Free · print it · hand it to your board

The 12 controls your cyber-insurer will ask about.

This is a self-check a treasurer or administrator can complete in about 20 minutes, using settings you already have access to. It is also the exact standard Org Guard's Cyber-Insurance Readiness Checkup scores your organization against - so if you complete it here first, you'll already know roughly where you stand before anyone else looks.

A 20-minute self-check for board members, treasurers, and administrators.

The Church & Small-Organization Insurance-Readiness Standard

Work through these 12 controls in order. For each one, check the box if you can honestly answer yes today - not "we plan to." Where you can, jot down the evidence (a screenshot, a policy date, a report) so it's ready if your broker asks.

  1. 1. MFA on every email account

    What it means: Every staff and volunteer email account requires a second step to sign in - a code or approval on a phone - not just a password.

    Check it yourself in 5 minutes: In your Google Workspace or Microsoft 365 admin console, look for a security or MFA policy report showing enrollment across all users, not just admins.

    Why insurers ask: Industry surveys report most carriers now require enforced MFA on email and remote access, and MFA gaps are among the most common reasons applications are declined.

  2. 2. MFA on admin and remote access

    What it means: The admin console itself, and any way to log in from outside the building (VPN, remote desktop), also requires MFA - not just regular mailboxes.

    Check it yourself in 5 minutes: Try signing into the admin console from a new device and confirm you're prompted for a second factor before regular mailbox users would be.

    Why insurers ask: Admin and remote-access accounts are the highest-value target - one compromised admin account can affect every mailbox at once.

  3. 3. Privileged accounts separated and reviewed

    What it means: The people who use email day-to-day for their own work don't also hold admin rights on their everyday account - admin access lives on a separate, reviewed account.

    Check it yourself in 5 minutes: List everyone with admin rights in your console. If it's more people than you expected, or includes someone who left, that's the gap.

    Why insurers ask: A daily-use account with admin rights is a single point of failure - one phished password becomes full control of the domain.

  4. 4. Email authentication enforced (SPF, DKIM, DMARC at reject)

    What it means: Your domain publishes rules that let other mail systems verify a message really came from you, and instructs them to reject anything that fails - not just flag it.

    Check it yourself in 5 minutes: Use a free DMARC lookup tool with your domain name and check whether the policy reads p=reject rather than p=none or p=quarantine.

    Why insurers ask: Without enforcement, anyone can send email that appears to come from your organization - a common vector in vendor and donor fraud.

  5. 5. Email filtering with human-verified alerting for targeted fraud

    What it means: Beyond spam filtering, someone actually looks at flagged messages that could be targeted scams - not just an automated rule that silently deletes them.

    Check it yourself in 5 minutes: Ask whoever manages your email: when a suspicious message is flagged, who sees it, and how quickly?

    Why insurers ask: Targeted fraud (fake invoices, wire-change requests) rarely trips spam filters - it needs a person, or a monitoring service, actually reviewing it.

  6. 6. Encrypted, offline-capable backups that are actually tested

    What it means: Your data is backed up somewhere an attacker with access to your live systems can't also delete, and someone has actually confirmed a restore works.

    Check it yourself in 5 minutes: Find the date of your last successful test restore. If nobody can produce one, this is a gap even if backups are technically running.

    Why insurers ask: Ransomware claims are frequently denied or reduced when backups exist on paper but were never verified to actually restore.

  7. 7. Endpoint protection (EDR) on staff computers

    What it means: Computers used for church or organization business run active protection software that can detect and stop malicious activity, not just built-in antivirus left on default settings.

    Check it yourself in 5 minutes: List the computers used for finance or admin work and confirm each one shows an active, updated protection product.

    Why insurers ask: Endpoint protection is a baseline expectation on most applications, and its absence on finance-adjacent machines is a frequent red flag.

  8. 8. A written incident-response plan with named roles

    What it means: A short document exists saying who does what if something goes wrong - who calls the bank, who calls the insurer, who talks to the congregation or members.

    Check it yourself in 5 minutes: Ask to see the plan. If it doesn't exist, or nobody knows where it is, that's the gap.

    Why insurers ask: A named, rehearsed plan measurably shortens response time and loss - insurers ask for it because it changes outcomes, not just paperwork.

