• Cyber Security Risk Assessment

    This assessment will take approximately 20-30 minutes to complete. You may save and continue later. Please complete the fields below and provide as many details as possible. After completion of the assessment you'll receive an assessment of your organization's accepted vs. addressed risk, the estimated cost of a serious incident or breach, and a detailed analysis of your security gaps.
  • This form uses a 256-bit SSL connection and is PCI, GDPR and CCPA compliant. All submissions are encrypted with RSA 2048 and automatically deleted. A licensed insurance agency will prepare your insurance quote. All quotes are subject to state availability and suitability.
  • How would you like to complete your assessment?
  • Organization Information

    Please tell us a little about your organization. The better we understand your organization the more customization we can provide you in order to maximize security while reducing expenses.
  • Organization Background

    In order to determine the proper cyber security controls and the potential cost of a breach it is important for us to know a little more about your organization.
  • Organization's Approximate Annual Revenue
  • Governance and Oversight

    The following questions are required to establish an understanding of your current cyber insurance governance and legal status. Please provide as many details as known related to the coverage.
  • Does your organization have a documented cybersecurity mission statement aligned to business objectives?
  • Have you formally identified internal and external cybersecurity stakeholders and their expectations?
  • Have you documented the legal, regulatory, and contractual cybersecurity requirements that apply to your organization (including privacy and civil liberties)?
  • Have you identified critical objectives, capabilities, and services that external stakeholders depend on?
  • Have you documented outcomes, capabilities, and services the organization itself depends on (critical dependencies)?
  • Are risk management objectives established and formally agreed upon by organizational stakeholders?
  • Has your organization established and communicated a written risk appetite / risk tolerance statement?
  • Is cybersecurity risk integrated into your enterprise risk management program (ERM)?
  • Have you defined and communicated risk response strategies (accept, transfer, mitigate, avoid)?
  • Are there established lines of communication across the organization for cybersecurity risks?
  • Do you use a standardized method for calculating, documenting, and prioritizing cybersecurity risks?
  • Are strategic opportunities (positive risks) characterized and included in cybersecurity risk discussions?
  • Is organizational leadership formally accountable for cybersecurity risk and fostering a risk-aware culture?
  • Are cybersecurity roles, responsibilities, and authorities formally established and communicated?
  • Are adequate resources (budget, headcount, tools) allocated commensurate with the cybersecurity risk strategy?
  • Is your cybersecurity policy reviewed, updated, and enforced on a defined schedule (at least annually)?
  • Are cybersecurity risk management strategy outcomes regularly reviewed to inform strategy adjustments?
  • Is the cybersecurity risk management strategy reviewed and adjusted based on changes in environment, mission, or risk?
  • Is organizational cybersecurity performance evaluated and reviewed for adjustments?
  • Do you formally understand, document, and communicate the cybersecurity risks posed by each critical supplier/service provider (e.g., via a risk register keyed to supplier tier)?
  • Do you handle FCI or CUI / have DoD contracts?
  • CMMC: Program

  • Have you identified and documented the CUI scope (systems, networks, physical locations that process/store/transmit CUI) for your CMMC assessment?
  • Do you flow CMMC/DFARS 252.204-7012 / NIST SP 800-171 requirements down to subcontractors who will handle CUI?
  • CMMC: Physical Protection

  • Is physical access to facilities containing FCI/CUI restricted to authorized personnel (e.g., badge access, locked server rooms, role-based clearance)?
  • Are visitors to sensitive areas escorted at all times and required to sign in/out of an access log?
  • Is the physical facility monitored for security (e.g., CCTV, alarm systems, guards) and are security logs reviewed?
  • Are physical access logs (badge events, visitor logs, server-room sign-ins) maintained and retained for audit review?
  • Do you maintain an inventory of physical access devices (keys, badges, combinations) with a process for issuance, revocation, and periodic review?
  • Do you enforce safeguarding requirements (encryption, VPN, approved devices) for work performed at alternative work sites (home offices, co-working, travel)?
  • CMMC: Access Control

  • Do systems enforce a limit on consecutive unsuccessful logon attempts (account lockout after N failures) per documented policy?
  • Do systems display an approved privacy and security notice (warning banner) before granting access, consistent with applicable federal or contractual requirements?
  • Do user sessions lock automatically after a defined period of inactivity, requiring re-authentication to resume?
  • Are user sessions automatically terminated (not just locked) after a defined condition (e.g., timeout, end-of-shift)?
  • Are all remote access sessions to systems containing CUI protected using cryptographic mechanisms (e.g., FIPS-validated VPN, TLS 1.2+)?
  • Do you formally limit, track, and disable use of portable storage devices (USB drives, external HDD/SSD) on organizational systems?
  • CMMC: Audit and Accountability

