United States
Cyber insurance requirements for small business
The controls carriers commonly ask small businesses about, each with the CIS Controls safeguard and NIST CSF 2.0 outcome behind it, and a 90-day schedule for the gaps. Sector rules (the FTC Safeguards Rule, the HIPAA Security Rule, 23 NYCRR 500, PCI DSS) are added only when ticked.
The controls
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
- Restoring from backup is tested as part of a disaster recovery exercise
- Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
- Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
- Inbound email is scanned for malware and phishing with unneeded attachment types blocked, and the domain publishes DMARC
- Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
- IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements
Start from the template, or mark the controls in the control list. How the schedule works.
Questions
- Does this page say the business can be covered?
- No. It shows the gaps and the rule behind each; cover is the insurer's decision.
- What does it cost?
- One applicant on screen is free in any jurisdiction. Saving clocks and the applicant link are on Solo.