The Cyber Insurance Readiness Checklist

The 10 questions your cyber insurer, your biggest clients, and your auditors are asking in 2026. Can you answer them with evidence — not "we think so"?

Why this checklist exists

Coalition's 2026 Cyber Claims Report calls 2026 the "Year of Technical Validation." Insurers no longer ask "do you have these controls?" — they ask "can you prove they were enforced at the time of the incident?" Chubb, Beazley, and Travelers 2026 policies now include Condition Precedent clauses that void coverage if the forensics don't add up.

Your enterprise clients are asking the same questions through vendor-risk questionnaires. This is the checklist that lets you walk into any of those conversations ready.

What's inside

  1. Multi-Factor Authentication — on every account that touches data, enforced by policy, with phishing-resistant methods preferred
  2. Endpoint Detection & Response — managed EDR/XDR, not basic antivirus, with 24/7 monitoring
  3. Email authentication — SPF, DKIM, and DMARC (at least p=quarantine) — post Microsoft's May 2025 enforcement
  4. DNS filtering — office and remote, with category policies and log retention
  5. Automated, immutable backups — with a restore test logged in the last 12 months
  6. Team password manager — with sharing governance and offboarding workflow
  7. Acceptable Use Policy — signed by every employee, including AI and device clauses
  8. Security awareness training — annual minimum, with simulated phishing and retained records
  9. Privileged access management — no shared admin accounts, just-in-time elevation for cloud roles
  10. Incident response plan — written AND tested in the last 12 months, with insurer hotline as step one

Each item explains what the insurer or client will ask, what "good" looks like, and — most importantly — how to prove it at time of incident. Plus a 15-minute self-scoring exercise at the end.

Download the checklist

Instant download. We keep your name and email so we know who we're helping — we don't spam or share your details.

Direct download — no waiting. Opting into the newsletter is optional and separate from the download.

Who should use this

If any of these are coming up in the next 12 months, this checklist is for you:

  • Cyber insurance renewal or first-time application
  • Vendor-risk questionnaire from a new enterprise or public-sector client
  • Board-level request for a cybersecurity posture summary
  • Post-incident review after a phishing or account-takeover scare
  • Switching MSPs and wanting to understand what you're actually buying

What makes it different

Most "cyber checklists" online were written in 2019 and cite Verizon stats from 2020. This one is built from real 2026 Canadian renewal questionnaires and references the Canadian Centre for Cyber Security baseline — so when your broker asks, you answer with the same language the underwriter is reading.

Want a second pair of eyes before renewal?

DVG Systems runs a free 45-minute Cyber Insurance Readiness Review for Northern Ontario businesses. We walk the 10 questions with you, flag the evidence gaps, and hand you a one-page summary you can share with your broker.

Ask AI

Accessibility