C-01 · Multifactor authentication Stopper
When your team checks email or logs in from outside the office, do they have to approve it on their phone or enter a code? When your team checks email or logs in from outside the office, do they have to approve it on their phone or enter a code?
Just a password isn't enough on its own anymore.
Yes, every time, including for the people who manage our systems Only in some places No, a password is all it takes
C-02 · Backups Stopper
If every file you own were locked up tonight, do you have a separate copy an attacker couldn't reach, and has anyone actually tried restoring from it in the past year? If every file you own were locked up tonight, do you have a separate copy an attacker couldn't reach, and has anyone actually tried restoring from it in the past year?
A backup nobody has ever restored from doesn't count yet.
Yes, and we tested restoring it this year We have backups, but nobody has tested restoring them No separate copy, or I'm not sure
C-03 · Security software Stopper
Do your computers run modern security software that can stop an attack while it's happening, not just traditional antivirus? Do your computers run modern security software that can stop an attack while it's happening, not just traditional antivirus?
Most insurers now ask for this by name on the application.
Yes, on every computer and server On some of them Just regular antivirus, or I'm not sure
C-04 · Who's watching Priced
If that software caught something at 2am on a Saturday, is there a person whose job it is to see the alert and act on it? If that software caught something at 2am on a Saturday, is there a person whose job it is to see the alert and act on it?
Software that catches an attack but nobody answers is a record of the attack, not a response to it.
Yes, someone monitors it around the clock Someone checks it during business hours No one is watching, or I'm not sure
C-05 · Remote access Stopper
Can someone reach your office computers from the internet without first connecting through a secure company connection? Can someone reach your office computers from the internet without first connecting through a secure company connection?
If staff "remote in" from home, it matters a great deal how they do it.
No, everyone connects through a secure company connection first I'm not sure Yes, people connect directly
C-06 · Incident plan Priced
If you were hit tomorrow morning, is there a written plan saying who calls whom, and has your team ever walked through it? If you were hit tomorrow morning, is there a written plan saying who calls whom, and has your team ever walked through it?
Insurers ask for the document and the date you last practiced it.
Written down, and we walked through it this year Written down, but never practiced Nothing written down
C-07 · Updates Priced
When an urgent security update comes out, how long before it's installed on your systems? When an urgent security update comes out, how long before it's installed on your systems?
Attackers start using these within days of them becoming public.
Within about a week Within about a month There's no set routine
C-08 · Email screening Priced
Is something checking your incoming email for dangerous links and attachments before it reaches your staff? Is something checking your incoming email for dangerous links and attachments before it reaches your staff?
This is where most wire fraud and ransomware starts.
Yes, and we've set up the records that stop people faking our email address Basic spam filtering only I'm not sure
C-09 · Who has the keys Priced
Do the people who manage your systems use a separate login for that work, and do regular staff only get access to what their job needs? Do the people who manage your systems use a separate login for that work, and do regular staff only get access to what their job needs?
This decides whether one compromised laptop becomes a company-wide problem.
Yes, separate logins and access limited by role Partly Everyone has full access
C-10 · Old systems Priced
Is anything in your office still running software the manufacturer stopped supporting? Is anything in your office still running software the manufacturer stopped supporting?
Old Windows versions, or an industry program that only runs on an old machine.
No, everything is current Some, and it's kept separate from everything else Yes, and it's on the main network
C-11 · Records
If you had to reconstruct what happened during a break-in, would you have at least three months of records to look back at? If you had to reconstruct what happened during a break-in, would you have at least three months of records to look back at?
Without them, investigators are guessing, and insurers price guesses cautiously.
Yes, three months or more, and someone reviews them We keep records, but nobody reviews them I'm not sure
C-12 · Staff training
Does everyone do security training at least once a year, with fake phishing emails sent to test whether it stuck? Does everyone do security training at least once a year, with fake phishing emails sent to test whether it stuck?
Most incidents start with a person, not a machine.
Yes, training and phishing tests Training, but no phishing tests Neither
C-13 · Outside vendors
Do outside companies who can get into your systems have to follow the same security rules your own staff does? Do outside companies who can get into your systems have to follow the same security rules your own staff does?
In Marsh's 2026 survey, 70% of organizations reported a serious incident that started with a third party.
Yes, and it's written into their contracts Informally, nothing written I'm not sure