Topshelf Technology / Cyber Insurance Checklist
Cyber Insurance Checklist.
Prepare for your next renewal conversation.
Review 12 security practices, flag controls to verify and download a personalized PDF to discuss with your technology team and insurance broker.
Free / 12 questions / Personalized PDF
Business and contact details personalize your results. This is a self-assessment, not a coverage decision.
01 / Know what to review
A clearer view of your security practices.
Keep the renewal conversation grounded in what your business actually does. The checklist turns your answers into a summary you can review with the people responsible for your technology and insurance.
ACCESS + DEVICES
Protect everyday work.
Review multifactor authentication, endpoint detection, email security, privileged access and device protection.
RECOVERY + OPERATIONS
Prepare for disruption.
Review backups, security training, incident response, patching, vendor access, written policies and incident history.
02 / Start with what you know
Work through your cyber insurance checklist.
Choose the answer that best reflects your current practices. Use Partial or Unsure when appropriate. After the questions, personalize your on-screen results and downloadable PDF.
Start your 12-question checklist
Choose Yes, Partial, No or Not sure for each control. Honest answers create a more useful list of what to verify and improve.
After the questions, enter your name, company, phone, work email and number of employees to personalize results. You can view them here and download a PDF. This tool does not email your report or send these entries to TST.
Select one answer. Keyboard shortcuts: Y for Yes, P for Partial, N for No, U for Not sure.
Personalize your report
Your answers are ready to score. These details personalize the results shown here and the PDF you download. No report is emailed and these entries are not sent to TST by this tool.
All fields are required except current policy status. Privacy policy
Your details and answers stay in this page's memory until you refresh or leave. The downloaded PDF contains your entries, so share it only with people you choose.
Your checklist results
Critical controls need attention
These reported gaps need prompt review regardless of the total score. This is a control-priority warning, not a prediction about insurance eligibility or a claim.
Verify critical controls first
You marked these important controls Not sure. Confirm their status with your IT team. Unknown is not the same as absent, but it earns no readiness points until verified.
Control gaps to verify and improve
Practical next steps
Your full checklist and evidence guide
Use these records to verify your answers. Follow the wording of your insurer's application and ask your broker or insurer about unclear requirements.
Discuss your readiness priorities
Use the report to review control gaps with your IT team, or talk with Topshelf about the technical work to address them.
This checklist is based on your answers. It is not a technical audit, insurance application, underwriting decision, coverage review or compliance certification. It does not predict a premium, policy approval or claim outcome. Requirements depend on your insurer, application and policy. Confirm insurance questions with your broker or insurer. Privacy policy
03 / Make the results useful
Verify the answers. Gather the evidence.
Your score is a starting point. Review important gaps first, assign an owner to each question and confirm the details before using them in an application.
01 / VERIFY
Confirm the controls.
Ask your technology team for current MFA coverage, endpoint monitoring details, backup restore test records and patching reports. Record exceptions and items you could not confirm.
02 / DOCUMENT
Bring the right records.
Gather your application or renewal questionnaire, relevant security policies, incident response contacts and prior incident records. Ask your broker which details and evidence the insurer needs.
Keep your technology team and insurance broker involved. A technical review helps establish what is in place; your broker can help you understand the insurer’s questions and policy requirements.
04 / Before you start
A few useful answers.
What does this cyber insurance checklist check?
It asks about 12 reported security practices, including MFA, endpoint detection, backups, email security, privileged access, training, incident response, patching, devices, vendors, policies and incident history. It does not scan your systems or verify that those controls work.
How should I interpret the score?
The score summarizes your answers using weighted questions. Higher scores reflect stronger reported practices. Partial, missing and unsure answers produce items to review, and important control gaps remain prominent even if the overall score is high. Read the findings alongside the score.
Does a high score mean we qualify for coverage or that a claim will be paid?
No. Requirements and coverage depend on the insurer, application, policy terms and facts of a claim. This checklist is a preparation tool. Review the actual questions and policy with your insurance broker, and verify technical answers with your technology team.
How do I receive my report?
After the 12 questions, enter your name, company, phone number, work email and company size to personalize your report. Results appear on screen, and you can download a PDF with your score, answers, findings and next steps. The tool does not automatically email the report.
What should we do with partial or unsure answers?
Treat them as verification tasks. Identify who can confirm the control, collect the relevant evidence and record any gaps. Use the report to organize a discussion with your technology team and insurance broker before completing an application or renewal.
Turn unanswered questions into next steps.
Explore more tools and guides, learn about Cybersecurity, or read our Privacy Policy.