  • Do you synchronize system clocks to an authoritative time source (e.g., NTP tier-1 or DoD time source) to support reliable audit timestamps?
  • Are audit logs and audit tools protected from unauthorized access, modification, or deletion (e.g., WORM storage, SIEM integrity, access controls)?
  • CMMC: Configuration Management

  • Do you restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services on systems?
  • CMMC: Identification & Authentication

  • Do you prevent reuse of identifiers (usernames, account IDs) for a defined period after account disablement?
  • Are user identifiers disabled (not deleted) after a defined period of inactivity?
  • Do systems obscure authentication feedback (mask passwords during entry, hide MFA codes in screen shares) to protect against observation?
  • CMMC: Maintenance

  • Do you perform scheduled and approved maintenance on organizational systems, and retain maintenance records?
  • Are diagnostic and test programs (e.g., maintenance tools, USB devices used by technicians) inspected for malicious code before connecting to systems containing CUI?
  • Are maintenance personnel supervised when they lack required access authorization (e.g., third-party technicians on-site)?
  • CMMC: Media Protection

  • Do you maintain accountability (chain of custody) for media containing CUI during transport outside of controlled areas?
  • Do you control the use of removable media on systems that store or process CUI (e.g., whitelist, encrypted-only, auto-scan)?
  • Do you prohibit the use of portable storage devices that have no identifiable owner (no tracking/assignment to an individual)?
  • CMMC: System Communications

  • Do network communications terminate after a defined period of inactivity or at the end of a session (e.g., TCP timeout, VPN tunnel teardown)?
  • Is VoIP use controlled and monitored (e.g., documented policy, authorized devices, encryption of signaling/media)?
  • CMMC: Assessment & Authorization

  • Do you maintain a Plan of Action and Milestones (POA&M) documenting identified security deficiencies, planned remediation, owners, and due dates?
  • Do you perform continuous monitoring of security controls (not only point-in-time) to confirm ongoing effectiveness?
  • Do you maintain a System Security Plan (SSP) describing system boundaries, control implementation, and relationships to other systems?
  • CMMC: Advanced Risk

  • Do you perform threat-informed risk assessments at least annually, incorporating current threat intelligence (e.g., DIB CS, ISAC, CISA)?
  • Do you employ advanced automation, analytics, or dedicated staff to identify risks not discovered by standard vulnerability scanning (e.g., attack-path analysis, adversary emulation)?
  • Do you formally document, review, and approve the rationale, assumptions, and constraints behind each selected security solution?
  • Do you regularly evaluate the effectiveness of security solutions (e.g., red-team/BAS results, control testing, KPI review) and adjust accordingly?
  • Do you conduct penetration testing annually that specifically exercises CUI-handling boundaries (not just public web assets)?
  • Organization IT Environment

    The following questions are required to understand the current IT Environment of your organization. Please answer each question and provide additional information as needed.
  • Do you have an up-to-date IT Asset List?
  • Do you utilize an Asset and Inventory Management System?
  • Do you have documented representations (diagrams, maps) of authorized network communications and external connections?
  • Are assets prioritized based on classification, criticality, and business impact?
  • Are systems, hardware, software, services, and data managed throughout their full lifecycle (acquisition -> decommission)?
  • Do you address unauthorized assets/devices when discovered (remove, quarantine, or authorize)?
  • Do you use an active/passive discovery tool to identify unauthorized assets on the network?
  • Do you address unauthorized software on enterprise assets (allowlist/block/remove)?
  • Do you use automated software inventory tools?
  • Do you ensure authorized software is supported by the vendor (no end-of-life without documented exception)?
  • Organization Staff + Asset / Device Management

