Cyber insurance readiness
Answer every question on your insurer’s form with a straight yes.
We map each question to a control and to the evidence, put the missing ones in place, and help you answer truthfully.

The questions insurers ask
The same handful of questions, in plain words.
Wording changes by insurer and at renewal, but these are the questions that come up again and again. Each one maps to a control and to a record you can hand over.
| What the form asks | The control | The evidence we keep |
|---|---|---|
| Is multi-factor authentication on for email and remote access? | Enforced on every account; conditional access on Secured | Enforcement report and dated exceptions |
| Is there endpoint detection and response on every device? | On every managed device | Coverage list, device by device |
| Are backups kept separate from the network, and tested? | Isolated copy, restore-tested monthly | Job results and dated restore tests |
| How quickly are critical patches applied? | Within 72 hours of release | Monthly patch compliance report |
| Who has administrator access? | Named accounts only, local admin removed | Admin list and last access review |
| Is email filtered, and is your domain protected from spoofing? | Filtering plus SPF, DKIM and DMARC | Filter policy and the DNS records |
| Do you run any unsupported systems? | Tracked in the asset register with a plan and a date | Asset register extract |
| How fast is access removed when someone leaves? | Within four business hours on Secured | Offboarding tickets with timestamps |
| Is there an incident response plan? | Written, and reviewed every year | The plan, with its review date |
Read your own form: requirements differ by insurer. We help you answer it accurately.
The honest answer
Sometimes you’re already in good shape.
If the review shows the controls are in place and documented, we say that and stop. If there are gaps, you get a short list in priority order, with what each one costs to close, before you decide anything.
- 01
Send the form
The questionnaire, or last year’s answers, is enough to start.
- 02
We map it
Every question to a control, and every control to the record that proves it.
- 03
You see the gaps
In priority order, with the cost to close each one, before anything is decided.
- 04
You answer truthfully
With evidence behind every yes, ready if the insurer asks.
We’re not your insurance broker or your attorney. We don’t guarantee coverage, premiums or that a claim will be paid. We make the technical answers accurate and the evidence ready. Read the guide: what your cyber insurer will ask.
Questions
Straight answers about insurance readiness.
Do you work with our broker?
What if we’re already in good shape?
Can you guarantee the policy or a claim?
What does the review cost?
Get started
Send us the questionnaire.
1‑855‑OPSWORQ855‑677‑9677 · Mon–Fri, 8am–5pm ET
If the business has stopped, call. Don’t use the form.
We read it, answer what we can from evidence and tell you plainly what’s missing.