Free Cyber Insurance Tool
Would you pass your cyber insurance application today?
Fourteen yes-or-no questions, the same ones a cyber liability application asks, in about three minutes. You get a readiness score, the controls you would have to answer no to, and what each no does to your premium, coverage, or eligibility. The full result appears on this page. No email address is required to see it.
Interactive Check
Answer the way your broker will ask. See what the underwriter sees.
The security section of a cyber liability application used to be a page of checkboxes. It is now a technical review: carriers ask about the same fourteen controls, treat five of them as conditions of coverage, and expect evidence behind every yes. This check asks those questions in carrier language, translates each one, and scores your answers the way an underwriter weighs them.
Cyber Insurance Readiness Check
- Fourteen questions, each phrased the way a carrier phrases it and then in plain language. Answer Yes, No, or Not sure.
- Not sure scores as No, because that is how an underwriter reads it, and is flagged separately in your result.
- Your answers stay in this browser. Nothing is stored unless you ask for the report.
Gate questions
All fourteen controls, heaviest first
Each row shows how most carriers treat a no on that control. Points show how much of your score it carries.
| Control | Your answer | Points | What a no does to your application |
|---|
What your broker will ask for
Every yes on an application needs a document behind it. Underwriters and claims adjusters ask for these after you sign, and a yes you cannot document is treated as a no. ETTE produces this evidence for clients as part of Virtual CISO and reports it quarterly through GuardRail.
Email me this report for my broker or board
Save the PDF now with the button below. Leave your details and an ETTE advisor will send a formatted copy of this report and answer questions about the gaps before your renewal.
How the Score Works
Fourteen controls, five of them conditions of coverage.
Each question carries the weight an underwriter gives it, and the weights add up to 100. The five gate questions are the controls most carriers treat as conditions of coverage: a no on any one of them triggers the eligibility warning no matter how high the rest of your score is. Two or more gate failures put you in Not ready.
- MFA everywhereEmail, remote access, and admin accounts. 12 points.
- Monitored EDROn every device and server. 10 points.
- Tested immutable backupsEncrypted, offline or immutable, restored in the last year. 10 points.
- Patching and supported systemsCritical patches inside 30 days, no unsupported OS. 8 points.
- No open remote desktopVPN or zero-trust only. 6 points.
You should qualify for standard coverage. Bring the report to your broker.
You will likely qualify, at a higher premium. Two or three fixes change that.
Expect a decline, a sublimit, or an exclusion on the missing control.
Most carriers will not write the policy as-is. The gap list is your plan.
Common Questions
Cyber insurance requirements, explained for the people who sign the application.
What do cyber insurance carriers require before they will write a policy?
Most applications open with the same five conditions of coverage: MFA on email, remote access, and admin accounts, and endpoint detection and response on every device. They also ask for backups that are encrypted, offline or immutable, and tested, patching within 30 days with no unsupported operating systems, and no Remote Desktop open to the internet. Behind those come email filtering, DMARC, staff training with phishing simulation, a written incident response plan, limited admin rights, payment verification by callback, and a vendor access inventory. Carriers treat the first group as conditions of coverage and price the second group into the premium. The fourteen questions above are that list.
Why did our premium go up when we have never filed a claim?
Because pricing follows your controls, not your history. Market-wide cyber rates have eased since their 2022 peak, yet many organizations still see increases at renewal. The reason is usually an application answer: a no on MFA, a backup that was never restore-tested, or an operating system past its support date. Carriers also add sublimits, which cap what they will pay for ransomware or social engineering, and those caps often arrive quietly in the renewal terms. Fixing the controls in the gate questions is the most reliable way to bring the number back down, and the report above shows which ones apply to you.
What happens if we answer a question on the application inaccurately?
The application becomes part of the policy, so an inaccurate yes is a material misrepresentation. After an incident, the carrier's forensic team checks whether the control was in place on the day of the loss. If MFA was not enforced everywhere, or the backup had never been restored, the carrier can deny that claim or rescind the policy entirely, and the organization pays the full cost of the incident. That is why the evidence list on your report matters as much as the answers: a yes you can document is the only yes that counts. When you are not sure, answer no and fix it before renewal.
How does a managed IT provider help with a cyber insurance application?
A managed provider owns most of the controls on the application, so the questions become reporting rather than projects. ETTE enforces MFA and Conditional Access, runs monitored EDR, manages immutable backups with documented restore tests, and keeps patching on a 30-day cadence for every managed client. Virtual CISO adds the written pieces carriers ask for, the incident response plan, tabletop exercise, payment verification procedure, and vendor inventory, and GuardRail reports all of it quarterly in language a board can read. When the application arrives, the answers and the evidence are already on file. Published pricing shows what that costs per user.
Next Step
Every no on this list is a control ETTE puts in place.
The gate questions take about 30 days to clear for a typical nonprofit or association. The rest follows within a quarter, and Virtual CISO keeps the evidence current, so next year's application is a printout rather than a project. Bring your readiness report to a conversation with an advisor and leave with a sequence, a timeline, and a clear read on what your team can do itself.