    The following questions are required to understand the risk management in place for both your staff and digital assets + devices in use by your organization. Please answer each question and provide additional information as needed.
  • Do you have a Vendor Risk Management solution in place?
  • Does any of your Staff work remotely?
  • Does your IT + Cyber Security Staff work remotely?
  • Are your employees subject to ongoing Background Checks?
  • Are your employees subject to ongoing Identity Screening + Monitoring?
  • Do you have a written Employee Policy in place for employees to notify your organization of Identity Breaches?
  • Browse Files
    Drag and drop files here
    Choose a file
    Cancelof
  • Please tell us if any of the following Corporate Devices are issued to employees?
  • Are your employees permitted to use their own Personal Devices?
  • Does your organization utilize any of the following Mobile Devices in the course of operations?
  • Do you have a Mobile Device Management solution implemented for all related devices?
  • Do you have Mobile Protection and Information-Centric Endpoint Protection?
  • Please indicate any Digital Assets that your organization owns:
  • Do you have a Digital Asset Management Program?
  • Are cybersecurity roles and responsibilities for suppliers, customers, and partners formally established, communicated, and coordinated?
  • Is supply chain cybersecurity risk management integrated into your cybersecurity and enterprise risk management process?
  • Do you classify and/or tier your service providers based on sensitivity and criticality?
  • Do you formally assess service providers before onboarding AND periodically thereafter?
  • Are relevant suppliers and third parties included in your incident response planning, exercises, and playbooks?
  • Do you have a documented service provider decommissioning process (credential revocation, data return/destruction, access removal)?
  • Do you classify data based on sensitivity (e.g., public, internal, confidential, restricted)?
  • Are data access control lists configured to enforce least-privilege access to sensitive data?
  • Do you enforce a documented data retention policy?
  • Do you have a documented secure data disposal / media sanitization process?
  • Do you maintain documented data flow diagrams for sensitive data?
  • Do you encrypt data on removable media?
  • Is sensitive data segmented from non-sensitive processing environments?
  • Cloud and Web Services

    The following questions are required to understand the cloud and web services in place for both your staff and in use by your organization. Please answer each question and provide additional information as needed.
  • Is your organization using any Web / Cloud Services?
  • Are you using any Cloud Security Posture Management tools that covers all cloud risks: spanning misconfigurations, vulnerabilities, identity risks, data security, API / PII / crown jewel asset exposure, and advanced threats?
  • Are you using any Cloud Native Endpoint Detection and Response solutions?
  • Remote Access and Configuration Management

    The following questions are required to understand the remote access and configuration management solutions in place for both your staff and in use by your organization. Please answer each question and provide additional information as needed.
  • Do you provide Remote Access of any kind to staff or customers / members?
  • Do you have any Remote Monitoring tools in place for controlling the Configuration and State of systems?
  • Cyber Security Questionnaire

