CelereTech

Free Assessment

Cyber Insurance Risk Assessment

Cyber insurance underwriting has gotten stricter, and carriers increasingly verify controls instead of just trusting an application. Rate your business across 18 statements covering identity and access, backups, incident response, and vendor risk, and get an instant score plus a recommendation on next steps from CelereTech.

How to Rate Your Business

Rate each statement based on where your business stands today:

  • 2 — In Place: This is established and consistently followed.
  • 1 — In Progress: Some groundwork is complete, but gaps remain.
  • 0 — Not Yet: This has not been addressed.
  • N/A — Not Applicable: This does not apply to your business.

Items marked are the controls carriers most commonly cite when denying coverage, declining renewal, or contesting a claim. A strong total score should not override an unresolved critical item.

1. Identity, Access & Endpoints

Multi-factor authentication (MFA) is enforced on every business email account.

MFA is enforced for VPN and all remote access to company systems.

MFA is enforced on privileged and administrator accounts.

Endpoint detection and response (EDR) or managed detection and response (MDR) is deployed on every workstation and server — not signature-based antivirus alone.

Administrator access follows least privilege, with no shared or generic admin logins.

A firewall is in place and actively monitored, not just installed and forgotten.

2. Backup, Patching & Email

Backups include an immutable or offline copy that ransomware cannot reach or encrypt.

Backup restores are tested on a regular, defined schedule, not just assumed to work.

A documented patch management process applies security updates on a regular cadence.

Email authentication (SPF, DKIM, and DMARC) is configured to reduce phishing and business email compromise.

3. Incident Response & Evidence

A written incident response plan exists, with defined roles and outside contacts.

That plan has been tested with a tabletop exercise in the past 12 months.

Employees receive regular security awareness training, including phishing simulations.

Security logs and events are retained and monitored, providing evidence that controls are actually working.

4. Vendor Risk & Application Accuracy

Vendors and contractors with access to your systems or data are reviewed for security risk.

Coverage limits have been checked against realistic exposure — ransomware, business email compromise, and business interruption, not just a policy minimum.

Someone in your business could accurately answer a carrier's application or renewal questionnaire today.

Any prior security incidents or claims would be disclosed accurately if a carrier asked.

Get Your Results