The Ultimate Agency

Free business guide / Cyber insurance

Get ready before you fill out the form.

Cyber insurance forms can ask hard questions. Use this list to gather the facts, spot weak areas, and talk with your IT team and insurance agent.

Start the checklist

Nine key areas

Check what your business has in place.

A yes does not mean you will get coverage. A no does not mean you will be turned down. Your insurer sets its own rules.

MFA

More than one sign-in step

Use a second check for email, cloud tools, remote access, and admin accounts. Ask if it covers every user.

BACKUPS

Clean copies of key data

Keep copies away from your main network. Test that you can bring files and systems back.

PATCHING

Fast fixes for weak spots

Know who updates computers, servers, apps, and network gear. Track old tools that no longer get fixes.

EDR

Watch computers for attacks

Ask what tool watches laptops and servers. Know who gets an alert and who acts on it.

EMAIL

Block bad mail and links

Use spam and link checks. Set rules that make it harder for a thief to fake your email.

ADMIN ACCESS

Keep high power accounts rare

Give admin rights only when needed. Use a separate admin account and remove old access fast.

INCIDENT PLAN

Know what to do after an attack

Write down who to call, what to shut off, what to save, and when to call your insurance team.

VENDORS

Check outside access

List firms that can reach your data or systems. Remove old access and ask how each firm stays safe.

TRAINING

Help staff spot a trick

Teach staff how to spot bad links, fake bills, and odd sign-in asks. Give them a fast way to report one.

What to gather

Put the facts in one safe place.

Do not send passwords, private keys, or full access details in a web form. Share only what is needed.

  • Your current cyber insurance form or renewal note
  • A list of key computers, servers, apps, and cloud tools
  • Names of your IT and security firms
  • Notes on MFA, backups, patching, EDR, and email safety
  • Your incident plan and key contact list
  • Dates from your last backup test and staff training
  • A list of vendors with access to data or systems
  • Any open gaps and the plan to fix them

Common questions

Ask before you say yes or no.

Small words on a form can mean a lot. If a question is not clear, ask the insurer or your agent what it means.

  • Does MFA cover every user, admin, and remote login?
  • How often are backups made and tested?
  • How fast are high-risk updates installed?
  • Does EDR cover every laptop and server?
  • Who watches alerts after work hours?
  • When was the incident plan last tested?
  • How fast is old staff and vendor access removed?
  • What proof should we keep for each answer?

Before you submit

Make sure each answer is true today.

ASK

Bring in the right people

Your owner, IT team, security firm, insurance agent, and legal team may hold different facts.

CHECK

Look for proof

Keep reports, test dates, tool lists, and written plans. Do not guess when you can check.

FIX

Make a short gap list

Write down each open need, who owns it, and the date it should be done.

This guide is for general help. It is not legal, insurance, or security advice. Only your insurer can tell you what it needs for a policy.

Want a second set of eyes?

Find the gaps before the form is due.

Tell us what your insurer is asking. We can help you sort the questions, gather the right people, and find next steps.

Request a free cyber review

We do not promise coverage, lower rates, or full security. There is no fee for the first review. We may connect you with an advisor or provider. If you buy from a provider we introduce, that provider may pay us.