  9. 9. Security-awareness training at least annually, plus a phishing exercise

    What it means: Staff and key volunteers get some form of training on scams at least once a year, and have been through at least one practice phishing test.

    Check it yourself in 5 minutes: Check the date of the last training session and whether a phishing exercise has ever been run.

    Why insurers ask: People, not software, catch most targeted scams - insurers treat training as evidence the organization takes that seriously.

  10. 10. Access reviews at least quarterly

    What it means: Someone periodically checks who can touch money, sensitive data, and the admin console, and removes access for people who no longer need it.

    Check it yourself in 5 minutes: Find the date of the last access review. If it predates a staff or volunteer departure, that's the gap.

    Why insurers ask: Old access left in place after someone leaves is one of the most common ways an incident starts.

  11. 11. Vendor and payout-change verification procedure

    What it means: Before acting on any request to change bank details for a vendor, contractor, or payee, someone calls a known phone number to confirm it - never a number or link from the request itself.

    Check it yourself in 5 minutes: Ask your bookkeeper: the last time a vendor's bank details changed, did anyone call to confirm it, and is that written down as a rule?

    Why insurers ask: Vendor and payout-change fraud is one of the most common and most costly claims - a written call-back rule is the single most effective control against it.

  12. 12. Known-exploited-vulnerability and breach-exposure watch

    What it means: Someone or something is watching whether your domain, email addresses, or public-facing services show up in breach data or have known, actively-exploited software vulnerabilities.

    Check it yourself in 5 minutes: Search your organization's domain on a free breach-checking site and note the date of your last check.

    Why insurers ask: Exposed credentials and unpatched, actively-exploited software are common entry points, and insurers increasingly ask whether anyone is watching for them.

How to read your result

12 / 12Renewal-ready. Keep your evidence organized and revisit this list before every renewal.
9–11A few documented gaps. Normal at this stage - write down what's missing and a rough timeline to close it.
Under 9Expect questions from your broker or insurer. Start with MFA and tested backups - those two close the most ground fastest.

There is no fixed passing score here - insurers weigh these controls differently by carrier and policy. The point of this checklist is simply to know where you stand before someone else asks.

Email me the printable PDF

Get this checklist as a worksheet you can print, hand to your board, and fill in with a pen.

Where Org Guard fits

Working through this list yourself tells you roughly where you stand. Org Guard's Cyber-Insurance Readiness Checkup ($750, one-time) does the same 12-control scorecard against your actual Google Workspace or Microsoft 365 setup - each line marked pass, gap, or evidence quoted - plus a one-page broker-ready summary and a prioritized fix list walked through on a call.

If you'd rather have ongoing monitoring instead of a one-time snapshot, see Org Guard's plans & pricing, including the Guardian Plus "Insurance Ready" tier built around renewal season.

Supports eligibility, underwriting readiness and risk reduction; does not guarantee premiums, coverage, claim payment or insurer approval.

Common questions

Is this checklist the same standard Org Guard scores against?

Yes. These are the same 12 controls used in Org Guard's Cyber-Insurance Readiness Checkup, which scores each one pass, gap, or evidence-needed against your actual Google Workspace or Microsoft 365 setup. This page is the self-check version you can do yourself first.

Do we need to pass all 12 to get cyber insurance?

No. Most carriers focus first on a handful of controls, especially MFA on email and tested backups. Passing fewer than 12 does not mean you are uninsurable, but it does mean expect follow-up questions from your broker or insurer, and it helps to have documented answers ready.

We do not have an IT department. Can we still complete this?

Yes. Every check on this list is written to be answered by a treasurer, administrator, or volunteer in about five minutes, using the settings screens you already have access to in Google Workspace or Microsoft 365 — no technical background required.

How long does the self-check actually take?

About 20 minutes for all 12 controls if you already know your admin login. A few items, like reviewing who has admin access, may take a little longer the first time you do them.

Does completing this checklist guarantee lower premiums or approval?

No. This checklist supports eligibility, underwriting readiness, and risk reduction. It does not guarantee premiums, coverage, claim payment, or insurer approval — those decisions remain with your insurer and broker.