Cyber Readiness & Insurance Gap Checklist
Review operational controls using the NIST CSF structure and turn unknown policy terms into exact broker questions.
What this worksheet is for
Cyber applications ask about controls, while policies use separate first- and third-party terms. This self-assessment keeps the operational and insurance conversations distinct.
Operational controls
This self-assessment follows the six NIST CSF functions. “Yes” should mean a control exists and can be evidenced—not merely planned.
Yes controls ÷ applicable controls. This is not a security grade, certification or underwriting score.
Operational follow-up
- Govern: A named person owns cybersecurity decisions
- Govern: Critical vendors and their responsibilities are documented
- Identify: Devices, software, data and critical services are inventoried
- Identify: Sensitive data locations and access are reviewed
- Protect: Multi-factor authentication protects important accounts
- Protect: Security updates are applied through a defined process
- Protect: Employees receive phishing and security training
- Protect: Access is removed promptly when roles change
- Detect: Important systems and account activity are logged
- Detect: Someone reviews security alerts and unusual activity
- Respond: A written incident response plan names contacts and decisions
- Respond: The response plan is tested or discussed on a schedule
- Recover: Backups are separated from normal systems
- Recover: Restoration from backup has been tested
Questions for the agent
- How does the proposed policy address data breach response and forensics—including trigger, limit, retention and exclusions?
- How does the proposed policy address customer notification and credit monitoring—including trigger, limit, retention and exclusions?
- How does the proposed policy address business interruption and restoration—including trigger, limit, retention and exclusions?
- How does the proposed policy address cyber extortion / ransomware—including trigger, limit, retention and exclusions?
- How does the proposed policy address vendor or dependent-system incident—including trigger, limit, retention and exclusions?
- How does the proposed policy address privacy or security liability and defense—including trigger, limit, retention and exclusions?
How the result is produced
- Controls are organized around Govern, Identify, Protect, Detect, Respond and Recover from NIST CSF 2.0.
- Completion is Yes responses divided by applicable controls. It is not a security, underwriting or certification score.
- Policy scenarios marked Unknown create questions to confirm against the actual policy with a licensed professional.
What it cannot determine
- Whether your organization is secure
- Whether an insurer will accept an application
- Whether a loss is covered under a specific policy
Sources used to design this worksheet
These sources support the questions and process—not an individualized recommendation. State-specific sources are identified as examples and are not presented as nationwide rules.
- NIST — Cybersecurity Framework 2.0 Small Business Quick Start ↗
- CISA — Small and medium-sized business resources ↗
- FTC — Cybersecurity for small business ↗
- FTC — Cyber insurance questions ↗
Method and sources reviewed August 13, 2026. Entries and results should be confirmed against the actual proposal or policy with an appropriately licensed professional.