Skip to main content

Pro audit program · v1.0

Cyber Insurance Readiness

Most cyber-insurance applications now ask the same 30 questions. Pre-empt them and avoid claim disputes.

  • General target area
  • NIST CSF framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Most cyber-insurance applications now ask the same 30 questions. Pre-empt them and avoid claim disputes.

Risks addressed

  • Critical Claim denied because a control attested-to was missing
  • Medium Premium spikes because of weak controls reported
  • High No incident playbook for insurer notification

Controls (7)

  1. MFA on email, VPN, admin, RDP

    Critical

    Multi-factor authentication (MFA) requires users to present at least two independent authentication factors before accessing email systems, VPN connections, administrative interfaces, and Remote Desktop Protocol (RDP) sessions. This control enforces possession-based or biometric factors in addition to passwords, significantly raising…

    How to test + evidence

    Testing procedure: Insurer Q: is MFA on every entry path? Yes / partial / no.

    Evidence to collect: MFA coverage evidence.

  2. EDR on all endpoints + servers

    Critical

    Endpoint Detection and Response (EDR) software is deployed on all workstations, laptops, and servers to provide continuous monitoring, threat detection, and automated response capabilities. EDR agents collect telemetry including process execution, network connections, file modifications, and registry changes, then correlate…

    How to test + evidence

    Testing procedure: EDR roster matches asset inventory.

    Evidence to collect: EDR coverage.

  3. Offline / immutable backups + quarterly restore test

    Critical

    This control requires organizations to maintain backup copies that are either physically disconnected from production networks (offline) or stored in write-once-read-many (WORM) formats that prevent modification or deletion (immutable). These backups are protected from ransomware, insider threats, and automated deletion…

    How to test + evidence

    Testing procedure: Backup immutability + most recent restore test.

    Evidence to collect: Backup config + restore test.

  4. Patching SLAs documented + met

    High

    This control requires that the organization define and document Service Level Agreements (SLAs) for applying security patches across all system types (e.g., critical systems within 48 hours, high-risk within 7 days, standard within 30 days). These SLAs establish maximum time…

    How to test + evidence

    Testing procedure: Critical patched <=7 days, high <=14 days, with evidence.

    Evidence to collect: Patch compliance dashboard.

  5. Email security: SPF + DKIM + DMARC + ATP

    High

    This control implements a layered email authentication and threat protection framework combining Sender Policy Framework (SPF) to authorize sending mail servers, DomainKeys Identified Mail (DKIM) to cryptographically sign messages, Domain-based Message Authentication Reporting and Conformance (DMARC) to enforce policy and…

    How to test + evidence

    Testing procedure: Email gateway + DMARC at p=quarantine or stricter.

    Evidence to collect: DNS + gateway config.

  6. IR plan + tabletop within last 12 months

    High

    This control requires an organization to maintain a documented incident response (IR) plan and conduct at least one tabletop exercise within the preceding 12 months. The IR plan defines roles, responsibilities, communication protocols, escalation paths, and technical procedures for detecting,…

    How to test + evidence

    Testing procedure: Insurer Q: when did you last test? Show after-action report.

    Evidence to collect: IR plan + tabletop AAR.

  7. Insurer notification timeline in IR plan

    High

    This control requires the incident response plan to explicitly define the timeline and conditions under which the organization's cyber insurance carrier must be notified following a security incident. The timeline should specify maximum notification windows (e.g., within 24 or 72…

    How to test + evidence

    Testing procedure: Plan documents who calls insurer and when (typically within 72h).

    Evidence to collect: IR plan extract.