WheelHouse ITMarsh Agency

Prepared jointly by WheelHouse IT and Marsh Agency.

Cyber insurance readiness check

Find out how your renewal will read to an underwriter.

Thirteen questions, about three minutes. You'll get a readiness score against the controls carriers weigh most heavily, a list of anything likely to stop or surcharge your placement, and a draft of your application answers to hand to your broker.

Start the check →
  • 25 years in business
  • ~300 Florida companies supported
  • Built with a Marsh Agency advisor

Finish the check and you may qualify for a free third-party cyber risk assessment.

Companies that complete the readiness check and meet the qualifying criteria receive an independent cyber risk assessment at no cost. It's conducted by a third party, not by us, so the findings stand on their own. Terms and conditions apply; see below.

0 of 13 answered0%

About your business

Anyone with an email address or system login, including part-time staff.

Computers your staff work on day to day.

Machines that run your systems in the background. Leave at 0 if everything runs in the cloud.

Physical offices where people work. Count home offices as one combined location.

The thirteen questions

C-01 · Multifactor authenticationStopper
When your team checks email or logs in from outside the office, do they have to approve it on their phone or enter a code?

Just a password isn't enough on its own anymore.

C-02 · BackupsStopper
If every file you own were locked up tonight, do you have a separate copy an attacker couldn't reach, and has anyone actually tried restoring from it in the past year?

A backup nobody has ever restored from doesn't count yet.

C-03 · Security softwareStopper
Do your computers run modern security software that can stop an attack while it's happening, not just traditional antivirus?

Most insurers now ask for this by name on the application.

C-04 · Who's watchingPriced
If that software caught something at 2am on a Saturday, is there a person whose job it is to see the alert and act on it?

Software that catches an attack but nobody answers is a record of the attack, not a response to it.

C-05 · Remote accessStopper
Can someone reach your office computers from the internet without first connecting through a secure company connection?

If staff "remote in" from home, it matters a great deal how they do it.

C-06 · Incident planPriced
If you were hit tomorrow morning, is there a written plan saying who calls whom, and has your team ever walked through it?

Insurers ask for the document and the date you last practiced it.

C-07 · UpdatesPriced
When an urgent security update comes out, how long before it's installed on your systems?

Attackers start using these within days of them becoming public.

C-08 · Email screeningPriced
Is something checking your incoming email for dangerous links and attachments before it reaches your staff?

This is where most wire fraud and ransomware starts.

C-09 · Who has the keysPriced
Do the people who manage your systems use a separate login for that work, and do regular staff only get access to what their job needs?

This decides whether one compromised laptop becomes a company-wide problem.

C-10 · Old systemsPriced
Is anything in your office still running software the manufacturer stopped supporting?

Old Windows versions, or an industry program that only runs on an old machine.

C-11 · Records
If you had to reconstruct what happened during a break-in, would you have at least three months of records to look back at?

Without them, investigators are guessing, and insurers price guesses cautiously.

C-12 · Staff training
Does everyone do security training at least once a year, with fake phishing emails sent to test whether it stuck?

Most incidents start with a person, not a machine.

C-13 · Outside vendors
Do outside companies who can get into your systems have to follow the same security rules your own staff does?

In Marsh's 2026 survey, 70% of organizations reported a serious incident that started with a third party.

A WheelHouse IT advisor will review your answers and follow up with your results.