• LCP2–Cyber Insurance – Renewal and Ransomware - Application Form

  • Rows
  • Cyber and Privacy Questions

  • 1. Are all servers, firewalls, etc. located in a purpose-built server room with access restricted to appropriate personnel?
  • 2. Do you have an email and internet usage policy that has been shared with all employees?
  • 3. Do you have firewall architecture in place?
  • 4. Do all systems users have individual, mandatory and non-trivial user IDs and passwords with forced periodic password changes?
  • 5. Are all PCs and servers protected with up-to-date anti-virus that is updated regularly?
  • Data Recovery & Business Interruption Questions

  • 1. Do you have a disaster recovery plan that is tested at least annually
  • 2. What is the time taken in hours to fully restore critical systems?
  • 3. What is the time taken in hours to fully restore non-critical systems?
  • 4. Do you have a business continuity plan that is tested at least annually?
  • Data Volume Questions

  • Whether it is encrypted:
  • Whether it is encrypted:
  • Whether it is encrypted:
  • Whether it is encrypted:
  • Whether it is encrypted:
  • Email Protection Questions

  • 1. Do you pre-screen e-mails for potentially malicious attachments and links?
  • 2. Do you provide a quarantine service to your users?
  • 3. Do you have sandbox capabilities to automatically evaluate attachments?
  • 4. Do you strictly enforce Sender Policy Framework (SPF) on incoming e-mails?
  • 6. Can users access email through a web-app on a non-corporate device?
  • 6a. If Yes to 6 above, do you enforce Multi-Factor Authentication (MFA)?
  • 7. Do you use Office 365 in your organization?
  • 7a.  If Yes to 7 above, do you use Office 365 Advanced Threat Protection?
  • DataBackup & Recovery Questions

  • 1. Are your backups encrypted?
  • 2. Do you use a cloud syncing service for backups, e.g. Dropbox, OneDrive, SharePoint, Google, etc.)?
  • 3. Within the last six months have you undertaken restoration and recovery testing of key server configurations and data?
  • 4. Do you test the integrity of backups prior to restoration to ensure the backups are free from malware?
  • Internal System Security Questions

  • 1. Do you use endpoint protection (EPP) across your networks?
  • 2. Do you use endpoint detection and response across your networks?
  • 3. Do you use MFA to protect privileged user accounts?
  • 4. Have you implemented a hardened baseline configuration across servers, laptops, desktops and managed mobile devices?
  • 7. Do you segregate end-of-life or out-of-support hardware and systems?
  • 8. Do any of your users have local admin rights?
  • 9. Do you provide your users with a password manager software?
  • 10. Have you established a Security Operations Centre (SOC)?
  • Date
     - -
  • Should be Empty: