The Cyber Insurance Readiness Checklist SMBs Should Review Quarterly

The Cyber Insurance Readiness Checklist SMBs Should Review Quarterly

Most small businesses review their cyber insurance controls once a year, if at all. The review happens in the weeks before renewal. Something is missing. There is not enough time to fix it. The application gets submitted anyway, or coverage gets delayed.

A quarterly review changes that. It keeps your controls current throughout the year and means you are never scrambling when the renewal window opens. This checklist is designed for business owners, office managers, and IT leads who want to maintain readiness without a large security team.

How to Use This Checklist

Work through each section with whoever manages your IT environment. For each item, confirm: Is this in place? Is it configured correctly? Has it been tested recently? Mark items that are incomplete or uncertain. Those are your action items for the next 30 days.

Identity and Access Controls

MFA is enabled for all users without exception. No accounts should be exempt. Check for service accounts, shared accounts, and executive accounts that may have been excluded.

MFA is enabled for all remote access methods. VPN, RDP, remote desktop tools, and web-based access to business applications should all require MFA.

Admin and privileged accounts have separate MFA requirements. High-privilege accounts should have stricter controls than standard user accounts.

Legacy authentication protocols are blocked. Confirm a conditional access policy is actively blocking sign-ins that use older protocols.

Terminated employees are removed from all systems within 24 hours. Former employees with active credentials are a consistent source of unauthorized access.

Endpoint Security

Endpoint detection and response (EDR) is deployed on all devices. Every device that accesses business data should have EDR installed and active. This includes remote work devices.

EDR alerts are monitored and reviewed. An EDR tool that generates unread alerts is not providing protection. Confirm who reviews alerts and at what frequency.

Operating systems and applications are patched and current. Outdated software is the most common vulnerability path. Confirm patching is running on a defined schedule.

Mobile Device Management is in place for business devices. Devices that access email and business data should be enrolled in MDM with remote wipe capability.

Backup and Recovery

Backups run on a defined schedule. Daily backups for critical data, at minimum. Weekly for lower-priority systems.

Backups include all critical data and business systems. Confirm your backup scope. Missing a file server or a database is a gap that only becomes visible during recovery.

A copy of your backups is stored off-site or offline. If your backups are in the same environment as your primary data, ransomware can reach both.

A backup restoration test was completed in the past 12 months. Untested backups are not reliable backups. Document the test date and the result.

Your estimated recovery time objective is documented. How long would it take to restore from backup and resume operations? Know the answer before an incident requires it.

Email Security

DMARC, DKIM, and SPF records are published for your domain. All three should be in place. DMARC should be set to at least a quarantine or reject policy, not just monitor mode.

Anti-phishing controls are active. If you use Microsoft 365, Defender for Office 365 anti-phishing policies should be configured. Confirm they are active and set to your risk level.

Automatic external email forwarding is blocked. Your mail flow rules or outbound spam policy should prevent users from automatically forwarding email to external addresses.

Security awareness training covering phishing was completed in the past 12 months. Users who know what phishing looks like are a meaningful control.

Network and Access Controls

Remote access to internal systems requires VPN with MFA. Open RDP to the internet is one of the most exploited access vectors. Confirm it is protected.

Vendor and contractor access is reviewed quarterly. Third-party access should be limited to what is necessary, reviewed regularly, and revoked when no longer needed.

Network segmentation separates critical systems from general use. Sensitive systems should not be reachable from every device on your network.

Documentation and Governance

A written incident response plan exists. The plan should define who is contacted, who makes decisions, and how you communicate during and after an incident.

The incident response plan has been reviewed in the past 12 months. A plan that has not been reviewed is a plan that may not match your current environment.

Your asset inventory is current. Know what systems and devices exist in your environment. You cannot protect what you do not know about.

Cyber insurance policy details are documented and accessible. Know your policy limits, your deductible, your insurer’s incident notification requirements, and who to call when an incident occurs.

Quarterly Action Steps and Resources

After each review, prioritize any incomplete items and assign ownership. Set a target completion date for each open item before the next quarterly review. Track changes over time. If the same item is incomplete for two consecutive quarters, it is not getting fixed without intervention.

The CIS Critical Security Controls provide a widely used framework for prioritizing security actions that maps well to cyber insurance requirements.

NexSecure Solutions LLC works with small businesses to close these gaps before they affect coverage. If you want to understand what a readiness review looks like for your specific environment, start here with NexSecure Solutions. Our cybersecurity services for SMBs include cyber insurance readiness assessments that confirm where you stand and what needs to change.

Categories: