How This Works

Nine questions, one per control: the big four — multi-factor authentication (MFA), endpoint detection and response (EDR), tested backups, and a written incident response plan — then the second ring of patching, training, offboarding, and email authentication, and the payment-verification rule. Each question is what the form asks, in some wording; under it sits the proof question, because one tie-breaker settles every argument before it starts: if you cannot say where the proof would come from, it is not green.

Mark the firm that exists, not the firm you wish you ran. This is a private snapshot, read on your own machine — flattering it defeats the point, which is finding out where you stand while finding out is still free. About five minutes.

Part 1 — The Big Four

The proof question: could you show a dated enforcement export and a coverage list today — shared mailboxes and administrator accounts included, with the old password-only sign-in closed?

The proof question: is there a coverage export reconciled against a written device list — and a monitoring arrangement in writing that names who acts on alerts?

The proof question: is there a dated restore-test note on file — what was restored, when, how long it took, verified by whom — and one copy out of reach of a stolen password?

The proof question: could a rattled person follow the page alone — first calls in order with numbers written out, a named decider, the don'ts, the evidence pack's location — with a walkthrough note from the past year?

Part 2 — The Second Ring

The proof question: does a monthly are-they-actually-applying check get filed — and is any unsupported machine off the network, with a retirement date in writing?

The proof question: is there a dated record of who attended, what was covered, and who led it?

The proof question: same day, from a written checklist covering email, remote access, the business applications, and the password vault — with the last departure's completed checklist on file (or the blank checklist and a named owner)?

The proof question: can you say what DMARC is set to, that every service sending mail as you is covered — with a dated checker report or provider confirmation filed?

Part 3 — The Payment Rule

The proof question: is the callback written up as a dated one-page procedure, taught at the annual training hour, with a log line each time the call happens?

Answer all nine questions to see your snapshot.

Your Renewal Readiness Snapshot

That’s where you stand today. The next step is being able to prove it — the evidence pack shows what to keep, control by control.

A first tally of two greens, a handful of ambers, and a few reds is ordinary for a firm that has been “fine” for years — an accurate map, not a failing grade. Count your ambers: often the control was real, and only the artefact was missing.

This check describes readiness, not coverage. Your policy wording controls — confirm coverage questions with your broker or carrier.

What to ask your IT provider

That’s the question for your first gap — one control of nine. The paid editions carry the full set: what counts as done for every control, the proof worth keeping for each, and the questions for your provider and your broker.

Ready to Be Able to Prove It?

The free check shows where you stand. The paid editions add the working documents — what counts as done for each of the nine controls, the proof worth keeping for each, the questions for your IT provider and your broker, and the renewal calendar that keeps the whole thing current — so you have the artefacts, not just the colours.

See the Editions + Toolkit →