Free browser-based worksheet

Cyber Readiness & Insurance Gap Checklist

Review operational controls using the NIST CSF structure and turn unknown policy terms into exact broker questions.

No signup · no upload · no stored entries

What this worksheet is for

Cyber applications ask about controls, while policies use separate first- and third-party terms. This self-assessment keeps the operational and insurance conversations distinct.

Operational controls

This self-assessment follows the six NIST CSF functions. “Yes” should mean a control exists and can be evidenced—not merely planned.

Govern
Identify
Protect
Detect
Respond
Recover
Policy scenario check
Your working result
Self-assessment completion0%

Yes controls ÷ applicable controls. This is not a security grade, certification or underwriting score.

Operational follow-up

  • Govern: A named person owns cybersecurity decisions
  • Govern: Critical vendors and their responsibilities are documented
  • Identify: Devices, software, data and critical services are inventoried
  • Identify: Sensitive data locations and access are reviewed
  • Protect: Multi-factor authentication protects important accounts
  • Protect: Security updates are applied through a defined process
  • Protect: Employees receive phishing and security training
  • Protect: Access is removed promptly when roles change
  • Detect: Important systems and account activity are logged
  • Detect: Someone reviews security alerts and unusual activity
  • Respond: A written incident response plan names contacts and decisions
  • Respond: The response plan is tested or discussed on a schedule
  • Recover: Backups are separated from normal systems
  • Recover: Restoration from backup has been tested

Questions for the agent

  • How does the proposed policy address data breach response and forensics—including trigger, limit, retention and exclusions?
  • How does the proposed policy address customer notification and credit monitoring—including trigger, limit, retention and exclusions?
  • How does the proposed policy address business interruption and restoration—including trigger, limit, retention and exclusions?
  • How does the proposed policy address cyber extortion / ransomware—including trigger, limit, retention and exclusions?
  • How does the proposed policy address vendor or dependent-system incident—including trigger, limit, retention and exclusions?
  • How does the proposed policy address privacy or security liability and defense—including trigger, limit, retention and exclusions?
Transparent method

How the result is produced

  1. Controls are organized around Govern, Identify, Protect, Detect, Respond and Recover from NIST CSF 2.0.
  2. Completion is Yes responses divided by applicable controls. It is not a security, underwriting or certification score.
  3. Policy scenarios marked Unknown create questions to confirm against the actual policy with a licensed professional.
Boundaries

What it cannot determine

  • Whether your organization is secure
  • Whether an insurer will accept an application
  • Whether a loss is covered under a specific policy

Sources used to design this worksheet

These sources support the questions and process—not an individualized recommendation. State-specific sources are identified as examples and are not presented as nationwide rules.

Method and sources reviewed August 13, 2026. Entries and results should be confirmed against the actual proposal or policy with an appropriately licensed professional.