notification steps and approved providers apply when an incident is suspected?
  • How do social engineering, funds transfer, ransomware, privacy events, business interruption, and dependent business interruption apply?
  • What sublimits, waiting periods, deductibles, territorial limits, panel requirements, and consent requirements apply?
  • What changes must be reported during the policy period?

Insurance advice boundary

These are discussion prompts only. Obtain coverage interpretation and recommendations from a licensed insurance professional and legal advice where appropriate.

What CyberTECT can and cannot do

CyberTECT can help inventory controls, verify selected evidence, identify gaps, coordinate restore testing, document responsibilities, and prepare a corrective-action plan.

CyberTECT does not act as an insurance broker, underwriter, adjuster, coverage lawyer, or claims decision-maker. Readiness work cannot guarantee eligibility, price, scope of coverage, or claim payment.

Frequently asked questions

Does every small business need cyber insurance?

Not necessarily. The decision depends on business risks, contracts, financial tolerance, available products, and professional advice. Discuss suitability and coverage with a licensed broker or insurer.

Will MFA and backups guarantee approval?

No. They are important controls, but underwriting considers the complete application and the insurer’s current appetite and requirements.

Can CyberTECT complete the insurance application for the client?

CyberTECT can help collect and verify technical and operational evidence. The organization must own its representations and should complete coverage decisions with its broker, insurer, and legal advisor where needed.

What if a control is only partly implemented?

Describe the scope accurately. Record covered and uncovered users or systems, compensating measures, the correction plan, and the evidence. Do not convert partial coverage into an unqualified ‘yes.’

Should the business retain the application after binding?

Yes. Retain the submitted application, policy, endorsements, broker correspondence, evidence, internal approvals, and incident-notification instructions according to the organization’s legal and records requirements.

Prepare the evidence before the form arrives

The fastest way to make a cyber-insurance application difficult is to discover during submission that nobody can verify the controls the organization believed it had. A readiness review separates facts, exceptions, and corrective actions before they become rushed representations.

CyberTECT can support that preparation through the Digital Operations Checkup, Backup & Recovery Validation, Cybersecurity & Staff Readiness, or the broader AI & Digital Operations Review.

Start with the level of review you need

Take the 90-second Digital Operations Control Check for an immediate directional result. For an evidence-based review of accounts, files, Microsoft 365 backups, vendors, AI use, and continuity, discuss the Digital Operations Checkup or the complete AI & Digital Operations Review. Scope and fees are confirmed before work begins.

General information only. This article does not provide legal, privacy, professional-conduct, or regulatory advice. Organizations should obtain appropriate advice for their sector, jurisdiction, information, and intended AI use.

Related CyberTECT services and checks

Authoritative sources and further guidance

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading