Free tool · Cyber insurance

Would your business be insurable tomorrow?

Fourteen questions, the ones insurers and brokers actually ask. A verdict right away, the full report by email, with what is yours to fix and what is your IT partner's.

0 / 14 answered

Identity and access

Is multi-factor authentication required for every email account, without exception?

Is it required for all remote access: VPN, remote desktop, administration tools?

Are administrator accounts separate from everyday accounts?

Endpoints and servers

Do all endpoints have EDR protection (detection and response), managed and monitored by someone?

Are security updates applied within 14 days on endpoints and servers?

Are there still systems that no longer receive updates: Windows 10, old servers, unsupported NAS?

Backups

Is there an offline or immutable backup copy, out of reach of ransomware?

Has a full restore been tested in the last 12 months?

Email and exposure

Is email protected against phishing and spoofing: advanced filtering, DMARC at reject?

Can you confirm that no service is directly exposed on the Internet: remote desktop, file shares, admin consoles?

Business processes

Do employees get phishing training at least once a year?

Is a change in a supplier's banking details always verified through a second channel, a call to a number already on file?

Are a departing employee's accesses cut the same day?

Is there a written incident plan: who to call, what to unplug, how to communicate?

Nothing is read from your systems: your answers are the only data. They serve only to produce your report and to follow up.