Appearance
Compliance: Cyber Insurance Annual Review Checklist
Purpose
Cyber insurance is the financial backstop for an incident that exceeds our internal containment capacity. The policy is only valuable if (a) we actually maintain the security controls the carrier requires us to have, (b) we know what is and is not covered, and (c) we can produce evidence quickly when we need to file a claim. This checklist drives the annual policy review.
Owner: Rory must personally review the actual policy document annually. No agent, script, or delegated party substitutes for that review. This checklist captures the evidence and talking points Rory uses in that review — it does not replace reading the policy.
When to Run
- Annual full review: 60 days before policy renewal date
- Mid-year evidence refresh: 6 months before renewal
- Trigger-based review: after any material change to our environment (new tenant, major acquisition, large-scale tooling change, HIPAA scope change)
- Post-incident review: within 30 days of any reported or reportable incident
1. Coverage Amounts
Capture the current policy's limits and deductibles. Compare against prior year and document whether the coverage still matches our risk profile.
- [ ] Aggregate limit — total payout ceiling across all claims in the policy year
- [ ] Per-incident sub-limit — maximum per single claim
- [ ] First-party coverages: business interruption, data restoration, forensic costs, ransom payment, notification costs, credit monitoring, PR/crisis management
- [ ] Third-party coverages: regulatory fines (HIPAA/OCR penalties), privacy liability, media liability, network security liability
- [ ] Retention (deductible) per claim type — lower retention generally means higher premium
- [ ] Waiting period before business interruption coverage kicks in (commonly 8–12 hrs)
- [ ] Sub-limit for social engineering / funds transfer fraud (often capped separately)
Action: Record year-over-year comparison. Flag any coverage that has dropped relative to growth in revenue, PHI record count, or endpoint count.
2. Exclusions to Watch
Exclusions are where claims get denied. Read these sections of the policy carefully every renewal — carriers update exclusion language each cycle.
- [ ] Unencrypted data exclusion — confirm policy does not exclude losses involving data that was not encrypted at rest or in transit. If it does, confirm our actual posture covers all the encryption the carrier requires.
- [ ] Unpatched systems exclusion — policy may exclude losses where a CVE with a patch available for >30 (or 60 or 90) days was the entry vector. Verify patching cadence matches the carrier's tolerance.
- [ ] Prior acts / known vulnerability exclusion — anything known at bind date that we failed to disclose is excluded.
- [ ] Failure to maintain controls — if the policy requires specific controls (MFA, EDR, backups, etc.) and they lapse, coverage is void for incidents during the lapse. See Section 3.
- [ ] War / act of war / nation-state exclusions — carriers have broadened these post-NotPetya. Read the attribution language — some exclude any attack "attributable to" a nation-state whether formally attributed or not.
- [ ] Infrastructure exhaustion / widespread outage exclusion — e.g. SolarWinds or AWS-wide outage clauses.
- [ ] Social engineering specific exclusions — many policies exclude employee-induced wire fraud unless a specific rider is in place.
- [ ] Biometric / wiretap / TCPA — privacy exclusions that vary by state.
- [ ] Retroactive date — claims arising from incidents before this date are excluded.
Action: List each material exclusion in the review memo with a one-line risk assessment.
3. Required Security Controls
Carriers condition coverage on maintaining specific controls. A lapse in any of these during the policy period is often enough to deny a claim. We must have continuous evidence that each required control is in place.
Map each required control to a SecOps evidence record (/api/evidence) — same pipeline used for SOC2 evidence.
- [ ] Multi-factor authentication on all privileged, remote, and email access
- Evidence: Entra Conditional Access policies + Maester weekly compliance report
- [ ] Endpoint detection and response on all servers and workstations
- Evidence: Cortex XDR coverage report, Arctic Wolf agent coverage
- [ ] Email security — anti-phishing, anti-spoofing, impersonation protection
- Evidence: Microsoft Defender for Office 365 policy exports
- [ ] Regular, tested backups — offline/immutable copy, restore tests
- Evidence: Veeam restore test results + RSV immutability settings +
runbooks/dr-test-checklist.mdquarterly reports
- Evidence: Veeam restore test results + RSV immutability settings +
- [ ] Privileged access management — no shared accounts, logged session recording for admin access
- Evidence: Keeper session recordings, PIM activation history
- [ ] Patching program — critical patches within N days (policy will specify)
- Evidence: Azure Update Manager compliance, AWS SSM Patch Manager reports
- [ ] Vulnerability scanning — regular scans with remediation SLA
- Evidence: Cortex vulnerability reports, Tenable/Qualys output if contracted
- [ ] Security awareness training — all employees, annual minimum
- Evidence: training platform completion reports, phishing test results
- [ ] Incident response plan — documented, tested
- Evidence:
runbooks/incident-response.md+ tabletop exercise records
- Evidence:
- [ ] Access control / least privilege — documented entitlement reviews
- Evidence: quarterly access review records, PIM role assignments
- [ ] Network segmentation — especially for PHI zones
- Evidence: NSG/firewall rules, VNET topology documents
- [ ] Logging and monitoring — centralized logs with retention
- Evidence: LAW retention settings, SecOps incident records
- [ ] Secure configuration baselines — CIS or equivalent
- Evidence: Azure Policy HIPAA/HITRUST initiative compliance reports
Action: For each required control, confirm current coverage percentage, identify any gap, and create a remediation story in SecOps if gap exists.
