This is a self-check a treasurer or administrator can complete in about 20 minutes, using settings you already have access to. It is also the exact standard Org Guard's Cyber-Insurance Readiness Checkup scores your organization against - so if you complete it here first, you'll already know roughly where you stand before anyone else looks.
Work through these 12 controls in order. For each one, check the box if you can honestly answer yes today - not "we plan to." Where you can, jot down the evidence (a screenshot, a policy date, a report) so it's ready if your broker asks.
What it means: Every staff and volunteer email account requires a second step to sign in - a code or approval on a phone - not just a password.
Check it yourself in 5 minutes: In your Google Workspace or Microsoft 365 admin console, look for a security or MFA policy report showing enrollment across all users, not just admins.
Why insurers ask: Industry surveys report most carriers now require enforced MFA on email and remote access, and MFA gaps are among the most common reasons applications are declined.
What it means: The admin console itself, and any way to log in from outside the building (VPN, remote desktop), also requires MFA - not just regular mailboxes.
Check it yourself in 5 minutes: Try signing into the admin console from a new device and confirm you're prompted for a second factor before regular mailbox users would be.
Why insurers ask: Admin and remote-access accounts are the highest-value target - one compromised admin account can affect every mailbox at once.
What it means: The people who use email day-to-day for their own work don't also hold admin rights on their everyday account - admin access lives on a separate, reviewed account.
Check it yourself in 5 minutes: List everyone with admin rights in your console. If it's more people than you expected, or includes someone who left, that's the gap.
Why insurers ask: A daily-use account with admin rights is a single point of failure - one phished password becomes full control of the domain.
What it means: Your domain publishes rules that let other mail systems verify a message really came from you, and instructs them to reject anything that fails - not just flag it.
Check it yourself in 5 minutes: Use a free DMARC lookup tool with your domain name and check whether the policy reads p=reject rather than p=none or p=quarantine.
Why insurers ask: Without enforcement, anyone can send email that appears to come from your organization - a common vector in vendor and donor fraud.
What it means: Beyond spam filtering, someone actually looks at flagged messages that could be targeted scams - not just an automated rule that silently deletes them.
Check it yourself in 5 minutes: Ask whoever manages your email: when a suspicious message is flagged, who sees it, and how quickly?
Why insurers ask: Targeted fraud (fake invoices, wire-change requests) rarely trips spam filters - it needs a person, or a monitoring service, actually reviewing it.
What it means: Your data is backed up somewhere an attacker with access to your live systems can't also delete, and someone has actually confirmed a restore works.
Check it yourself in 5 minutes: Find the date of your last successful test restore. If nobody can produce one, this is a gap even if backups are technically running.
Why insurers ask: Ransomware claims are frequently denied or reduced when backups exist on paper but were never verified to actually restore.
What it means: Computers used for church or organization business run active protection software that can detect and stop malicious activity, not just built-in antivirus left on default settings.
Check it yourself in 5 minutes: List the computers used for finance or admin work and confirm each one shows an active, updated protection product.
Why insurers ask: Endpoint protection is a baseline expectation on most applications, and its absence on finance-adjacent machines is a frequent red flag.
What it means: A short document exists saying who does what if something goes wrong - who calls the bank, who calls the insurer, who talks to the congregation or members.
Check it yourself in 5 minutes: Ask to see the plan. If it doesn't exist, or nobody knows where it is, that's the gap.
Why insurers ask: A named, rehearsed plan measurably shortens response time and loss - insurers ask for it because it changes outcomes, not just paperwork.
What it means: Staff and key volunteers get some form of training on scams at least once a year, and have been through at least one practice phishing test.
Check it yourself in 5 minutes: Check the date of the last training session and whether a phishing exercise has ever been run.
Why insurers ask: People, not software, catch most targeted scams - insurers treat training as evidence the organization takes that seriously.
What it means: Someone periodically checks who can touch money, sensitive data, and the admin console, and removes access for people who no longer need it.
Check it yourself in 5 minutes: Find the date of the last access review. If it predates a staff or volunteer departure, that's the gap.
Why insurers ask: Old access left in place after someone leaves is one of the most common ways an incident starts.
What it means: Before acting on any request to change bank details for a vendor, contractor, or payee, someone calls a known phone number to confirm it - never a number or link from the request itself.
Check it yourself in 5 minutes: Ask your bookkeeper: the last time a vendor's bank details changed, did anyone call to confirm it, and is that written down as a rule?
Why insurers ask: Vendor and payout-change fraud is one of the most common and most costly claims - a written call-back rule is the single most effective control against it.
What it means: Someone or something is watching whether your domain, email addresses, or public-facing services show up in breach data or have known, actively-exploited software vulnerabilities.
Check it yourself in 5 minutes: Search your organization's domain on a free breach-checking site and note the date of your last check.
Why insurers ask: Exposed credentials and unpatched, actively-exploited software are common entry points, and insurers increasingly ask whether anyone is watching for them.
There is no fixed passing score here - insurers weigh these controls differently by carrier and policy. The point of this checklist is simply to know where you stand before someone else asks.
Get this checklist as a worksheet you can print, hand to your board, and fill in with a pen.
Working through this list yourself tells you roughly where you stand. Org Guard's Cyber-Insurance Readiness Checkup ($750, one-time) does the same 12-control scorecard against your actual Google Workspace or Microsoft 365 setup - each line marked pass, gap, or evidence quoted - plus a one-page broker-ready summary and a prioritized fix list walked through on a call.
If you'd rather have ongoing monitoring instead of a one-time snapshot, see Org Guard's plans & pricing, including the Guardian Plus "Insurance Ready" tier built around renewal season.
Supports eligibility, underwriting readiness and risk reduction; does not guarantee premiums, coverage, claim payment or insurer approval.
Yes. These are the same 12 controls used in Org Guard's Cyber-Insurance Readiness Checkup, which scores each one pass, gap, or evidence-needed against your actual Google Workspace or Microsoft 365 setup. This page is the self-check version you can do yourself first.
No. Most carriers focus first on a handful of controls, especially MFA on email and tested backups. Passing fewer than 12 does not mean you are uninsurable, but it does mean expect follow-up questions from your broker or insurer, and it helps to have documented answers ready.
Yes. Every check on this list is written to be answered by a treasurer, administrator, or volunteer in about five minutes, using the settings screens you already have access to in Google Workspace or Microsoft 365 — no technical background required.
About 20 minutes for all 12 controls if you already know your admin login. A few items, like reviewing who has admin access, may take a little longer the first time you do them.
No. This checklist supports eligibility, underwriting readiness, and risk reduction. It does not guarantee premiums, coverage, claim payment, or insurer approval — those decisions remain with your insurer and broker.