Hartford Cyber 2026, filled from Big Tex’s Shop.

14-employee Auto industry · Prosper, Texas · 6 endpoints

This is what your application looks like after you click Auto-fill. Every answered field carries the citation back to the assessment control or signup data it was drawn from. 3 of the 47 fields are flagged for your input, the things only you can know.

Identity and access

Who can sign in to your systems, and how.

Q01

Do you require multi-factor authentication for all administrative accounts?

Yes

PR.AC-01 (Multi-factor authentication), implemented 12 April 2026

Q02

Do you require multi-factor authentication for all employee accounts?

Yes

PR.AC-01 (Multi-factor authentication), implemented 12 April 2026

Q03

Do you enforce strong password policies (minimum 12 characters, complexity requirements)?

Yes

PR.AC-01 password policy, enforced via M365 baseline

Q04

Do you maintain a list of authorized personnel with access to sensitive data?

Yes

ID.AM-06 (Asset inventory), score 2.9 of 3.0, reviewed quarterly

Q05

Are former employee accounts disabled within 24 hours of departure?

Yes

PR.AC-04 (Access management), same-day revocation policy

Q06

Do you use single sign-on (SSO) for company applications?

Partially

M365 SSO covers email and core productivity. Third-party apps not yet consolidated.

Q07

Do you conduct quarterly access reviews?

Yes

ID.AM-06, most recent review April 2026

Q08

How many privileged or administrative accounts exist in your environment?

3

Owner plus two designated administrators per asset inventory

Q09

Do you maintain a centralized identity directory (e.g., Microsoft 365, Okta)?

Yes

Microsoft 365, primary identity provider

Q10

Are passwords stored in a managed password vault?

Yes

1Password Business, included with managed-services package

Endpoint security

The laptops, desktops, and devices your team uses.

Q11

How many endpoint devices (laptops, desktops, mobile) are in your environment?

6

Syxsense device snapshot, 04 May 2026, 6 endpoints

Q12

Do you have endpoint detection and response (EDR) software installed on all endpoints?

No

DE.CM-04 (Endpoint detection), score 1.6 of 3.0, Cylance install scheduled June 2026

Q13

Are all endpoints managed by a mobile device management (MDM) tool?

Yes

Syxsense Cloud Management Suite, 6 of 6 endpoints enrolled

Q14

Are critical security patches applied within 30 days of release?

Yes

Syxsense patch compliance, 6 of 6 endpoints current as of 04 May 2026

Q15

Is encryption enforced on all endpoint hard drives?

Partially

PR.DS-01 (Data at rest), score 0.8 of 3.0, FileVault on for 2 of 3 Macs, BitLocker rollout in progress

Q16

How many of your endpoints run Windows?

3

Syxsense fleet inventory, 3 Windows 11 Pro endpoints

Q17

How many of your endpoints run macOS?

3

Syxsense fleet inventory, 3 macOS 14.5 endpoints

Q18

Do you use a secure web gateway or DNS filtering?

Yes

Email Security Basic package, DNS filtering included

Q19

Is anti-malware software installed on all endpoints?

Yes

Syxsense AV inventory, Microsoft Defender on all 6 endpoints

Q20

Do you have a documented endpoint hardening standard?

No

Not documented in current assessment. Hardening baseline planned for Q3 2026.

Data protection

How your customer data is handled, encrypted, and backed up.

Q21

Do you classify customer data (e.g., PII, financial, health)?

Yes

Information Security Policy §05, three categories defined: customer-PII, vehicle-records, payment-references

Q22

Is customer data encrypted at rest?

Partially

PR.DS-01 (Data at rest), in progress, expected complete end of June 2026

Q23

Is customer data encrypted in transit (TLS)?

Yes

PR.DS-02, TLS 1.2+ enforced on all customer-facing endpoints

Q24

Do you store payment card data?

No

Information Security Policy §05, only last-four digits and authorization codes are retained for reconciliation

Q25

Do you have a documented data retention policy?

Yes

Information Security Policy §08, annual review and material-change cadence

Q26

Approximately how many customer records do you store?

Approximately 5,200

Estimated from 14-employee Auto industry profile and 4-year operating history

Q27

Do you back up customer data regularly?

Yes

PR.IP-04 (Backups), daily incremental, weekly full

Q28

Are backups stored offsite or in cloud?

Yes

Microsoft 365 cloud backup, geographically redundant

Q29

Are backups tested for successful restoration at least quarterly?

No

PR.IP-04 (Backup verification), score 0.4 of 3.0, last successful test recorded 90+ days ago

Incident response

What you do when something goes wrong.

Q30

Do you have a written incident response plan?

Yes

Information Security Policy §07, Incident Response Plan referenced; standalone IRP doc in progress

Q31

Have you conducted an incident response tabletop exercise in the past 12 months?

No

RS.IM-01, no tabletop exercise recorded in audit history. Scheduled for Q3 2026.

Q32

Do you currently have a cyber insurance policy in force?

No

Customer signup did not record an existing cyber insurance policy

Q33

Have you experienced a cyber incident, breach, or data loss event in the past 24 months?

[your input]
Needs your input

Prior-incident disclosure must come from the owner directly. The platform does not infer claims history.

Q34

Do you have a designated incident response team or external retainer?

Yes

H2Cyber retainer, Paul Horn, Practitioner, 30 years

Q35

What is your committed time-to-detect for security incidents (in hours)?

4

DE.AE-02, 4-hour detection commitment per Information Security Policy

Q36

What is your committed time-to-notify customers and regulators after a confirmed breach (in hours)?

24

Texas Business and Commerce Code §521.053, 24-hour notification requirement

Q37

Do you maintain logs of system access for at least 90 days?

Yes

PR.PT-01, Microsoft 365 audit logs retained 180 days

Q38

Have you ever paid a ransomware demand?

No

No ransomware payment recorded in customer history

Business operations

Your company profile and regulatory posture.

Q39

What is your industry sector?

Auto

Customer signup data, industry: Auto

Q40

How many employees do you have?

14

Customer signup data, 14 employees

Q41

What is your approximate annual revenue?

[your input]
Needs your input

Revenue is not in the assessment scope. The owner enters this directly.

Q42

Are you registered with the SEC?

No

Regulatory profile, state-AG only

Q43

Are you registered with FINRA?

No

Regulatory profile, state-AG only

Q44

Are you registered with NYDFS?

No

Regulatory profile, state-AG only

Q45

Do you operate in states with active cyber notification or data-protection requirements?

Yes

State of Texas, Texas Business and Commerce Code §521.053

Q46

How many third-party vendors have access to customer data?

2

Vendor inventory, Microsoft (M365) and Syxsense, both with active DPAs

Q47

What policy limit are you requesting on this application?

[your input]
Needs your input

Coverage limit is the owner's decision. The platform does not recommend a number.

BACKED BY ASSESSMENT
44 of 47 fields
MARKED FOR YOUR INPUT
3 fields
PREPARED
04 MAY 2026

Your form would auto-fill from your own assessment data.

Take the 11-question free assessment. The platform answers every question on every form your insurer or your customer sends, with citations your underwriter can verify.