The Cybersecurity Checklist Insurers Actually Check
Most cybersecurity checklists tell you to “use strong passwords” and “keep software updated.” You already knew that. What they do not tell you is what good actually looks like, or which gaps will get a claim denied when you need your cyber insurance to pay out.
This one is built around the controls insurance underwriters and auditors actually ask about. Work through it honestly. Anything you cannot answer yes to is a gap worth a conversation.
How to use this checklist
Answer each item yes or no. “Probably” counts as no. If you are not certain whether a control is in place, it is not in place, because nobody is verifying it.
1. Identity and access
Stolen credentials are the most common way attackers get in, and identity is where most small businesses have the widest gap.
- Multi-factor authentication is enforced on email, VPN, remote access, and every administrative account. Not offered. Enforced, with no exceptions carved out for executives.
- Administrative accounts are separate from daily-use accounts. Your IT person should not browse the web logged in as a domain admin.
- Departing employees lose access the same day they leave, across every system including the ones IT did not set up.
- Nobody shares a login. Shared accounts mean you cannot tell who did what after an incident.
MFA is the one item on this list that insurers now treat as non-negotiable. Several carriers will not write a policy without it, and a claim can be contested if you attested to having it and coverage turns out to be partial.
2. Email
Email is still where most attacks start, and business email compromise costs companies more than ransomware does.
- Advanced phishing filtering is running, beyond what came in the box with your mail platform.
- SPF, DKIM, and DMARC are configured, and DMARC is set to something stronger than monitor-only. Half-configured DMARC protects nobody.
- External senders are visibly flagged so a spoofed message from “the CEO” is obvious.
- Mailbox forwarding rules are monitored. Attackers who get into a mailbox often set up a quiet forward and read your mail for weeks before doing anything.
- Any change to payment details gets verified by phone, using a number you already had, not the one in the email.
3. Devices
- Every computer runs endpoint detection and response, not consumer antivirus. EDR watches behavior and can isolate a machine mid-attack. Antivirus matches known signatures and misses anything new.
- Laptops are encrypted, so a device left in a car is an inconvenience rather than a breach notification.
- Patches are applied on a schedule somebody owns and reports on, covering third-party software as well as Windows.
- Personal devices that reach company data are either managed or explicitly blocked. Pick one.
- No machine on the network is running an operating system past end of support.
4. Backup and recovery
This is where the checklist stops being about prevention. Backups are what determine whether a bad week becomes a bad quarter.
- Backups run automatically and somebody sees an alert when one fails.
- At least one copy is offsite and immutable, meaning ransomware that reaches your network cannot encrypt or delete it.
- Microsoft 365 is backed up. Microsoft replicates your data for availability. That is not the same as keeping a copy you can restore from after a deletion or an account compromise.
- A real restore has been tested in the last 90 days. Not a green checkmark in a dashboard. An actual file pulled back and opened.
- You know how long a full recovery would take, and the business has agreed that number is survivable.
5. Monitoring and response
- Something watches your systems outside business hours. Most intrusions start on a Friday evening or over a holiday weekend for exactly that reason.
- Alerts go to a human who is expected to act on them, not to an inbox nobody opens.
- You have a written incident response plan naming who isolates systems, who calls the insurer, who talks to clients, and who contacts law enforcement.
- Somebody has walked through that plan out loud in the last year.
6. Your people
- Staff get security awareness training more than once a year, and you can produce records of it.
- Simulated phishing runs regularly, and the results are used for coaching rather than blame.
- People know who to tell when they think they clicked something, and they know they will not get in trouble for reporting fast.
That last one matters more than it sounds. The gap between a click and a report is where most of the damage happens, and staff who expect to be blamed stay quiet.
7. Documentation and insurance
- You have written security policies, and what they describe matches what is actually configured.
- Everything you attested to on your cyber insurance application is genuinely in place today.
- Vendors with access to your systems or data have been reviewed at least once.
- You know which compliance frameworks apply to you and where you currently fall short of them.
Reading your score
Nobody gets all of these. Count your no answers.
- Zero to three no answers: Solid footing. Focus on testing what you believe is working.
- Four to eight: Typical for a growing business without dedicated security help. Prioritize MFA coverage, immutable backup, and a tested restore before anything else.
- Nine or more: You are relying on not being noticed. That works until it does not, and the recovery cost is usually many times what closing the gaps would have run.
Real failures are rarely one dramatic mistake. They are an old admin account nobody disabled, a backup that had been failing silently for five months, and one person having a distracted Tuesday.
Frequently asked questions
What should a small business cybersecurity checklist cover? At minimum: enforced multi-factor authentication, email filtering with SPF, DKIM and DMARC, endpoint detection and response on every device, immutable offsite backup with tested restores, after-hours monitoring, staff training with records, and a written incident response plan.
Is antivirus enough? No. Antivirus matches known threats. Endpoint detection and response watches for suspicious behavior and can isolate a machine while an attack is in progress, which is what stops ransomware from spreading.
Do we really need to back up Microsoft 365? Yes. Microsoft is responsible for keeping the service running, not for recovering data you deleted or an attacker destroyed. Retention windows are limited and shorter than most businesses assume.
How often should we test a restore? Quarterly at minimum, and after any significant change to your environment. A backup nobody has restored from is a theory.
Why does our cyber insurance keep asking harder questions? Carriers paid out heavily on ransomware and have tightened underwriting since. They now verify controls rather than taking your word for it, and they will check your attestations against reality when a claim comes in.
Find out where you actually stand
Working through this list on your own will surface the obvious gaps. It will not catch the ones you do not know to look for, like the backup job that has been quietly failing or the service account created for a project three years ago that still has full access.
QIT Solutions runs security assessments for businesses across West Palm Beach, South Florida, and Atlanta. You get a clear picture of what is in place, what is missing, and what to fix in what order.
See our cybersecurity services, schedule an assessment, or call 1-844-855-4748.