See where you stand on the questions carriers actually ask — and what to do about each one. Nine plain-English questions, one per control — the big four, the second ring, and the payment rule — each read green, amber, or red the way the form will read them. About five minutes. No email required.
Plain-English readiness — without us ever seeing your answers. It runs in your browser; nothing you type leaves your machine.
The nine controls nearly every form asks about. The check walks the same ground the renewal form does: the big four — multi-factor authentication (MFA), endpoint detection and response (EDR), tested backups, and a written incident response plan — then the second ring of patching, security-awareness training, offboarding, and email authentication, and the payment-verification rule that guards how money moves.
What you get. A colour for each of the nine, with one honest tie-breaker doing the reading: if you cannot say where the proof would come from, it is not green. Amber is the honest middle where most firms start, and a red is just an amber with more homework. You also get the first question to put to your IT provider, drawn from your first gap. The rubric mirrors Appendix F of the companion book, Cyber Insurance in Plain English.
What it isn't. This is general guidance. It is not insurance, legal, or brokerage advice; it is not an application, a quote, or a policy; and it makes no promise about coverage, claims, or premiums. It describes readiness, not coverage — your policy wording controls; confirm coverage questions with your broker or carrier. Responsibility for your organisation's security and insurance decisions remains with you.
Everything behind this free check — what counts as done for each control, the proof worth keeping, the questions for your IT provider and your broker, and the renewal calendar that keeps it current. Three editions — Solo, Team, and Pro Advisor — to fit how you work.
See the full toolkit →One-time purchase · files you own forever · 30-day money-back guarantee.