Free · 22 questions · nothing leaves your browser

Would your business pass a cyber insurance application today?

Cyber insurers now ask detailed questions about your security before they write or renew a policy. Answer 22 of the questions they actually ask, drawn from published Travelers, Beazley, Coalition and Chubb material, and get a readiness score, your gaps, and the order to fix them in. Built for Canadian businesses by IT Rapid Support in Vaughan.

Your answers stay on your device. There is no sign up, the tool never asks for your name, company or email, and nothing is sent to us or anyone else. Close the tab and the answers are gone.
Answer for your whole business0 of 22 answered

Multi-factor authentication

1 of 22 · critical controlweight 6
Is multi-factor authentication enforced on every email account, including webmail opened from personal devices?
2 of 22 · critical controlweight 6
Does every form of remote access (VPN, remote desktop, remote support tools) require multi-factor authentication?
3 of 22 · critical controlweight 6
Do all administrator accounts use multi-factor authentication, for internal as well as remote access?

Endpoint detection and response

4 of 22 · critical controlweight 6
Is endpoint detection and response (EDR), not only traditional antivirus, installed on every laptop, desktop and server?
5 of 22weight 3
Are security alerts watched around the clock by people who can isolate a machine or disable an account?
6 of 22weight 3
Do everyday users work without local administrator rights on their own computers?

Backups and recovery

7 of 22 · critical controlweight 6
Is at least one copy of your backups offline or immutable, so it cannot be deleted or encrypted from your network?
8 of 22weight 4
Have you restored key servers and data from backup as a test within the last six months, and kept a record?
9 of 22weight 2
Are backups encrypted, and made with a real backup product rather than relying on OneDrive, Dropbox or SharePoint sync?

Patching and vulnerabilities

10 of 22weight 4
Are critical security patches installed on a defined timeline, within 30 days of release at the latest?
11 of 22weight 3
Is every system still supported by its vendor, with anything end of life removed or cut off from the rest of the network?
12 of 22weight 2
Do you run scheduled vulnerability scans across your environment, or a penetration test each year?

Email security

13 of 22weight 3
Is incoming email filtered for malicious links and attachments, with suspicious messages quarantined?
14 of 22weight 3
Does your domain publish SPF, DKIM and a DMARC policy set to quarantine or reject?
15 of 22weight 2
Are Office macros from the internet blocked by default?

Privileged access

16 of 22weight 4
Are admin accounts separate from everyday accounts, kept to a small named list, and reviewed at least once a year?
17 of 22weight 1
Do staff use a company password manager instead of reusing passwords or keeping them in spreadsheets?

Security awareness training

18 of 22weight 3
Does every employee complete security awareness training at least once a year, with phishing simulations?

Incident response

19 of 22weight 4
Do you have a written incident response plan that names who to call first, including your insurer or broker, and has your team walked through it?

Network and logging

20 of 22weight 3
Is your network segmented, with firewalls that block inbound connections by default and guest Wi-Fi kept separate?
21 of 22weight 2
Are security logs from Microsoft 365, firewalls and servers stored centrally, kept for months rather than days, and reviewed?

Vendor risk

22 of 22weight 2
For vendors who can reach your systems or data, do you set written security requirements and review their access regularly?

How the score is built

Each question carries a weight from 1 to 6, printed next to it. A control fully in place keeps its full weight, a partial answer keeps half, and a missing or unsure answer keeps nothing. The points you keep, out of a possible 78, become a score from 0 to 100.

5 controls are marked critical: MFA on email, MFA on remote access, MFA on admin accounts, EDR on every device, and an offline or immutable backup. These are the answers most often described as able to stop an application on their own, so a "no" on any of them puts you at risk of decline and a "partly" caps you at conditional, whatever the total. Otherwise 80 and above reads as likely insurable, 55 to 79 as conditional, and below 55 as at risk of decline.

The questions come from documents insurers publish: the Travelers CyberRisk application and its Multi-Factor Authentication Supplement, the Beazley Ransomware Supplemental Application, Coalition’s list of essential cyber insurance requirements, and the focus areas Chubb lists for its cyber services. Each gap in your results names the document that asks about it. Our cyber insurance readiness checklist explains how to prepare for the application itself.

What this is not

It is not an underwriting decision and not any insurer’s real criteria. Every carrier’s form is different, forms change at renewal, and underwriters also weigh your industry, revenue, data and claims history.

It is also not legal or insurance advice. Answer your real application accurately with your broker. An honest application with a higher premium is worth more than a cheaper policy that fails at claim time.

Closing the gaps

Cyber insurance readiness checklist

What insurers ask for, the gaps that trip up small businesses, and how to prepare before renewal.

Read the checklist

Managed detection and response

EDR on every device, watched around the clock by people who can contain a threat at 2am.

See the MDR service

Backup and disaster recovery

Offline and immutable copies, tested restores, and recovery targets you can write on an application.

Read the backup guide

Cyber insurance readiness FAQs

What does the cyber insurance readiness score measure?

It checks your business against 22 security controls that appear on published cyber insurance applications and carrier guidance: multi-factor authentication on email, remote access and admin accounts, endpoint detection and response, offline or immutable backups with tested restores, patching timelines, email filtering and SPF, DKIM and DMARC, privileged access, security awareness training, an incident response plan, network segmentation, logging and vendor access. You get a score out of 100, a readiness band, and a list of what to fix first.

Does any of my information leave the browser?

No. The questionnaire runs entirely in your browser. It does not ask for your name, company or email, nothing is sent to IT Rapid Support or anyone else, and your answers are gone when you close or reload the page.

Which insurers ask these questions?

The questions are drawn from documents carriers publish themselves: the Travelers CyberRisk application and its Multi-Factor Authentication Supplement, the Beazley Ransomware Supplemental Application, Coalition’s published list of essential cyber insurance requirements, and the focus areas Chubb lists for its cyber services. Every insurer’s form is different and forms change at renewal, so treat this as preparation, not as any carrier’s actual criteria.

Why does one missing control put me in the at risk band?

Five controls are marked as critical: MFA on email, MFA on remote access, MFA on admin accounts, EDR on every device, and an offline or immutable backup. Carriers and brokers consistently describe these as the ones that can stop an application on their own, so a "no" on any of them puts you in the at risk band whatever the rest of the score says. A "partly" on any of them caps the result at conditional.

Is a high score a guarantee of coverage?

No. Underwriting also looks at your industry, revenue, the data you hold, claims history and the limits you ask for, and only the insurer can decide. The score tells you whether your security controls are likely to be a problem, and what to fix before an application or renewal.

What should I do if I am unsure about an answer?

Mark it "No, or not sure" and treat it as a gap. On a real application, an answer you cannot back up with evidence is the one most likely to cause trouble at claim time. Ask your IT provider for proof, such as an MFA enrolment report, an EDR coverage count or the date of the last test restore, before you answer.

Want the gaps closed before your renewal?

We roll out MFA, EDR with 24/7 monitoring, immutable backups and patching, then hand you the evidence your broker will ask for. Start with the free email spoofing check if you want to test one control right now.

We use cookies for analytics and ads. Cookie Policy · Privacy