Knowledge Centre
Cyber Security GuidesChecklist and Guide

Cyber Insurance Readiness Guide

7 minutes to completeEvergreen guide — kept up to date

Cyber insurance can provide specialist and financial support following a serious cyber incident. However, policy suitability and claim outcomes can depend on the cover purchased, exclusions and limits, accurate application answers, the continued operation of declared security controls and prompt use of the insurer’s incident process. Use this guide to prepare for a broker or insurer discussion and to verify the technical controls your organisation declares.

This guide provides general technology and cyber-security information. It is not insurance, legal or financial advice — insurance advice should be obtained from an appropriately authorised insurer or broker.

Step 1: Check existing policies

  • Review current business insurance policies.
  • Check whether cyber cover is already included.
  • Check whether cyber losses are specifically excluded elsewhere.
  • Identify policy limits and sub-limits.
  • Record renewal dates.
  • Record broker and insurer contact details.
  • Obtain the complete policy wording.
  • Obtain all endorsements and schedules.

Step 2: Identify business risks

  • Business interruption
  • Ransomware
  • Data breach
  • Payment fraud and business email compromise
  • Cloud-service failure
  • Managed-provider incident
  • Website or ecommerce outage
  • Loss of customer data
  • Regulatory investigation
  • Third-party claim
  • System restoration
  • Crisis communications

For each risk, record the potential operational effect, the likely financial effect, the existing control, the alternative business process, whether cover is required and the policy section addressing it.

Step 3: Verify application answers

Assign each question to the person able to verify it — possible owners include a director, finance, HR, the legal or data-protection lead, the IT provider, internal IT or the broker. Track the answers in a simple ownership table:

QuestionBusiness OwnerTechnical VerifierEvidenceLast Checked

Never assume that last year’s answer is still correct.

Step 4: Check identity and access security

  • MFA protects Microsoft 365 or Google Workspace.
  • MFA protects administrator accounts.
  • MFA protects remote access.
  • MFA protects backup platforms.
  • Shared administrator accounts are avoided where practical.
  • Old accounts are removed promptly.
  • Privileged access is reviewed.
  • Emergency accounts are protected.
  • Supplier access is documented.
  • Leaver access is removed.

Step 5: Check devices, patching and protection

  • Supported operating systems are used.
  • Unsupported devices are identified.
  • Security updates are monitored.
  • Endpoint protection is active and coverage is checked regularly.
  • Disk encryption is enabled where required.
  • Local administrator access is controlled.
  • Mobile and remote devices are considered.
  • Firewall and network equipment remain supported.

Step 6: Check backups and recovery

  • Critical servers and systems are backed up.
  • Microsoft 365 or other SaaS data is considered separately.
  • Backups are encrypted and backup access uses MFA.
  • Copies are isolated from the production environment.
  • Backup failures are monitored.
  • Retention meets business needs.
  • Restoration has been tested and recovery time measured.
  • Recovery responsibilities are documented.
  • Credentials needed during recovery are available securely.

Step 7: Review the policy details

  • Overall policy limit and excess
  • Business-interruption waiting period and indemnity period
  • Ransomware or extortion sub-limit
  • Social-engineering and funds-transfer fraud cover
  • Supplier and cloud-service cover
  • Data-restoration cover
  • Forensic, legal and public-relations support
  • Regulatory investigation cover
  • Notification deadline
  • Approved supplier and prior-consent requirements
  • War or state-backed cyber exclusions
  • Territorial limits and retroactive date
  • Conditions precedent or continuing obligations

Ask your broker or insurer to explain anything unclear — this guide cannot interpret policy wording for you.

Step 8: Prepare for an incident

  • Insurer emergency number and broker details are recorded.
  • The policy number is accessible offline.
  • Senior management knows who may notify the insurer.
  • The IT provider knows the notification process.
  • Alternative communication is available.
  • An incident-response plan exists.
  • Staff know how to report suspicious activity.
  • Evidence-preservation instructions exist.
  • Major expenditure requires appropriate authorisation.
  • Data-protection and legal responsibilities are assigned.
  • The plan has been tested.

Step 9: Keep controls operating

  • MFA coverage is monitored.
  • Backup failures are investigated and restore tests are scheduled.
  • Unsupported software is reviewed.
  • Patch compliance is monitored.
  • Security-provider coverage is checked.
  • Administrator access is reviewed.
  • Supplier changes are assessed.
  • Major system changes are reported where required.
  • Policy conditions are checked during the year.
  • Renewal answers are rebuilt from current evidence.

Questions for your broker or insurer

  1. 1What events and losses does the policy cover?
  2. 2What are the principal exclusions?
  3. 3What is the policy limit, and which areas have sub-limits?
  4. 4What excesses and waiting periods apply?
  5. 5Does the policy cover business interruption, and how is lost income calculated?
  6. 6Are cloud and technology-supplier outages covered?
  7. 7Is social-engineering or payment-diversion fraud included?
  8. 8Must we obtain approval before incurring costs, and which specialists must we use?
  9. 9How quickly must an incident be reported, and who do we contact out of hours?
  10. 10What security controls must remain in place during the policy period?

Questions for your IT provider

  1. 1Can you verify the technical answers in our insurance application?
  2. 2Is MFA enabled for all administrator and remote-access accounts, with no exclusions?
  3. 3Which systems are unsupported or approaching end of support?
  4. 4How are security updates monitored, and what endpoint protection is deployed?
  5. 5Are our backups encrypted and separated from the production environment?
  6. 6When was restoration last tested, and how long would full recovery take?
  7. 7Is Microsoft 365 or other cloud data backed up separately?
  8. 8How is supplier access controlled and logged?
  9. 9Can you support an insurer-appointed forensic team?
  10. 10Can you provide written evidence of the controls we have declared?

Want the full business explanation?

Read our Technology Intelligence article on how cyber insurance works and why the wording matters:

Cyber Insurance: What Does It Really Protect?

Plain-English Takeaway

Cyber insurance should work alongside your security controls and incident-response plan. Understand the cover, verify every technical answer, retain evidence and make sure the required controls continue operating throughout the policy period.

Downloadable guide

Download the Cyber Insurance Readiness Checklist

A printable checklist covering policy details, technical controls, application answers, backups and incident response.

Download PDF

Free download. No email address required.

Want the full business explanation?

The Technology Intelligence article covers why this matters, where it helps and what to watch out for.

Read the full Technology Intelligence article

Related Knowledge Centre resources

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.