Skip to main content

Free resource

Cyber insurance claim-readiness checklist

The evidence, controls, and documentation an underwriter or adjuster asks for, in the order they ask for it, so a claim is not denied on a technicality.

In short: most denied cyber insurance claims trace back to a control that was promised on the application but was not actually in place on the date of loss. This free checklist lists the ten checks, MFA coverage, written policies, endpoint protection, patching, tested offline backups, wire transfer training, social engineering coverage, application review, the carrier hotline, and an annual tabletop, that underwriters and adjusters verify. It is built for owners and executives in the United States, not for security teams, and it takes one sitting to work through.

The ten checks in the checklist

  1. 1. Enforce MFA everywhere

    Email, VPN, remote desktop, and every administrator account, with no legacy exceptions. Missing MFA on a single admin account is the most common single reason a claim is contested.

  2. 2. Maintain written security policies

    Information security, incident response, and vendor management, approved, distributed, and actually followed. Adjusters ask for the version that was in force on the date of loss.

  3. 3. Deploy endpoint protection on every device

    Servers, laptops, and contractor devices. An unmonitored device is where carriers look first when they are testing your application answers.

  4. 4. Patch on a defined schedule

    Operating systems, firewalls, and internet-facing applications. Unpatched, end-of-life systems are a common policy exclusion, not just a finding.

  5. 5. Keep a tested, offline backup

    At least one immutable or offline copy, with restoration tested quarterly rather than only at setup. Untested backups turn a recoverable event into a business interruption claim.

  6. 6. Train staff on wire transfer verification

    Business email compromise is one of the most common and most preventable losses, and training records are frequently requested as proof.

  7. 7. Confirm social engineering coverage is on the policy

    Wire fraud and funds transfer fraud are often sublimited or excluded unless specifically endorsed. Read the endorsement, not the summary.

  8. 8. Review the application with a security advisor before signing

    The application is a legal document, not a sales form. Inaccurate answers can void the policy entirely, even when the answer was an honest assumption.

  9. 9. Save the carrier's incident hotline now

    In the phones of the CEO, CFO, and IT lead, before you need it. Late notice is its own denial ground under most policies.

  10. 10. Run a tabletop exercise annually

    So leadership knows the first 72 hours cold, before a real incident forces the pace and the notice clock starts running.

Who it is for

  • Owners and CEOs carrying a cyber policy they have never tested
  • Finance and operations leaders responsible for the renewal
  • Medical, dental, and mental health practices under HIPAA
  • Financial services and insurance firms under the FTC Safeguards Rule
  • Accounting and tax preparation firms under IRS taxpayer data security rules
  • Legal services firms under client confidentiality rules
  • Government contractors under CMMC and NIST 800-171
  • Retail and e-commerce businesses under PCI DSS

How to use it

  1. 1.Print it and take it into your next leadership meeting. Each item needs an executive who can say it is genuinely true, not assumed.
  2. 2.Mark anything you cannot evidence today. Gaps you can name are gaps you can fix before renewal.
  3. 3.Compare the marked items against the answers on your last insurance application. Any mismatch is the exposure worth closing first.
  4. 4.Bring the marked copy to your broker or to a readiness review so the conversation starts from facts.

What happens after you download it

You get a private download link by email and on screen, valid for seven days. Nothing else is automatic: no newsletter, no drip sequence. A senior operator may follow up once to offer a readiness review, and you can opt out of that in the notes field. If the email does not arrive, call or text (855) 624-6262 and we will send it directly.

Related reading

Pair the checklist with 10 Reasons Cyber Insurance Claims Are Denied, our insurance consulting engagement, and the regulatory applicability assessment if you are not sure which rules apply to you.

Get the checklist

Tell us where to send it. We email a private download link, no newsletter, no sales sequence.

We use your details only to respond to this inquiry. See our privacy policy.

Questions about the checklist

Is the cyber insurance claim-readiness checklist free?

Yes. The checklist is free. We ask for your name, work email, and a short note so we know where to send the private download link and what to follow up on. There is no cost and no purchase required.

What is inside the checklist?

Ten checks that decide whether a cyber insurance claim is paid: MFA coverage, written security policies, endpoint protection, patching cadence, tested offline backups, wire transfer verification training, social engineering coverage, application review before signing, the carrier incident hotline, and an annual tabletop exercise. It also maps which regulations apply by industry, including HIPAA, the FTC Safeguards Rule, IRS taxpayer data security, CMMC and NIST 800-171, and PCI DSS.

Do I need to already have a cyber insurance policy to use it?

No. If you have a policy, use the checklist to test the answers you already gave on your application. If you are buying coverage for the first time, use it to get your controls and evidence in order before you fill out an application you will be held to.

How long does the checklist take to work through?

About 30 to 45 minutes for a leadership team to read and mark honestly. Closing the gaps you find takes longer, but the checklist itself is a single sitting.

Will someone call me after I download it?

A senior operator may follow up once to ask if you want a readiness review. There is no newsletter, no drip sequence, and no sales automation. You can tell us not to follow up in the notes field and we will not.

Is my information shared or sold?

No. Your details are stored privately and used only to send the checklist and respond to your inquiry. We do not sell, rent, or share lead data with third parties.

How is the download delivered, and does the link expire?

After you submit the form we email a private download link and also show it on screen. The link is generated for your request only, is not published anywhere on the site, and expires after seven days. Request it again any time.

How often is the checklist updated?

We revise it as carrier application questions and regulatory expectations change, currently version 1.1. Requesting it again gives you the newest revision.

Is this legal or insurance advice?

No. The checklist is informational only and is not legal, insurance, or compliance advice. Consult your carrier and counsel for guidance specific to your organization.

For informational purposes only, not legal, insurance, or compliance advice. Consult your carrier and counsel for guidance specific to your organization.