4. Evidence Documentation
The carrier (or their forensic firm, during a claim) will ask for evidence that controls were in place before and during the incident. Maintain a continuously-updated evidence binder. Same approach as SOC2 evidence — same backing store.
- [ ] SharePoint folder
Compliance → Cyber Insurance → <renewal-year>contains:- [ ] Signed policy PDF (current + prior two years)
- [ ] Policy summary — coverage/exclusions/controls memo Rory writes each renewal
- [ ] Proof-of-control evidence (see Section 3) — can be links to SecOps evidence records instead of re-uploading
- [ ] Year's incident log (even trivial — shows we're tracking)
- [ ] Annual security training completion roster
- [ ] DR test reports (all 4 quarters)
- [ ] Annual access review sign-offs
- [ ] Tabletop exercise after-action reports
- [ ] SecOps
/api/evidencerecords taggedcyber-insurancecarry apolicy-yearattribute so pulling a year's controls evidence is one query - [ ] 7-year retention applied to all cyber-insurance-tagged evidence (match evidence bucket WORM policy)
5. Renewal Timeline
Budget backwards from renewal date. Carriers' questionnaires have gotten long — start early.
| Time before renewal | Activity |
|---|---|
| T-90 days | Confirm renewal date, request prior-year loss run from broker |
| T-75 days | Broker provides renewal application / questionnaire |
| T-60 days | Run this checklist — Rory reads current policy, identifies coverage |
gaps, confirms required controls |
| T-45 days | Submit completed questionnaire with evidence attachments | | T-30 days | Negotiate with carrier on coverage adjustments, pricing, sub-limits | | T-15 days | Review bound quote, confirm coverage effective dates align (no gap) | | T-7 days | Sign renewal, pay premium | | T-0 days | New policy effective — archive old policy to SharePoint |
6. Claim Readiness
Not a renewal activity per se, but part of the annual review — confirm we know how to file if we need to.
- [ ] Carrier's breach hotline number is documented in
runbooks/incident-response.md - [ ] Panel firms (forensic, legal, PR, notification vendor) are listed and Rory has made a pre-breach introduction to forensic + legal
- [ ] Notification timelines are documented — many policies require notifying the carrier within 24–72 hours of discovery (failure to notify timely = denied claim)
- [ ] Internal escalation path: who notifies the carrier — Rory primary, Kevin backup
- [ ] Attorney-client privilege note: the policy's panel counsel typically retains forensic firm; do NOT retain forensics directly before calling counsel — breaks privilege
7. Review Memo Template
Rory produces a 1-page memo each renewal summarizing this review. Structure:
Cirius Group — Cyber Insurance Review <YYYY>
Prepared by: Rory
Date: <YYYY-MM-DD>
Renewal date: <YYYY-MM-DD>
1. COVERAGE SUMMARY
- Aggregate limit: $X (prior year $Y)
- Deductible: $X (prior year $Y)
- Material changes vs prior year: [list]
2. EXCLUSIONS OF NOTE
- [Exclusion 1 + our exposure]
- [Exclusion 2 + our exposure]
3. REQUIRED CONTROLS STATUS
- Control N: in place — evidence ref
- Control M: partial — gap + remediation plan + story ID
- Control O: not in place — action plan
4. RECOMMENDED CHANGES TO BIND
- [e.g. add social engineering endorsement, increase ransom sub-limit]
5. SIGN-OFF
Rory — <date>File the signed memo in SharePoint alongside the signed policy PDF.
Related Documents
compliance/annual-review-checklist.md— broader annual review (this fits inside)runbooks/incident-response.md— claim notification procedurerunbooks/dr-test-checklist.md— evidence source for backup/recovery controlcompliance/hipaa-controls.md— evidence mapping for required controls