Free Self-Assessment

Cyber Insurance Readiness Check

How This Check Helps

Cyber insurance applications and renewals now ask detailed questions about your security controls, and an answer that does not match reality can affect your coverage when you need it. This check is built from the controls carriers and brokers ask about, including multi-factor authentication, endpoint detection and response, offline backups and payment-change verification.

You answer 22 questions, see your score instantly and get a prioritized list of gaps. Use it before your renewal questionnaire arrives, or to check whether your current IT provider has the controls in place that your application says you have.

Hands completing a printed security readiness checklist on a clipboard

Answer 22 Questions

Choose Yes, No, Unknown or Not applicable for each question. It takes about 6 minutes, and you see your score as soon as you finish.

Login & Access Security

Does every employee need a one-time code or app approval, not just a password, to check company email?

Multi-factor authentication on email is among the controls carriers ask about most, because stolen email passwords are a common way attacks begin.

Is a one-time code or app approval required to connect remotely to your network, such as through VPN or remote desktop?

Remote access is a top ransomware entry point; carriers require MFA on every VPN and remote-desktop connection before binding coverage.

Do IT administrator and other privileged accounts require a one-time code or app approval beyond a password to log in?

Privileged accounts control the whole network; unprotected admin access is one of the three controls carriers grade as a hard minimum.

Are administrator-level permissions limited to only the few people who truly need them, rather than shared broadly?

Privileged access management (least privilege) limits how much damage one stolen password or phished employee can cause.

Endpoints, Network & Patching

Is endpoint detection and response (EDR) software installed on every computer and server, not just some devices?

Carriers ask whether EDR covers every endpoint, including servers. Gaps in coverage can affect whether you qualify and how a claim is handled.

Are security alerts from your computers and servers actively watched, with someone able to respond at any hour?

Insurers' logging and monitoring controls expect alerts to be watched and acted on around the clock; unwatched alerts give attackers time.

Are security updates (patches) applied to computers, servers, and software on a regular, defined schedule?

Carriers expect critical patches to be applied promptly on a defined schedule; unpatched systems are a common way attackers get in.

If remote desktop (RDP) is used, is it blocked from being reached directly over the public internet?

Exposed RDP is one of the most common ransomware entry points; carriers flag it as a standalone hardening question.

Backup & Recovery

Do you keep at least one backup copy offline or immutable, disconnected from your regular network?

Attackers target connected backups first; carriers treat an offline or immutable copy as required before they will pay a ransomware claim.

Have you tested restoring data from backup within the last 12 months to confirm it actually works?

There is no point having backups that are unavailable or incomplete when needed; insurers treat regular restore testing as essential, not optional.

Do your backups cover all critical business systems and data, not only files on individual computers?

Partial backups leave core operations unrecoverable; carriers ask whether backup scope covers critical systems, not just individual user files.

Email, Data & Payment Security

Do you use email filtering software that blocks or flags suspicious links and attachments before they reach inboxes?

Phishing is a common way ransomware starts; email filtering that blocks malicious links and attachments is a named carrier control.

Are laptops and mobile devices holding company data encrypted, so data is unreadable if a device is lost or stolen?

Encryption protects data even if hardware disappears; government guidance specifically recommends disk encryption for laptops and mobile devices.

Do you require a follow-up phone call to a known number before changing any vendor's payment or bank account details?

Carrier applications ask this directly. Calling a known number before changing payment details helps stop fraudulent payment-change requests.

Incident Response & Awareness

Do you have a written incident response plan describing exactly what to do first if you suspect a cyberattack?

A documented incident response plan, reviewed by leadership, is a named carrier control and helps your team act quickly and in the right order.

Has your incident response plan been tested with a practice run (tabletop exercise) in the last 12 months?

An annual tabletop exercise is a recommended practice so the response team knows its role; an untested plan often fails under real pressure.

Do all employees receive recurring security awareness training, including simulated phishing tests, at least once a year?

