Cyber Insurance Readiness Checklist for Small Businesses

Use this checklist to prepare your small business for cyber insurance applications, renewals and security reviews. Built for Las Vegas businesses.

IT Resource

Cyber Insurance Readiness Checklist for Small Businesses

Cyber insurance applications have become more detailed. Many carriers now ask direct questions about MFA, backups, endpoint protection, email security, vendor access, incident response and user training.

This checklist helps small businesses prepare for renewal conversations, identify gaps before an application is submitted and understand which controls may need attention.

Who This Is For

Use This Before Renewal, Application or Security Review

This resource is built for owners, operations leaders, office managers and internal IT teams who need a practical way to prepare for cyber insurance questions without getting buried in technical language.

01

Who This Is For

Owners, operations leaders, office managers and internal IT teams preparing for renewal, a new application or a security review.

02

What You Will Learn

Which common controls to review, including MFA, backups, endpoint protection, email security, access cleanup and documentation.

03

How to Use It

Use the checklist before renewal so missing controls are not discovered at the last minute.

Checklist 1

Identity and Access Controls

01

Multi-Factor Authentication

  • MFA is enabled for Microsoft 365 and remote access.
  • Administrators use MFA on every privileged account.
  • Shared accounts are removed or tightly controlled.
  • Legacy authentication is disabled where possible.
02

User Access Review

  • Former employees and vendors are removed promptly.
  • Admin permissions are limited to people who need them.
  • Shared mailboxes, distribution lists and file permissions are reviewed.
  • New user and offboarding steps are documented.

Checklist 2

Backup and Recovery Readiness

Insurance carriers often want to know whether the business can recover from ransomware, accidental deletion or system failure.

03

Backup Coverage

  • Critical servers, cloud data and business applications are included.
  • Microsoft 365 data protection is reviewed instead of assumed.
  • Backup alerts are monitored by someone responsible.
  • Retention expectations are documented.
04

Recovery Testing

  • Restore tests are performed on a schedule.
  • Recovery time expectations are understood by leadership.
  • Backup credentials are protected.
  • Offline, immutable or separated backup options are considered where appropriate.

Checklist 3

Endpoint, Email and User Protection

Endpoint Protection

Business computers and laptops have managed endpoint protection, alerting and a response owner.

Email Security

Email filtering, phishing protection and suspicious link controls are reviewed for Microsoft 365.

Security Awareness

Employees receive practical training on phishing, password safety, fake invoices and suspicious requests.

Patch Management

Operating systems, browsers, business applications and security tools are updated consistently.

Remote Access

Remote tools use MFA, logging and limited permissions. Old access paths are removed.

Vendor Access

Third-party access is reviewed, documented and removed when no longer needed.

Checklist 4

Documentation and Response Planning

The best answer to an insurance question is evidence. If the control exists but nobody can prove it, the business may still struggle during underwriting or after an incident.

Minimum Documentation to Gather

  • Inventory of key systems, users, vendors and security tools.
  • Backup and recovery process notes.
  • Incident response contact list and escalation path.
  • Cybersecurity policy or acceptable use guidance.
  • Evidence of MFA, endpoint protection, email security and training.

Cyber Insurance Readiness FAQs

Does this checklist guarantee cyber insurance approval?

No. Insurance approval and pricing depend on the carrier, the application, claims history, business risk and underwriting requirements. This checklist helps identify common readiness gaps before the application process.

Should small businesses enable MFA everywhere?

MFA should be enabled for Microsoft 365, remote access, administrative accounts and other critical systems where supported. It is one of the most common controls requested by insurers.

Do backups matter for cyber insurance?

Yes. Carriers often ask whether backups exist, whether they are monitored, whether they are separated from production systems and whether restore testing has been performed.

Can Nevada IT Support help with the technical review?

Yes. Nevada IT Support can review practical security gaps, Microsoft 365 settings, backups, documentation and the technology planning needed to support cyber insurance readiness.

Next Step

Need help preparing for cyber insurance questions?

Nevada IT Support can help review your Microsoft 365, backups, endpoint protection, email security and cybersecurity documentation before gaps become renewal problems.