    The following questions are required to diagnosis the current cyber security environment of your organization. Please answer each question and provide additional information as needed.
  • Do you have Endpoint Detection & Response (EDR)?*
  • Do you have Next Generation Anti-Virus on all endpoints?*
  • Do you have Managed Detection & Response (MDR) in place for all sources of active detection?*
  • Do you have a Vulnerability Assessment and Management solution to discover and assess assets in your environment, including dynamic cloud or remote workforce assets?
  • Do you have Advanced Email Protection for O365/G-Suite as well as your cloud-based collaboration platforms including: pre and post delivery protection, URL and attachment sandboxing, anti-malware scanning, data loss prevention, and encryption?*
  • Do you have Multi-factor Authentication (MFA) implemented for all users?*
  • Do you have Multi-factor Authentication (MFA) implemented for all remote access and 3rd party applications?*
  • Do you have Password Identity Management and Administration tools in place?
  • Do you have Access and Rights Management tools in place?
  • Do you have Application Safelisting (whitelisting / blacklisting) enabled for all workstations and servers?*
  • Do you have Zero Trust Segmentation implemented for all endpoints?*
  • Do you use a Zero Trust Network Access Solution to control remote access?*
  • Do you have Privileged Access Management (PAM) implemented for all privileged accounts?*
  • Do you currently have Segregation of Duties + Business Controls in place for all outgoing payments / funds transfers?*
  • Do you have Single Sign On (SSO) enabled and configured for all 3rd party applications?*
  • Do you have At-Rest Encryption enabled for all endpoints and devices?*
  • Do you have a formal Patch Management Program in place which is informed by critical security and vulnerability data within 30 days?*
  • Do you have an Immutable Backup Strategy (REQUIRES: 3+ backup sources covering all systems / data and 1+ offline / inaccessible from the network where the systems/data reside)?*
  • Do you have a Log Resilience/Centralization Platform (such as a SIEM)?*
  • Do you have Next Generation Firewalls at all locations (REQUIRES: inbound / outbound proxy, threat detection, DoS protection, etc)?*
  • Do you have a Data Loss Prevention (DLP) solution deployed?*
  • Do you log sensitive data access?*
  • Is data in use protected (e.g., memory protection, confidential computing, runtime protections)?*
  • Is automatic session locking configured on endpoints and servers?*
  • Do you run host-based firewalls on servers and end-user devices?*
  • Are administrative/management channels for enterprise assets secured (out-of-band, jump hosts, bastion, dedicated admin workstations)?*
  • Are default accounts on enterprise assets and software disabled, removed, or renamed and secured?*
  • Are unnecessary services disabled or uninstalled on enterprise assets and software?*
  • Are trusted DNS servers configured on enterprise assets?*
  • Do you maintain an inventory of all accounts (user + service + admin)?*
  • Do you disable dormant accounts after a defined period of inactivity (e.g., 45 days)?*
  • Do you maintain an inventory of authentication and authorization systems (IdPs, directories, access brokers)?*
  • Do you have a documented vulnerability remediation process (SLAs by severity, exceptions, tracking)?*
  • Do you ingest threat intelligence and track known threats relevant to your environment?*
  • Do you evaluate potential impacts and likelihoods of threats exploiting vulnerabilities?*
  • Are changes and exceptions managed, assessed for risk impact, recorded, and tracked?*
  • Do you have a process to receive, analyze, and respond to external vulnerability disclosures (e.g., a VDP or security@ mailbox)?*
  • Do you assess the authenticity/integrity of hardware and software prior to acquisition (SBOM, signed software, vendor attestations)?*
  • Do you ensure adequate log storage capacity and retention consistent with policy/regulation?*
  • Is time synchronized across systems (NTP from trusted sources)?*
  • Do you collect DNS, URL, and command-line audit logs?*
  • Do you ensure only supported browsers and email clients are in use (no EOL)?*
  • Do you use DNS filtering services on all enterprise assets?*
  • Do you enforce network-based URL filtering?*
  • Do you restrict unnecessary / unauthorized browser and email client extensions?*
  • Have you implemented DMARC (plus SPF and DKIM) for all sending domains?*
  • Have you disabled autorun/autoplay on removable media across endpoints?*
  • Is anti-malware scanning configured to run automatically on removable media insertion?*
  • Are anti-exploitation features (e.g., DEP, ASLR, CFG, EMET-equivalent) enabled on endpoints?*
  • Is anti-malware centrally managed across the enterprise?*
  • Is your network infrastructure firmware / OS up-to-date (no EOL/EOS devices)?*
  • Do you maintain current network architecture diagrams?*
  • Do you centralize AAA (authentication, authorization, accounting) for network infrastructure (e.g., RADIUS/TACACS+ with SSO/MFA)?*
  • Do you use secure network management and communication protocols (SSH/HTTPS/SNMPv3 - no Telnet/SNMPv1)?*
  • Do you have host-based intrusion detection deployed on servers/endpoints?*
  • Do you have network intrusion prevention (NIPS) deployed at the perimeter/between segments?*
  • Is the physical environment (data centers, wiring closets) monitored for tampering/unauthorized access?*
  • Are environmental threats (fire, flood, power, HVAC) addressed with appropriate controls?*
  • Are resilience mechanisms (redundancy, failover, capacity) implemented to meet availability requirements?*
  • Is hardware maintained, replaced, and securely removed in alignment with risk?*
  • Are identities proofed and bound to credentials based on the context of interactions (identity proofing per NIST 800-63-3 equivalent)?*
  • Are identity assertions protected, conveyed, and verified (e.g., signed SAML/OIDC assertions)?*
  • Do you collect DHCP lease logs (assignments, releases, conflicts) and retain them for asset inventory and incident investigation?*
  • Is sensitive data encrypted in transit across untrusted networks (TLS 1.2+/IPsec) with weak ciphers disabled?*
  • Do end-user devices automatically lock after a defined period of inactivity (e.g., 15 minutes) and after a limited number of failed login attempts?*
  • Do you actively monitor service providers' security posture (e.g., annual attestation review, continuous monitoring tools, breach notification SLAs) and log/review provider access to your systems?*
  • Do you monitor activity performed by external service providers (remote admin sessions, API usage, data egress by third parties) for anomalous or unauthorized behavior?*
  • Technologies + Development

    The following questions are related to specific technology needs and development. Please answer each question and provide additional information as needed.
  • Do you have Operational Technologies?
  • Do you have Operational Technology Detection and Response solutions?
  • Do you develop Applications or Custom Code for yourself or customers?
  • Do you have Application and Code Security solution in place?
  • Do you develop Web Applications or APIs, or utilize APIs for any of your own Web Applications?
  • Do you have Web Application and API Security solutions in place?
  • Do you host your own Custom Email or any similar Custom Applications?
  • Do you have a DDoS Attack Mitigation solution in place?
  • Do you perform root-cause analysis on security vulnerabilities found in your applications?
  • Do you use a formal severity rating system for application vulnerabilities (e.g., CVSS) with remediation SLAs?
  • Are standard hardening configuration templates used for application infrastructure?
  • Are production and non-production systems formally separated (distinct accounts, networks, and data)?
  • Cyber Security Program

