Guide4 min read·

Cyber insurance readiness, before renewal day.

This cyber insurance readiness checklist for small businesses covers the questions applications now ask — MFA, endpoint protection, backups, access control, patching, documentation, and training — so you can find gaps before deadlines get stressful.

A cyber insurance application with MFA, endpoint protection, backups, admin access, patching, and incident plan checked off, next to a renewal-ready shield.
01

Why applications ask detailed questions.

Carriers want to understand how a business reduces risk and how prepared it is to respond. For many small businesses, the application reveals that key security details are scattered, outdated, or unclear.

The answers matter: incomplete or inaccurate responses can create problems during underwriting or after a claim.

02

1. Multi-factor authentication.

MFA is one of the most common requirements. Confirm it is enforced — not just available — on:

Email & productivity

Microsoft 365 or Google Workspace.

Remote access

VPN and any remote desktop tools.

Admin & backup

Administrator accounts, backup systems, and cloud portals.

Finance & business apps

Banking portals, password managers, and line-of-business apps.

03

2. Endpoint protection.

Document the product, which devices are covered (including servers), who monitors alerts, how agents update, whether devices can be isolated remotely, and what happens when a device falls out of compliance. Coverage gaps are easier to fix when they are visible.

04

3. Backup and recovery.

Review what is backed up, frequency, retention, storage location, ransomware protection, alerting, restore testing, and estimated recovery time.

Backups running, monitored, and restore-tested
Strong answer
Backups running but never restore-tested
Gap
Unsure what is backed up
Fix first
05

4. Access controls.

Strong access controls keep one compromised account from becoming a larger incident.

  • Know who has admin rights
  • Separate admin accounts from daily-use accounts
  • Approve access deliberately and remove it at offboarding
  • Eliminate shared accounts where possible
  • Close old vendor and former-employee accounts
06

5. Patch and update practices.

Document how operating system, third-party application, and firewall or network firmware updates are handled, how urgent patches are prioritized, and who verifies update status. Patch management does not need to be complicated, but it should be intentional.

07

6. Documentation and incident response.

An incident response plan does not need to be a large enterprise document — just clear enough to help people act quickly. Your business should know:

  • Who to contact during a security incident
  • Who manages email and backups
  • Where system documentation is stored
  • Which vendors need to be notified
  • Which systems are most critical
  • Who can make emergency decisions, and how staff report suspicious activity
08

7. Security awareness.

Human error is still a major source of risk. Consider documenting phishing awareness training, new-employee security onboarding, password manager expectations, suspicious-email reporting, sensitive data handling, and periodic refreshers.

Starter checklist

Eight items carriers commonly ask about.

Tick them off as you go — your progress is saved in this browser. Stuck on a step? That's exactly what we help with.

Get help with your plan →
0 of 8done

Review your IT before cyber insurance renewal.

Computers by Geeks can check MFA coverage, endpoint protection, backups, documentation, access control, and incident response readiness. We can't guarantee approval or coverage — but we can show you where you're strong and where you need attention.