Free resource
Cyber insurance claim-readiness checklist
An executive checklist for organizing security controls, supporting evidence, application records, policy documents, incident contacts, and response information before an application, renewal, incident, or claim review.
Direct answer
This checklist helps leadership verify the controls, evidence and documents commonly addressed during cyber-insurance underwriting, renewal and claim review. It does not predict whether a claim will be paid. Coverage depends on the application, policy language, endorsements, exclusions, notice and cooperation requirements, applicable law and the facts of the loss.
The checklist covers MFA scope, written security documents, endpoint-protection coverage, patching and remediation, backup protection and restoration testing, payment verification training, social-engineering and funds-transfer provisions, application answers, insurer reporting instructions, and a tabletop exercise. It is written for owners and executives in the United States and takes one sitting to work through.
For the executive explanation behind this checklist, read the Cyber Insurance Readiness CEO Guide.
Written by Joseph Boyd, MBA, Founder and Principal Advisor at Infosec Check
Last reviewed
Scope: General educational and risk-management information. This checklist is not a legal opinion, coverage determination, certification, or guarantee. · Jurisdiction: United States
General educational and informational content. Not legal, insurance, or coverage advice. Requirements depend on your facts, contracts, policy language, and applicable law.
Authoritative sources
- Cyber Insurance
Issuer: Federal Trade Commission
Supports: General small-business guidance on cyber insurance concepts and terminology.
- Safeguards Rule: What Your Business Needs to Know
Issuer: Federal Trade Commission
Supports: Scope of the FTC Safeguards Rule and the safeguards a covered business documents.
- Publication 4557, Safeguarding Taxpayer Data
Issuer: Internal Revenue Service
Supports: Taxpayer-data security guidance for tax and accounting firms.
- HIPAA Security Rule
Issuer: U.S. Department of Health and Human Services
Supports: Security Rule requirements relevant to covered entities and business associates.
- PCI DSS
Issuer: PCI Security Standards Council
Supports: Payment card data security requirements referenced in the checklist.
These sources support security and regulatory-readiness concepts. None determines whether a particular insurance claim will be paid, denied, reduced, or rescinded.
The ten checks in the checklist
1. Verify the MFA scope represented or required
Confirm which accounts and systems are covered, including email, remote access and administrator accounts, and document any exceptions rather than relying on the statement that the business uses MFA.
2. Verify written security documents and how they operate
Retain approved information security, incident response and vendor management documents, along with evidence of the version in force and how each was communicated and reviewed.
3. Verify endpoint-protection coverage across devices
Compare reports against the device inventory and record exceptions, inactive agents, contractor devices and unmanaged systems.
4. Verify the patching and remediation process
Maintain a defined process and records for operating systems, firewalls and internet-facing applications, including unsupported technology and planned remediation.
5. Verify backup protection, retention and restoration testing
Document backup frequency, whether copies are protected or isolated, retention periods and the results of restoration tests rather than assuming a posture.
6. Verify payment and wire verification training
Confirm the verification procedure staff are expected to follow and retain training records.
7. Verify social-engineering and funds-transfer provisions
Review the actual policy, endorsements, sublimits and definitions that apply to wire fraud and funds-transfer loss rather than a summary or proposal.
8. Verify material application answers before signature
Review the application with leadership at application and renewal and confirm the available evidence supports each material answer.
9. Verify the insurer's incident reporting contact and instructions
Save the current reporting contact and instructions where the CEO, CFO and IT lead can reach them, and confirm the notice, consent and cooperation provisions in the policy.
10. Verify readiness through a tabletop exercise
Exercise the notice, consent, preservation and decision steps the policy requires so leadership knows the sequence before an event.
Who it is for
- Owners and CEOs carrying a cyber policy they have never tested
- Finance and operations leaders responsible for the renewal
- Medical, dental, and mental health practices under HIPAA
- Financial services and insurance firms under the FTC Safeguards Rule
- Accounting and tax preparation firms under IRS taxpayer data security rules
- Legal services firms under client confidentiality rules
- Retail and e-commerce businesses under PCI DSS
How to use it
- 1.Print it and take it into your next leadership meeting. Each item needs an executive who can say it is supported by evidence, not assumed.
- 2.Mark anything you cannot evidence today. Gaps you can name are gaps you can address before renewal.
- 3.Compare the marked items against the answers on your last insurance application. Any mismatch is worth reviewing first.
- 4.Bring the marked copy to your broker, your coverage counsel or a readiness review so the conversation starts from facts.
What happens after you download it
You get a private download link by email and on screen, valid for seven days. Nothing else is automatic: no newsletter, no drip sequence. A senior operator may follow up once to offer a readiness review, and you can opt out of that in the notes field. If the email does not arrive, call or text (855) 624-6262 and we will send it directly.
Related reading
Pair the checklist with Why Cyber Insurance Claims May Be Denied or Disputed, our insurance consulting engagement, and the regulatory applicability assessment if you are not sure which rules apply to you.
Questions about the checklist
Is the cyber insurance claim-readiness checklist free?
Yes. The checklist is free. We ask for your name, work email, and a short note so we know where to send the private download link and what to follow up on. There is no cost and no purchase required.
What is inside the checklist?
Ten items to verify before an application, renewal, incident or claim review: MFA scope, written security documents and how they operate, endpoint-protection coverage, the patching and remediation process, backup protection and restoration testing, payment and wire verification training, social-engineering and funds-transfer provisions, material application answers, the insurer's incident reporting contact and instructions, and a tabletop exercise. It also notes regulatory considerations by industry, including HIPAA, the FTC Safeguards Rule, IRS taxpayer data security, and PCI DSS.
Do I need to already have a cyber insurance policy to use it?
No. If you have a policy, use the checklist to verify the answers you already gave on your application against available evidence. If you are buying coverage for the first time, use it to organize controls and evidence before completing an application.
How long does the checklist take to work through?
About 30 to 45 minutes for a leadership team to read and mark honestly. Closing the gaps you find takes longer, but the checklist itself is a single sitting.
Will someone call me after I download it?
A senior operator may follow up once to ask if you want a readiness review. There is no newsletter, no drip sequence, and no sales automation. You can tell us not to follow up in the notes field and we will not.
Is my information shared or sold?
No. Your details are stored privately and used only to send the checklist and respond to your inquiry. We do not sell, rent, or share lead data with third parties.
How is the download delivered, and does the link expire?
After you submit the form we email a private download link and also show it on screen. The link is generated for your request only, is not published anywhere on the site, and expires after seven days. Request it again any time.
How often is the checklist updated?
We revise it as carrier application questions and regulatory expectations change, currently version 1.1. Requesting it again gives you the newest revision.
Is this legal or insurance advice?
No. The checklist is informational only and is not legal, insurance, or compliance advice. Consult your carrier and counsel for guidance specific to your organization.
For informational purposes only, not legal, insurance, or compliance advice. Consult your carrier and counsel for guidance specific to your organization.