    The following questions are required in order to better understand your written policies + procedures and response plans. Please answer each question and provide additional information as needed.
  • Do you have a Written Cyber Security Program in place which aligns with regulatory requirements and/or industry standards (NIST, CIS, etc)?*
  • Browse Files
    Drag and drop files here
    Choose a file
    Cancelof
  • Is your organization (OR any of your customers) subject to additional regulatory requirements by any of the following regulated industries?
  • Do you have an Incident Response Plan in place currently?
  • Is your Incident Response Plan approved by your insurance carrier?
  • Do you have a dedicated Computer Security Incident Response Team (CSIRT)?
  • Is your Computer Security Incident Response Team (CSIRT) approved by and aligned with your insurance carrier?
  • Do you have a formal Security Awareness Training program with mandatory annual completion for all workforce?
  • Does training cover recognizing social engineering / phishing attacks?
  • Does training cover authentication best practices (password hygiene, MFA, passkeys)?
  • Does training cover causes of unintentional data exposure (misconfig, accidental share, shadow IT)?
  • Does training cover how to recognize and report security incidents?
  • Does training cover how to identify and report missing/outdated security updates on assets?
  • Does training cover dangers of connecting to / transmitting data over insecure networks?
  • Do privileged role holders (admins, developers, IT staff) receive specialized, role-specific training at hire and at least annually?
  • Have you assigned documented key roles and responsibilities in your Incident Response Plan (including executive sponsor, IC, legal, communications)?
  • Have you established and documented incident severity thresholds / declaration criteria?
  • Are incoming incident reports triaged and validated per a documented process?
  • Are incidents formally categorized and prioritized on declaration?
  • Are incidents escalated or elevated per a defined matrix (severity x role)?
  • Are criteria defined and applied for initiating incident recovery?
  • Is root-cause analysis performed for declared incidents, documented, and integrated into improvements?
  • Are investigator actions recorded with chain-of-custody / integrity preservation?
  • Is incident magnitude formally estimated and validated during response?
  • Do you have documented containment procedures for common incident types (ransomware, BEC, data exfil)?
  • Do you have documented eradication procedures for removing attacker presence?
  • Is adverse-event impact/scope analysis performed (what was touched, how much data, what users)?
  • Is adverse-event information provided to authorized staff and tools (SOAR, ticketing, ChatOps)?
  • Is cyber threat intelligence integrated into adverse-event analysis?
  • Do you have a documented recovery plan integrated with the Incident Response Plan?
  • Are recovery actions selected, scoped, and prioritized per plan during incident response?
  • Is backup/restoration asset integrity verified before use in recovery?
  • Are critical mission functions considered to establish recovery priorities (RTO/RPO)?
  • Is integrity of restored assets verified and normal operations formally declared resumed?
  • Is the end of incident recovery declared based on defined criteria, and is documentation completed?
  • Are recovery activities communicated to internal and external stakeholders per plan?
  • Are public recovery updates provided using approved messaging and channels (PR/comms plan)?
  • Are improvement opportunities formally captured from evaluations, exercises, and incidents?
  • Do you have a formal Penetration Testing Program documenting scope, frequency, and rules of engagement?
  • Do you perform external penetration tests at least annually?
  • Do you perform internal penetration tests at least annually?
  • Are penetration test findings tracked through to remediation with validation retesting?
  • Do you validate security controls regularly (breach-attack simulation, purple team, control testing)?
  • Does your Security Awareness Training include data handling best practices (classification, storage, transmission, disposal) with role-specific content for staff who handle sensitive data?
  • Cyber Liability Insurance

    The following questions are required to establish an understanding of your current cyber insurance in force (or desired coverage). Please provide as many details as known related to the coverage.
  • Does your organization currently have Cyber Liability Insurance?
  • Is the insurance policy part of a Group/Membership Plan or your own coverage?
  • When is the Renewal Date for this policy?
     - -
    2 digit month, 2 digit day, 4 digit year
  • Have you received an Offer for Renewal?
  • Is Cyber Liability Insurance desired?
  • When would you like coverage to begin?
     - -
    2 digit month, 2 digit day, 4 digit year
  • Please indicate if you would like recommendations for any additional coverage:
  • Date Submitted*
     - -
    2 digit month, 2 digit day, 4 digit year
  • Should be Empty: