• Cyber Insurance Audit Preparation Checklist

    Use this checklist to capture the information and documents needed to prepare for a cyber insurance audit.
  • Organization and Contact Information

  • Preferred Contact Method*
  • Cybersecurity Program Overview

  • Documented cybersecurity program in place?*
  • Policies, Standards, and Governance

  • Policy Status Assessment*
    Rows
  • Last Review Date*
     - -
    2 digit month, 2 digit day, 4 digit year
  • Asset and Data Inventory

  • Do you maintain an up-to-date inventory of assets and data?*
  • Which inventory categories are maintained?*
  • Key systems or data categories inventory*
  • Is the inventory reviewed and updated on a regular schedule?*
  • Access Management and Authentication

  • User access review frequency*
  • Multi-factor authentication enabled for critical systems and remote access*
  • Privileged accounts restricted and monitored*
  • Security Monitoring and Incident Response

  • Security logging and monitoring implemented?*
  • Incident response plan exists and has been tested?*
  • Date of last test or tabletop exercise
     - -
    2 digit month, 2 digit day, 4 digit year
  • Backup, Recovery, and Business Continuity

  • Backup frequency*
  • Are backups encrypted and tested?*
  • Is there a business continuity or disaster recovery plan?*
  • Last recovery test date
     - -
    2 digit month, 2 digit day, 4 digit year
  • Third-Party and Vendor Risk

  • Are vendors and service providers reviewed for security risk?*
  • Do contracts include security requirements?*
  • Vendor risk review list*
  • Employee Awareness and Training

  • Is security awareness training required for all employees?*
  • Insurance and Audit Readiness Documents

  • Documents Available*
  • Upload a File
    Drag and drop files here
    Choose a file
    Cancelof
  • Should be Empty:
Select theme: