10 questions your cyber insurer (or a customer) will ask this year
A one-page cheat sheet you keep at the desk while you fill out a broker form or a customer security questionnaire. Not a completed application. Not a promise that any carrier will bind.
Who it is for
US companies of roughly 10–150 people running Microsoft 365 or Google Workspace, staring at a cyber-insurance renewal or a customer's security questionnaire without written answers yet. If you are the owner, the ops lead, or the IT director who got handed the form, this is the sheet you wish came stapled to it.
The ten questions
Every broker form phrases them differently, but it is the same ten things. The download gives you, for each one, what evidence actually answers it and what to say if the honest answer is "not yet."
- Written information security policy, approved
- MFA on email and remote access
- Backups and last restore test
- Incident response: who you call in hour one
- Joiner / mover / leaver access
- Vendor / MSP admin access
- Training completion
- Encryption at rest on laptops
- Admin and mailbox audit logs
- Incident or claim in the last 3–5 years
Get the free one-pager
One page. Ten questions. The evidence that answers each one, and how to answer when you do not have it yet. Written by a CISSP for companies without a security team.
Anthony Bahn, CISSP · AMB Digital Group LLC · https://www.anthonybahn.com/
If the free file will not download, email webmaster@ambdigitalgroupllc.com.
What this is not
- Not the full SMB Security Document Pack (that is the $147 / $297 download below).
- Not a CMMC, NIST 800-171, or SOC 2 package.
- Not a vCISO, a phone call, a workshop, or consulting hours.
- Not an MSP white-label kit.
- Not a completed insurance application, and not a promise that any carrier will quote, bind, renew, or pay.
If you want the written baseline
The cheat sheet tells you what they will ask. If the honest answer to question one is "we do not have a written policy," the SMB Security Document Pack is the eleven policies plus a first-60-minutes incident response plan that becomes that evidence.
If you need the written policies and the IR plan. Placeholders throughout; you fill the one-page intake and search-and-replace them yourself. Instant download.
DIY pack — $147If you want the intake stamped in for you. Your company name and stack applied from your completed intake, files back in 3 business days. No call.
Named Pack — $297One-organization license. Templates and a starting point — not legal or insurance advice. Published by AMB Digital Group LLC.
Read this before you answer a form
Downloading a cheat sheet does not mean you "have NIST CSF," and it does not mean an insurer will bind, renew, or pay a claim. If you do not do the thing, answer no or planned. Do not "yes" your way into a warranty you cannot back up.
Start with the free one-pager
Need the written policies too? DIY pack, $147 · Named Pack, $297