United States
Cyber insurance application questions, and the rule behind each
A small business cyber application asks about multi-factor authentication, backups, endpoint protection, email security, training, encryption and incident response. Each page below shows the CIS Controls safeguard and the NIST CSF 2.0 outcome behind the question, and the sector rule when one is ticked.
The controls
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
- Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them
- Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
- Inbound email is scanned for malware and phishing with unneeded attachment types blocked, and the domain publishes DMARC
- Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
- Laptops, phones and removable media that hold sensitive data are encrypted
- There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names
Start from the template, or mark the controls in the control list. How the schedule works.
Questions
- Does this page say the business can be covered?
- No. It shows the gaps and the rule behind each; cover is the insurer's decision.
- What does it cost?
- One applicant on screen is free in any jurisdiction. Saving clocks and the applicant link are on Solo.