Skip to content
FioSec Consulting

Free readiness check

Would you pass a cyber-insurance review?

Insurers now treat security controls as conditions of coverage. Answer sixteen questions, one per control carriers actually ask about on their applications, for an instant read on where you’d likely qualify and where the gaps are. Nothing is sent anywhere: your answers are scored right here in your browser.

Cyber insurance readiness questions

Heads up: this is a general educational self-check, not insurance advice, an application, or any guarantee of coverage or eligibility. Every insurer’s requirements differ. Use it to spot likely gaps, then talk to your broker.

01 · Multi-factor authentication

Is multi-factor authentication (MFA) enforced everywhere underwriters check: email, remote access, and key cloud apps (Microsoft 365, Google Workspace, finance/HR)?

02 · Privileged access management

Are privileged and admin accounts separated from everyday logins, with access kept to least privilege?

03 · Endpoint detection & response

Is endpoint detection & response (EDR, or a managed detection and response (MDR) service) deployed across all endpoints and servers, not just traditional antivirus?

04 · Patch management

Are operating systems and applications patched on a regular, defined cadence?

05 · End-of-life software

Is your environment free of unsupported or end-of-life software that no longer receives security updates?

06 · Email filtering & anti-phishing

Is inbound email filtered for phishing, malware, and impersonation (business email compromise) before it reaches inboxes?

07 · Security awareness training

Do staff get security-awareness training at least annually, ideally ongoing?

08 · Phishing simulations

Are staff tested with simulated phishing campaigns?

09 · Remote access

Is remote access locked down, with no RDP or similar services exposed directly to the internet?

10 · Network segmentation

Is your network segmented, so one compromised device can’t reach everything?

11 · Backups: protected

Are backups kept immutable or air-gapped, so ransomware can’t alter or delete them?

12 · Backups: tested

Have you test-restored from backups recently, proving recovery actually works?

13 · Log collection

Are security logs from your key systems collected in one place (e.g. a SIEM)?

14 · Monitoring & alerting

Is someone, in-house or a managed service, monitoring those logs and alerts for signs of intrusion?

15 · Incident response plan

Do you have a written incident response plan that names who does what?

16 · IR plan testing

Has that plan been tested with a tabletop exercise in the past year?

Sixteen questions. Answer “Partly” when a control covers only some systems or people; “Not sure” is a valid answer too. No email required; scored in your browser, never sent anywhere.