FTC Safeguard Assessment
  • FTC Safeguard Assessment

    This assessment will take approximately 20 minutes to complete. You may save and continue later. Please complete the fields below and provide as many details as possible. Upon completion of the assessment, you'll receive a detailed analysis of your organization's compliance status related to FTC Safeguard Rules.
  • PRIVACY

    This form uses a 256-bit SSL connection and is PCI, GDPR and CCPA compliant. All submissions are encrypted with RSA 2048 and automatically deleted. A licensed insurance agency will prepare your insurance quote. All quotes are subject to state availability and suitability.
  • How would you like to complete your assessment?
  • Organization Information

    Please tell us a little about your organization. The better we understand your organization the more customization we can provide you in order to maximize security while reducing expenses.
  • Organization Background

    In order to determine the proper cyber security controls and the potential cost of a breach it is important for us to know to a little more about your organization.
  • Organization's Approximate Annual Revenue
  • Organization IT Environment

    The following questions are required to understand the current IT Environment of your organization. Please answer each question and provide additional information as needed.
  • Organization Staff + Asset / Device Management

    The following questions are required to understand the risk management in place for both your staff and digital assets + devices in use by your organization. Please answer each question and provide additional information as needed.
  • Are your employees subject to ongoing Identity Screening + Monitoring?
  • Do you have a written Employee Policy in place for employees to notify your organization of Identity Breaches?
  • Browse Files
    Drag and drop files here
    Choose a file
    Cancelof
  • Please tell us if any of the following Corporate Devices are issued to employees?
  • Are your employees permitted to use their own Personal Devices?
  • Is your organization using any Web / Cloud Services?
  • Are you using any Cloud Security Posture Management tools that covers all cloud risks: spanning misconfigurations, vulnerabilities, identity risks, data security, API / PII / crown jewel asset exposure, and advanced threats?
  • Cyber Security Questionnaire

    The following questions are required to diagnosis the current cyber security environment of your organization. Please answer each question and provide additional information as needed.
  • Do you have Single Sign On (SSO) enabled and configured for all 3rd party applications?*
  • Do you have At-Rest Encryption enabled for all endpoints and devices?*
  • Do you currently have Segregation of Duties + Business Controls in place for all outgoing payments / funds transfers?*
  • Do you have a formal Patch Management Program in place which is informed by critical security and vulnerability data within 30 days?*
  • Do you have Endpoint Detection & Response (EDR)?*
  • Do you have Managed Detection & Response (MDR) in place for all sources of active detection?*
  • Do you have a Vulnerability Assessment and Management solution to discover and assess assets in your environment, including dynamic cloud or remote workforce assets?
  • Do you have Advanced Email Protection for O365/G-Suite as well as your cloud-based collaboration platforms including: pre and post delivery protection, URL and attachment sandboxing, anti-malware scanning, data loss prevention, and encryption?*
  • Do you have Multi-factor Authentication (MFA) implemented for all users?*
  • Do you have Multi-factor Authentication (MFA) implemented for all remote access and 3rd party applications?*
  • Do you have Zero Trust Segmentation implemented for all endpoints?*
  • Do you have an Immutable Backup Strategy (REQUIRES: 3+ backup sources covering all systems / data and 1+ offline / inaccessible from the network where the systems/data reside)?*
  • Do you have a Log Resilience/Centralization Platform (such as a SIEM)?*
  • Technologies + Development

    The following questions are related to specific technology needs and development. Please answer each question and provide additional information as needed.
  • Do you have Operational Technologies?
  • Do you develop Applications or Custom Code for yourself or customers?
  • Do you develop Web Applications or APIs, or utilize APIs for any of your own Web Applications?
  • Do you host your own Custom Email or any similar Custom Applications?
  • Cyber Security Program

    The following questions are required in order to better understand your written policies + procedures and response plans. Please answer each question and provide additional information as needed.
  • Do you have a Written Cyber Security Program in place which aligns with regulatory requirements and/or industry standards (NIST, CIS, etc)?*
  • Browse Files
    Drag and drop files here
    Choose a file
    Cancelof
  • Do you have an Incident Response Plan in place currently?
  • Is your Incident Response Plan approved by your insurance carrier?
  • Cyber Liability Insurance

    The following questions are required to establish and understanding of your current cyber insurance in force (or desired coverage). Please provide as many details as known related to the coverage.
  • Does your organization currently have Cyber Liability Insurance?
  • When is the Renewal Date for this policy?
     - -
  • Is Cyber Liability Insurance desired?
  • When would you like coverage to begin?
     - -
  • Date Submitted*
     - -
  • Should be Empty: