OPSWORQ

Cyber insurance readiness

Answer every question on your insurer’s form with a straight yes.

We map each question to a control and to the evidence, put the missing ones in place, and help you answer truthfully.

A clipboard with a blank checklist and an orange pen, beside a closed laptop.

The questions insurers ask

The same handful of questions, in plain words.

Wording changes by insurer and at renewal, but these are the questions that come up again and again. Each one maps to a control and to a record you can hand over.

Question, control and evidence
What the form asksThe controlThe evidence we keep
Is multi-factor authentication on for email and remote access?Enforced on every account; conditional access on SecuredEnforcement report and dated exceptions
Is there endpoint detection and response on every device?On every managed deviceCoverage list, device by device
Are backups kept separate from the network, and tested?Isolated copy, restore-tested monthlyJob results and dated restore tests
How quickly are critical patches applied?Within 72 hours of releaseMonthly patch compliance report
Who has administrator access?Named accounts only, local admin removedAdmin list and last access review
Is email filtered, and is your domain protected from spoofing?Filtering plus SPF, DKIM and DMARCFilter policy and the DNS records
Do you run any unsupported systems?Tracked in the asset register with a plan and a dateAsset register extract
How fast is access removed when someone leaves?Within four business hours on SecuredOffboarding tickets with timestamps
Is there an incident response plan?Written, and reviewed every yearThe plan, with its review date

Read your own form: requirements differ by insurer. We help you answer it accurately.

The honest answer

Sometimes you’re already in good shape.

If the review shows the controls are in place and documented, we say that and stop. If there are gaps, you get a short list in priority order, with what each one costs to close, before you decide anything.

  1. 01

    Send the form

    The questionnaire, or last year’s answers, is enough to start.

  2. 02

    We map it

    Every question to a control, and every control to the record that proves it.

  3. 03

    You see the gaps

    In priority order, with the cost to close each one, before anything is decided.

  4. 04

    You answer truthfully

    With evidence behind every yes, ready if the insurer asks.

We’re not your insurance broker or your attorney. We don’t guarantee coverage, premiums or that a claim will be paid. We make the technical answers accurate and the evidence ready. Read the guide: what your cyber insurer will ask.

Questions

Straight answers about insurance readiness.

Do you work with our broker?
Yes. We answer the technical questions from evidence; your broker handles the policy.
What if we’re already in good shape?
Then we say so and stop. A clean result is a good outcome, and we’d rather earn your trust with it than invent a project.
Can you guarantee the policy or a claim?
No. We make the technical answers accurate and the evidence ready. Coverage, premiums and claims are between you and your insurer.
What does the review cost?
It’s quoted in writing after we’ve seen the questionnaire. For managed clients the evidence already exists, so it’s usually a short job.

Get started

Send us the questionnaire.

1‑855‑OPSWORQ

855‑677‑9677 · Mon–Fri, 8am–5pm ET

If the business has stopped, call. Don’t use the form.

We read it, answer what we can from evidence and tell you plainly what’s missing.

What’s it about? Select all that apply.

A sentence is plenty.

A person replies within one business day. Nothing is sold, and you’re not added to a mailing list.

Prefer to talk? Pick a time for a 20‑minute review Or call 1‑855‑OPSWORQ.

Call Get your price