Carriers ask how often phishing training runs; annual or more-frequent simulated phishing is a named control tied to fewer breach claims.

Do you keep logs of network and security activity, retained for at least a few months, not just a few days?

Guidance recommends logs stay accessible for at least three months and backed up for a year, to support investigation and claims.

Vendor Risk & Governance

If you use an outside IT provider (MSP), do you know what security controls they apply to your systems?

MSP compromise can expose every client at once; cyber applications specifically ask whether an MSP is used and which one.

Do you review the cybersecurity practices of vendors or suppliers who can access your network or data?

A breached vendor with access to your network or data can expose your business too, so carriers ask how you manage vendor risk.

Do you keep track of any outdated or unsupported (end-of-life) software or hardware still in use?

Unsupported systems stop receiving security patches and become known, easy targets; tracking and replacing them is a named carrier control.

Do you review your cyber insurance coverage and limits at each renewal to make sure they still match your risk?

Coverage needs change as a business grows; regulators recommend discussing current risk and policy fit with your agent at every renewal.

This self-assessment is educational. It is not an audit, a certification, legal advice or an insurance underwriting decision. Your answers stay in your browser and are not sent to Triton unless you contact us.

How Your Score Works

Each Yes earns points, weighted by how much insurers care about the control. No and Unknown earn none, because an underwriter treats a control you cannot confirm as missing. Not applicable removes a question from your total.

A score of 85 percent or higher, with every high-priority control in place, is a strong result. High-priority controls are the ones carriers commonly treat as requirements: multi-factor authentication on email, remote access and administrator accounts, endpoint detection and response on every device, and an offline or immutable backup.

Every carrier’s application is different. Answer your actual application truthfully, and use this check to find what to fix before you do.

What Happens After You Finish

A strong score: congratulations. Your security controls are where reviewers expect them to be. If you are happy with your current IT provider, they are doing their job. If you are not, Triton would be a good fit: we can take over without losing what you have built.

Gaps or a failing score: set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps.

Cyber Insurance Readiness: Common Questions

No. Underwriting decisions belong to the carrier and depend on your industry, size, claims history and the full application. A high score means the controls carriers ask about most appear to be in place.

Because the application asks you to confirm each control. If you cannot confirm it, treat it as missing until someone verifies it.

No. Your answers stay in your browser, and nothing is sent to Triton unless you choose to contact us.

The owner, the office manager or whoever completes your insurance application, ideally with your IT provider. If you are not sure, choose Unknown.

No. Triton puts the security controls in place and documents them, so you can answer your carrier’s questions accurately. Your broker or carrier handles the policy.

Set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps before your renewal.

How Triton Delivers

The Sophos XDR Mandate

We deploy Sophos Firewalls as the non-negotiable perimeter standard. Any firm operating without synchronized endpoint protection is an insurance liability. Sophos Endpoint (EDR/XDR) is the mandatory internal security layer.

AWS Scalability

We deploy on AWS because downtime is not an option. When a critical system goes down, AWS support responds with enterprise urgency, not a ticket queue. Every dollar of downtime is a dollar your IT provider owes you an answer for.

The AI Autonomous Advantage

Axiom, Triton’s proprietary AI monitoring system, gives our engineers real-time visibility that off-the-shelf tools cannot replicate. It is not for sale, it is how we deliver.

Founded in 2001

25 Years of IT Expertise

Serving New England

5 Regional Offices + Dublin & BVI

Under 10 Minute Response

84th Percentile · MSPbots Verified

Sophos Silver · Microsoft Solutions Partner

Security & Cloud Partners

HIPAA · CMMC · SOC 2 · PCI

Multi-Framework Compliance

Let's Discuss Your IT Needs

Triton Technologies delivers managed IT services, cybersecurity, and IT support for businesses across New England. Contact our team today to start a conversation about your technology environment.

Triton Technologies support engineer at workstation