Cyber Insurance Subjectivity Tracker

Guides / United States

United States

Cyber insurance requirements for small business

The controls carriers commonly ask small businesses about, each with the CIS Controls safeguard and NIST CSF 2.0 outcome behind it, and a 90-day schedule for the gaps. Sector rules (the FTC Safeguards Rule, the HIPAA Security Rule, 23 NYCRR 500, PCI DSS) are added only when ticked.

The controls

Start from the template, or mark the controls in the control list. How the schedule works.

Questions

Does this page say the business can be covered?
No. It shows the gaps and the rule behind each; cover is the insurer's decision.
What does it cost?
One applicant on screen is free in any jurisdiction. Saving clocks and the applicant link are on Solo.