Pre-Audit Questionnaire
Client intake form for discovery/scoping and readiness support before the evidence review begins.
Evidence Checklist
Interactive 47-item evidence review checklist. Track evidence supported, partial evidence, not verified, and not reviewed items.
Report Template
Working report template for structured evidence review, discussion-ready findings, recommendations, and evidence appendix notes.
Outreach Templates
Outreach drafts for broker and IT-director conversations about evidence review and readiness support.
Broker One-Pager
Print-ready handout for broker conversations about evidence review and readiness support.
⏱ Typical Engagement Timeline
🎯 Example Cyber Insurance Questionnaire Focus Areas
Carrier requirements vary by policy, carrier, industry, renewal cycle, and coverage limit. Always verify against the current questionnaire and broker guidance.
- MFA on all users (including email) Required
- MFA on all admin / privileged accounts Required
- Immutable, offline, or air-gapped backups Required
- EDR on all endpoints Required
- Documented patch management SLA Common
- Email filtering / anti-phishing Common
- Incident Response plan (documented) Common
- Security awareness training (>90%) Common
- Penetration test may be requested by some carriers; not included in this service unless separately scoped Varies
- Privileged Access Management (PAM) Varies
- SIEM / centralized log collection Varies
- Third-party / MSP access controls Varies
These are examples only, not current carrier rules or guarantees. Always verify against the current questionnaire and broker guidance.
- MFA coverage may be requested for users and privileged access
- Backup immutability and separation from production may be requested
- EDR endpoint coverage and policy exports may be requested
- External attack surface findings can be a common evidence concern
- Patch cadence for critical CVEs may be reviewed
- Formal incident response planning may be requested
- Privileged access controls may be reviewed
- Security awareness training documentation may be requested
- Third-party vendor risk management may be reviewed
- Network segmentation evidence may be requested
- Ransomware-specific controls may receive additional attention
- Remote access controls may be requested
- Legacy authentication blocking may be reviewed
- Email security controls may be requested
- Backup restore testing evidence may be requested
Ready to start your audit?
Free 30-minute discovery call. Fixed quote before you commit. Conroe, TX — serving clients remotely nationwide.