Resources

Prepare before the questions arrive.

Use practical guidance to understand common technical controls, collect useful evidence, and identify where a deeper review may be needed.

Turn scattered questions into organized next steps.

Featured resource

Cyber Insurance Readiness Checklist

A concise starting point for reviewing the technical controls frequently raised during cyber insurance applications and renewals.

Cyber Insurance Readiness Checklist

Review eight practical areas and note what evidence your organization can produce today.

Download PDF

Readiness topics

Understand the question before someone asks for the evidence.

These are the practical control questions that often trigger a readiness review.

What insurers mean by MFA

Enabled is not always enforced. Understand which users, applications, and access paths are actually covered.

Why backups are not enough

A completed job does not prove the protected data is complete or that a usable restore can be demonstrated.

What EDR coverage means

Confirm which endpoints report into the platform, which are missing, and who responds to alerts.

SPF, DKIM, and DMARC

Understand how the three controls work together to protect a domain and support trustworthy email.

Conditional Access

See how identity conditions can enforce requirements based on the user, device, application, and sign-in risk.

Evidence before the request

Know which screenshots, reports, configurations, logs, and test records can support an answer.

How to use the checklist

Treat it as a starting point.

The checklist can help organize an internal conversation. It is not an audit, certification, guarantee of coverage, or substitute for a scoped technical assessment.

Review each control

Identify the systems, settings, and owners connected to it.

Collect evidence

Note what configuration or operating evidence is available.

Prioritize gaps

Focus first on material exposures and immediate business requirements.

Common questions

What the checklist can and cannot do.

Does completing the checklist make us insurable?

No. Insurers make underwriting decisions based on their own requirements, the application, and other factors. The checklist is a preparation aid.

Should every control produce evidence?

Useful evidence depends on the control and the question being answered. A scoped assessment can clarify what is relevant and available.

Can Prometheus work with our current IT provider?

Yes. Prometheus can coordinate with the organization and its existing provider within the agreed technical scope.

Can we submit sensitive records through the contact form?

No. Do not submit passwords, health information, privileged legal materials, or other sensitive information through the website form.

Need a verified answer?

Turn the question into a scoped Readiness Assessment.