Forms · Hartford Cyber Insurance · 2026 Application

00 of 47 filled
Reading your assessmentPhase 01 of 04
·· THE HARTFORD · CYBER 2026 ·· · prepared for Big Tex's Shop

Hartford Cyber 2026 Application.

Reading your assessment, mapping each question to the controls and signup data that answer it, drafting answers with citations underneath.

04 MAY 2026
Identity and access

Who can sign in to your systems, and how.

Q01

Do you require multi-factor authentication for all administrative accounts?

Q02

Do you require multi-factor authentication for all employee accounts?

Q03

Do you enforce strong password policies (minimum 12 characters, complexity requirements)?

Q04

Do you maintain a list of authorized personnel with access to sensitive data?

Q05

Are former employee accounts disabled within 24 hours of departure?

Q06

Do you use single sign-on (SSO) for company applications?

Q07

Do you conduct quarterly access reviews?

Q08

How many privileged or administrative accounts exist in your environment?

Q09

Do you maintain a centralized identity directory (e.g., Microsoft 365, Okta)?

Q10

Are passwords stored in a managed password vault?

Endpoint security

The laptops, desktops, and devices your team uses.

Q11

How many endpoint devices (laptops, desktops, mobile) are in your environment?

Q12

Do you have endpoint detection and response (EDR) software installed on all endpoints?

Q13

Are all endpoints managed by a mobile device management (MDM) tool?

Q14

Are critical security patches applied within 30 days of release?

Q15

Is encryption enforced on all endpoint hard drives?

Q16

How many of your endpoints run Windows?

Q17

How many of your endpoints run macOS?

Q18

Do you use a secure web gateway or DNS filtering?

Q19

Is anti-malware software installed on all endpoints?

Q20

Do you have a documented endpoint hardening standard?

Data protection

How your customer data is handled, encrypted, and backed up.

Q21

Do you classify customer data (e.g., PII, financial, health)?

Q22

Is customer data encrypted at rest?

Q23

Is customer data encrypted in transit (TLS)?

Q24

Do you store payment card data?

Q25

Do you have a documented data retention policy?

Q26

Approximately how many customer records do you store?

Q27

Do you back up customer data regularly?

Q28

Are backups stored offsite or in cloud?

Q29

Are backups tested for successful restoration at least quarterly?

Incident response

What you do when something goes wrong.

Q30

Do you have a written incident response plan?

Q31

Have you conducted an incident response tabletop exercise in the past 12 months?

Q32

Do you currently have a cyber insurance policy in force?

Q33

Have you experienced a cyber incident, breach, or data loss event in the past 24 months?

Needs your input

Prior-incident disclosure must come from the owner directly. The platform does not infer claims history.

Q34

Do you have a designated incident response team or external retainer?

Q35

What is your committed time-to-detect for security incidents (in hours)?

Q36

What is your committed time-to-notify customers and regulators after a confirmed breach (in hours)?

Q37

Do you maintain logs of system access for at least 90 days?

Q38

Have you ever paid a ransomware demand?

Business operations

Your company profile and regulatory posture.

Q39

What is your industry sector?

Q40

How many employees do you have?

Q41

What is your approximate annual revenue?

Needs your input

Revenue is not in the assessment scope. The owner enters this directly.

Q42

Are you registered with the SEC?

Q43

Are you registered with FINRA?

Q44

Are you registered with NYDFS?

Q45

Do you operate in states with active cyber notification or data-protection requirements?

Q46

How many third-party vendors have access to customer data?

Q47

What policy limit are you requesting on this application?

Needs your input

Coverage limit is the owner's decision. The platform does not recommend a number.

Backed by assessment
44 of 47 fields
Marked for your input
3 fields
Prepared
04 MAY 2026