How Insurable Is Your Organization?
Sixteen controls drawn directly from real cyber insurance applications, organized across the four domains insurers actually underwrite on. Free to use — no signup, no email required.
This is also a simulator: check every control already in place and see your insurability score out of 100 — the same questions cyber insurers ask on every application.
Identity & Access
Who can get in, and how tightly that's controlled — the single most attacked layer in every breach.
- 1
MFA enforced on every email account
Multi-factor authentication is required for remote access to all company email accounts — the most targeted entry point for attackers.
- 2
MFA enforced for remote network access
VPN and any other remote access to your network requires multi-factor authentication, not just a password.
- 3
MFA enforced on cloud resources with sensitive data
Every cloud application or storage location holding sensitive or confidential information requires multi-factor authentication to access.
- 4
Local admin rights restricted
Everyday users don't have local administrator rights on their laptops or desktops, and privileged accounts are kept separate from day-to-day use.
Threat & Incident Readiness
What happens the moment something goes wrong — detection, response, and the controls that stop fraud.
- 1
Network monitoring or SOC in place
A monitoring solution or Security Operations Centre alerts your organization to suspicious or malicious activity on the network.
- 2
Incident response plan tested periodically
A formal cyber incident response plan exists and is tested on a regular schedule, not just written and filed away.
- 3
Annual phishing simulation training
Employees are tested with simulated phishing attacks at least once a year to keep awareness sharp.
- 4
Out-of-band verification for fund transfers
Before changing a vendor's bank details or wiring funds, your team verifies the request through a separate channel — the single control insurers check first for crime coverage.
Vulnerability Management
How fast you find weaknesses — and how fast you close them — before attackers do.
- 1
Recurring vulnerability scanning
Your network perimeter is scanned for vulnerabilities on a recurring schedule, not just once a year.
- 2
Regular penetration testing
Independent penetration testing of your network and applications happens at least annually.
- 3
EDR deployed on every endpoint
Endpoint detection and response is deployed and monitored across all endpoints — not just servers or a subset of devices.
- 4
No unmanaged end-of-life software
Systems past end-of-life or end-of-support are identified and either retired or fully segregated from the network.
Foundational Controls
The baseline every cyber insurer expects before they'll even quote you.
- 1
Next-generation firewalls at every ingress point
Next-gen firewalls are deployed at all network ingress and egress points, not just the perimeter edge.
- 2
Email filtering with DMARC enforced
Inbound and outbound email is filtered for spam and malicious content, with DMARC enforced against spoofing.
- 3
Sensitive data encrypted at rest and in transit
Sensitive and confidential data is encrypted both while stored and while moving across your network.
- 4
Backups tested and kept offline from the live environment
Backups are stored disconnected from the live environment and you regularly test full restoration — not just that the backup job completed.
Need help closing the gaps?
Our consultants implement every one of these controls and prepare your application so you qualify for stronger terms.
