IT Security

Cyber Insurance Requirements

Every Business Requires Cybersecurity Insurance but before you get Insurance here is the TECHNICAL ASSESSMENT: that every Insurance company needed as without that you can't get the Cyber insurance

CYBER INSURANCE APPLICATION

TECHNICAL ASSESSMENT:

1. Are all computers in your organization running Windows 10 or later?

Yes No

If NO, is all end-of-life segregated and offline?

Yes No

2. Do you protect all your devices with anti-virus, anti-malware, and/or endpoint protection software?

Yes No

3. Do you install all security patches (e.g., those issued by Microsoft) within 60 days of release?

Yes No

4. Do you use cloud-based email services (e.g., Office365, Gmail, Microsoft Outlook on the web)?

Yes No

If YES, have you enabled multifactor authentication (MFA) on all accounts?

Yes No

5. Do you allow remote access to your network (e.g., enabling employees to work from home)?

Yes No

If YES, do you require multi-factor authentication (MFA) for all remote connections?

Yes No

6. Have you taken measures to ensure that you comply with all privacy and data protection laws and regulations that apply to your organization (e.g., PCI, HIPAA, PIPEDA)?

Yes No

Please add any additional commentary/clarifications to answers provided here:

Further

7. Are firewalls installed at all gateways and configured to block inbound connections by default?

Yes No

8. Are access controls employed using the principle of least privilege?

Yes No

9. Do you maintain physically disconnected ‘offline’ back-ups (e.g., tape drives) for all critical data?

Yes No

11. Have you disabled all Remote Desktop Protocol (RDP) ports?

Yes No

12. Do you encrypt all personal and confidential data in-transit?

Yes No

13. Have you taken measures to ensure that your organization’s website and print content do not infringe on any trademarks or copyrights?

Yes No

14. Do you scan all incoming emails for malicious attachments and/or links?

Yes No

Please add any additional commentary/clarifications to answers provided here:

Advance

15. Do you utilize next generation anti-virus or behavioral analysis software, including Endpoint Detection and Response (EDR) tools?

Yes No

If YES, please state which product is used (e.g., CrowdStrike Falcon, SentinelOne)?

16. Are employees trained in phishing and social engineering techniques?

Yes No

17. Do you utilize email filtering tools and/or software?

Yes No

If YES: please state which software and/or tools are used (e.g., Proofpoint with e.g. SPF. DKIM and DMARC enabled):

18. Have you disabled all local administrator accounts on workstations and servers?

Yes No

If NO, do all local administrator accounts utilize a unique password?

Yes No

19. Do you run any version of Windows Server?

Yes No

If YES, do you take frequent back-ups of Active Directory servers?

Yes No

If YES, do all login attempts to Domain Administrator accounts require multifactor authentication (MFA)?

Yes No

Please add any additional commentary/clarifications to answers provided here: