Black Shard

ToolsDefensive & advisory

Cyber insurance answer check.

Twenty-two control questions, answered the way a proposal form asks them.

Runs in your browser. Nothing you enter is sent, stored or logged.

Context

Remote access

  • Remote access runs through one controlled path with multi-factor on it.

    One gateway rather than several. Forms ask this separately from staff sign-in, because the two often diverge.

  • Remote desktop is not reachable from the internet except through that path.

    Directly published remote desktop appears by name on most proposal forms as its own question.

Identity and multi-factor coverage

  • Multi-factor authentication is enforced on every mailbox, including shared and service accounts.

    Forms treat email as its own question. The mailbox exempted for convenience is the one they are asking about.

  • Sign-in methods that skip multi-factor are switched off.

    Basic authentication, older mail protocols and app passwords let a stolen password work without the second factor.

  • Multi-factor authentication covers the cloud services holding your data, not only your own network.

    Accounting, file sharing, payroll and customer platforms are in scope when they hold the records you are insuring.

Backups and restoration

  • Backup copies cannot be deleted or encrypted by a compromised administrator account.

    Immutable, offline or separately governed copies. Forms word this as whether backups are segregated from the production domain.

  • A restore has been performed and timed within the last twelve months.

    The question is not whether backups run. It asks when a restore was last done, of what, and how long it took.

  • You know how much data you would lose and how long you would be down.

    Recovery point and recovery time. Both figures get quoted back at you if the policy is ever tested.

Email filtering and impersonation

  • Inbound mail is filtered for phishing links and malicious attachments.

    Forms ask what does the filtering and whether it applies to every domain you receive on, including ones you acquired.

  • SPF, DKIM and DMARC are published for every domain you send from.

    Parked and marketing domains included. DMARC is increasingly asked for by name rather than folded into a general question.

  • Changes to payment or bank details are verified by calling a number you already held.

    Funds transfer cover commonly turns on this control. It is a process question rather than a technology one.

Endpoint protection and detection

  • Every workstation and server runs endpoint protection managed from one console.

    Forms ask about coverage rather than licences held. A machine the console cannot see counts as an uncovered machine.

  • Endpoint alerts are reviewed outside business hours by a person or a service.

    Deployment and monitoring are separate questions on the form, because intrusions rarely wait for Monday.

  • You could produce a list of every device that touches company data.

    Coverage answers rest on an inventory. Without one, every coverage figure on the form is an estimate.

Privileged and administrative accounts

  • Administrators use separate accounts for privileged work.

    A daily account carrying admin rights is the pattern these questions are probing.

  • Privileged access is reviewed, and removed when people change role or leave.

    Forms ask how often the review happens. Intent to review is not what the field is collecting.

Patching internet-facing systems

  • Critical patches on internet-facing systems are applied within two weeks, sooner when exploitation is public.

    Answer against the window the form prints rather than against general intent. Windows vary between insurers.

  • You know every service of yours that is reachable from the internet.

    Firewalls, VPN appliances, remote desktop gateways, web applications, and anything a supplier stood up on your behalf.

Supplier and third-party access

  • You have a list of suppliers who can reach your systems or your data.

    Managed IT providers, bookkeepers, developers, and platforms holding records on your behalf.

  • Supplier access uses named accounts with multi-factor, and is removed when the work ends.

    Shared logins handed to a provider are the specific arrangement this question is looking for.

Incident response readiness

  • There is a written incident response plan naming who does what.

    Forms ask whether a plan exists and when it was last exercised. Both halves get asked, usually in the same question.

  • The plan has been walked through with the people named in it within the last year.

    A tabletop walkthrough counts. A plan written once and filed is a partial answer to this question.

0 of 22 answered. Nothing is stored, so reloading this page clears every answer.

Reading against the form

Answer each line the way your form words it.

ReadingNothing answered yet

A directional read of how your answers would sit on a proposal or renewal form. Accuracy matters here because a tick you cannot evidence is the one examined at claim time, which is a reason to answer precisely and qualify in writing. The version that stands up is a control review with the evidence sighted.

What this does, and what it deliberately does not.

This check works through the control questions proposal and renewal forms ask, and sorts your answers into what you can tick today, what is true only with a written qualifier, and what would be an overstatement. It predicts no premium and makes no cover decision. It rehearses the form; sighting the evidence behind each answer is a control review.

Want the answers evidenced before the form goes back?

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au