Please read and accept the terms of use to continue.
What this is
This is a free self-assessment tool. It reads how ready your organisation is on nine security controls that cyber insurance applications and renewals commonly ask about — each marked green, amber, or red — and offers recommended practices drawn from widely recognised security guidance. It is general guidance.
What this isn't
It is not insurance, legal, or brokerage advice. It is not an insurance application, a quote, or a policy; it is not underwriting; and it makes no promise about coverage, claims, premiums, or any carrier's decision. An honest readiness check helps you prepare for renewal questions, but your policy wording controls — confirm coverage questions with your broker or carrier. Sylvan Assurance is not an insurer, an insurance broker, or a law firm.
Your responsibility
Responsibility for your organisation's security and insurance decisions remains with you.
Verify any recommendation against your own circumstances and your own policy's wording.
Engage a licensed broker or carrier — or another qualified professional — where needed.
Nine questions — the controls that appear, in some wording, on nearly every carrier's form — each read green, amber, or red in your browser. Free, and nothing you type leaves your machine.
How This Works
Nine questions, one per control: the big four — multi-factor authentication (MFA), endpoint detection and response (EDR), tested backups, and a written incident response plan — then the second ring of patching, training, offboarding, and email authentication, and the payment-verification rule. Each question is what the form asks, in some wording; under it sits the proof question, because one tie-breaker settles every argument before it starts: if you cannot say where the proof would come from, it is not green.
Green — enforced or tested, and you could prove it today: a dated export, log, page, or written answer a stranger could verify.
Amber — probably true, but no proof in hand.
Red — not in place, or unknown. No idea is red — and a red is just an amber with more homework.
Mark the firm that exists, not the firm you wish you ran. This is a private snapshot, read on your own machine — flattering it defeats the point, which is finding out where you stand while finding out is still free. About five minutes.
Part 1 — The Big Four
The proof question: could you show a dated enforcement export and a coverage list today — shared mailboxes and administrator accounts included, with the old password-only sign-in closed?
The proof question: is there a coverage export reconciled against a written device list — and a monitoring arrangement in writing that names who acts on alerts?
The proof question: is there a dated restore-test note on file — what was restored, when, how long it took, verified by whom — and one copy out of reach of a stolen password?
The proof question: could a rattled person follow the page alone — first calls in order with numbers written out, a named decider, the don'ts, the evidence pack's location — with a walkthrough note from the past year?
Part 2 — The Second Ring
The proof question: does a monthly are-they-actually-applying check get filed — and is any unsupported machine off the network, with a retirement date in writing?
The proof question: is there a dated record of who attended, what was covered, and who led it?
The proof question: same day, from a written checklist covering email, remote access, the business applications, and the password vault — with the last departure's completed checklist on file (or the blank checklist and a named owner)?
The proof question: can you say what DMARC is set to, that every service sending mail as you is covered — with a dated checker report or provider confirmation filed?
Part 3 — The Payment Rule
The proof question: is the callback written up as a dated one-page procedure, taught at the annual training hour, with a log line each time the call happens?
Free snapshot · read entirely in the browser — answers never leave the device
Your Renewal Readiness Snapshot
—
—
That’s where you stand today. The next step is being able to prove it — the evidence pack shows what to keep, control by control.
A first tally of two greens, a handful of ambers, and a few reds is ordinary for a firm that has been “fine” for years — an accurate map, not a failing grade. Count your ambers: often the control was real, and only the artefact was missing.
This check describes readiness, not coverage. Your policy wording controls — confirm coverage questions with your broker or carrier.
What to ask your IT provider
That’s the question for your first gap — one control of nine. The paid editions carry the full set: what counts as done for every control, the proof worth keeping for each, and the questions for your provider and your broker.
Free guide
Your First Renewal Moves
A short, plain-English guide to the ninety days before your cyber insurance renewal — what the form will ask, the order to take the big four in, and the proof worth filing as you go. Enter your email and we'll send it over.
Optional, and separate from your check — your answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
Ready to Be Able to Prove It?
The free check shows where you stand. The paid editions add the working documents — what counts as done for each of the nine controls, the proof worth keeping for each, the questions for your IT provider and your broker, and the renewal calendar that keeps the whole thing current — so you have the artefacts, not just the colours.