Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Free cyber insurance checklist

Cyber insurance readiness checklist

Insurers now ask detailed questions about your security before they quote or renew. Check off the 21 controls they ask about most, see your readiness score, and get a gap report to close before your renewal.

Check off what you have in place today

These are the controls cyber insurance applications ask about most often. Your readiness score updates as you go.

Readiness score0%

Your gap report

    Get help closing these gaps

    How it works

    Why insurers ask these questions

    Cyber insurance underwriting has shifted from a short questionnaire to a detailed review of your controls. Missing MFA, no endpoint detection and response, or backups that live on the same network can mean higher premiums, lower limits, exclusions, or a declined application.

    Many policies also make coverage depend on the answers you give. If an application says a control is in place and it is not, a claim can be disputed. Answer carefully, and keep evidence.

    Next steps

    How to use this checklist

    Work through the list with whoever manages your IT. Anything you cannot confirm should stay unchecked. Your gap report lists every unchecked control with a short explanation of why underwriters care about it.

    Give yourself at least 60 to 90 days before renewal. Controls like MFA and EDR can often be rolled out in weeks, but backup redesigns and policy work take longer.

    FAQ

    Cyber Insurance Readiness Checklist: common questions

    What controls do cyber insurers require most often?

    The most common requirements are MFA on email, remote access, and admin accounts, endpoint detection and response, offsite or immutable backups, regular patching, security awareness training, and an incident response plan.

    Will completing this checklist lower my premium?

    It cannot guarantee a lower premium, but closing the gaps insurers ask about is the most reliable way to improve your terms and avoid exclusions.

    Does WEBIT sell cyber insurance?

    No. WEBIT is a managed IT and cybersecurity provider. We help clients put these controls in place and answer the technical questions on their applications. Your broker handles the policy.

    How often should we review this list?

    At least once a year, about three months before renewal, and any time you change systems, open a new location, or change IT providers.

    More free tools

    Try another tool

    Security Scorecard

    Ten questions, an instant A to F grade, and a fix for every gap.

    Open the tool →

    IT Budget Planner for 2027

    Hardware, licensing, support, security, and projects in one plan.

    Open the tool →

    Email Spoofing Checker

    See whether your domain can be spoofed and exactly what to fix.

    Open the tool →

    Two new clients per month. Maximum.

    Want an owner to walk through your results?

    Thirty minutes, no pressure. You will leave with a clear next step, whether or not we end up working together.

    Your gap report

    Where should we send your gap report?

    We will email your checklist results and every gap to close before renewal. A WEBIT owner may follow up to answer questions.