Cyber Insurance Audit Preparation Checklist
Use this checklist to capture the information and documents needed to prepare for a cyber insurance audit.
Organization and Contact Information
Organization Name
*
Industry / Sector
*
Please Select
Technology
Financial Services
Healthcare
Retail
Manufacturing
Education
Government
Professional Services
Nonprofit
Other
Primary Contact Name
*
Job Title / Role
Business Email
*
example@example.com
Preferred Contact Method
*
Email
Phone
Text Message
Other
Cybersecurity Program Overview
Documented cybersecurity program in place?
*
Yes
No
Overall security maturity for audit readiness
*
Initial
1
2
3
4
5
6
7
8
9
Fully prepared
10
1 is Initial, 10 is Fully prepared
Brief summary of current cybersecurity posture and main concerns
Policies, Standards, and Governance
Policy Status Assessment
*
Rows
In place
Partially in place
Not in place
Needs review
Access control policy
1
2
3
4
Acceptable use policy
5
6
7
8
Incident response policy
9
10
11
12
Backup and restore policy
13
14
15
16
Vendor management policy
17
18
19
20
Employee awareness and training policy
21
22
23
24
Policy Owner / Reviewer
*
Last Review Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Asset and Data Inventory
Do you maintain an up-to-date inventory of assets and data?
*
Yes
Partially
No
In Progress
Which inventory categories are maintained?
*
Hardware
Software
Cloud Services
Critical Data Assets
Network Devices
Other
Key systems or data categories inventory
*
Is the inventory reviewed and updated on a regular schedule?
*
Yes
No
Not Yet Established
Access Management and Authentication
User access review frequency
*
Monthly
Quarterly
Semi-annually
Annually
Ad hoc
Other
Multi-factor authentication enabled for critical systems and remote access
*
Yes
No
Partially
Other
Privileged accounts restricted and monitored
*
Yes
No
Partially
Other
Notes on joiner, mover, and leaver access processes
Security Monitoring and Incident Response
Security logging and monitoring implemented?
*
Yes
No
Partially
Planned
Other
Incident response plan exists and has been tested?
*
Yes, and tested
Yes, but not yet tested
In development
No
Other
Date of last test or tabletop exercise
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Number of incidents in the past 12 months
Brief description of major incidents or lessons learned
Backup, Recovery, and Business Continuity
Backup frequency
*
Daily
Weekly
Monthly
Other
Are backups encrypted and tested?
*
Yes
No
Partially
Other
Recovery time objective (hours)
*
Recovery point objective (hours)
*
Is there a business continuity or disaster recovery plan?
*
Yes
No
In progress
Other
Last recovery test date
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Third-Party and Vendor Risk
Are vendors and service providers reviewed for security risk?
*
Yes
No
In Progress
Not Applicable
Do contracts include security requirements?
*
Yes
No
Partially
Not Applicable
Number of critical vendors
*
Vendor risk review list
*
Employee Awareness and Training
Is security awareness training required for all employees?
*
Yes
No
Training frequency
*
Please Select
New hire onboarding
Quarterly
Semi-annually
Annually
Ad hoc
Other
Completion rate or percentage trained
*
Additional training topics needed before audit
Insurance and Audit Readiness Documents
Documents Available
*
Policies
Network Diagrams
Asset Inventory
Incident Response Plan
Backup Evidence
Training Records
Vendor Reviews
Other
Supporting Documents
Upload a File
Drag and drop files here
Choose a file
Cancel
of
Audit Readiness Notes or Blockers
Submit Checklist
Should be Empty: