The renewal questionnaire used to be a checkbox. Now it asks for proof — MFA everywhere, enforced email authentication, tested backups, a named incident-response plan — and it is due whether or not anyone on your team has ever seen a form like it. We score you against the 12 controls insurers actually probe, close the gaps, and hand your broker a page they can act on.
Read-only, enforced by Google and Microsoft — we never hold a password. Call or text (940) 281-6672
A few years ago the cyber-insurance application was a page of yes/no boxes nobody checked. Ransomware losses changed that. Carriers now ask for specifics — is MFA enforced on every account, is there a written incident-response plan, are backups actually tested — and increasingly they verify the answers before they pay a claim, not just before they write the policy.
Churches and small nonprofits are an odd fit for that shift. You hold member directories, giving records, and sometimes payment data — real PII, the same kind a hospital or bank protects — but almost never a paid IT staff person to answer a security questionnaire correctly. The form does not know that. It is due at renewal whether or not anyone on your team has ever seen it before.
That gap is exactly what the Checkup closes: someone who reads these forms for a living tells you, in plain English, where you actually stand — before your renewal date, not after a claim gets denied.
This is the Church & Small-Organization Insurance-Readiness Standard — the same 12 lines your scorecard is measured against. Print the full checklist at /insurance-checklist.html.
| Control | What the insurer is really asking | How Org Guard helps |
|---|---|---|
| 1. MFA on every email account | Can one stolen password alone get an attacker into a mailbox? | We check enforcement, not just availability, and close the gap on Guardian and above. |
| 2. MFA on admin & remote access | Is the console that controls everything else itself protected? | Included in every posture assessment; hardened on Guardian and above. |
| 3. Privileged accounts separated & reviewed | Does one compromised login hand over the whole organization? | We identify who holds admin rights and whether it is reviewed on a schedule; quarterly reviews included on Guardian Plus. |
| 4. Email authentication enforced (SPF/DKIM/DMARC at reject) | Can someone spoof your domain to phish your own members? | We read your published records and move you to enforced p=reject on Guardian and above. |
| 5. Filtering with human-verified alerting | Is targeted fraud — not just bulk spam — actually being caught? | Core to Org Guard: our engine flags, a Security Architect verifies, before you ever hear about it. |
| 6. Encrypted, offline-capable backups, actually tested | If ransomware hits, can you recover without paying? | We check the configuration and test cadence; managed backup with an annual restore test is scoped separately on Guardian Complete. |
| 7. Endpoint protection (EDR) on staff computers | Are the devices reading this email themselves protected? | We check current coverage; managed EDR is scoped separately on Guardian Complete. |
| 8. Written incident-response plan with named roles | Does anyone know what to do in the first hour of an incident? | We help you draft or tighten it; a joint practice run is included on Guardian Complete. |
| 9. Security-awareness training + phishing exercise, at least annually | Are your staff and volunteers the last line of defense, trained? | An annual threat-awareness talk is included from Guardian; an annual phishing simulation is included on Guardian Plus and above. |
| 10. Access reviews at least quarterly | Who can currently touch money, member data, and the admin console? | Quarterly access reviews are included on Guardian Plus and above. |
| 11. Vendor/payout-change verification (call-back procedure) | Would a fraudulent banking-change request actually get caught? | We write the procedure with you and watch for the warning signs that precede these attempts. |
| 12. Known-exploited-vulnerability & breach-exposure watch | Are you watching what attackers are using against organizations like yours this week? | Included in every plan — your domain against the published breach catalogue and CISA's actively-exploited list. |
A one-time assessment built to answer the renewal questionnaire honestly — and to keep answering it, year after year, on Guardian Plus.
Just need the outside-in basics watched — spoofing protection, breach watch, a monthly report — without the full checkup? Org Guard Essentials starts at $99/mo ($79 for churches & nonprofits) and covers up to 10 staff inboxes. For brokers who want to recommend this to their own book of church and nonprofit clients: /insurance-partners.html.
Fifteen minutes on the phone. We ask a handful of questions about how your organization runs and tell you honestly whether the full Checkup is worth it for you right now.
A screen-share to connect read-only access, then an assessment against all 12 controls with evidence quoted for every line.
A prioritized, plain-English list of gaps, walked through with you on a call — what to fix first and why.
A one-page summary built to hand straight to your broker or insurer at renewal.
The concierge repeats the process at every renewal, so the evidence packet is never more than a year stale.
We sit down with it alongside you — reading each question, telling you honestly whether you can answer it truthfully today, and closing the gap when you can't. The signature and the submission stay yours; insurers want the named officer of your organization attesting to the answers, not a vendor doing it for you.
No, and we would not trust anyone who tells you otherwise. Insurer pricing and approval decisions are theirs alone, based on your full application and their own risk appetite. What we can do is prepare the evidence your broker and insurer ask for and help close the gaps most commonly cited in declines — industry guides report proactive controls can be associated with premium reductions of up to about 20%, attributed as an industry pattern, never as our result.
No — ever. Assessment access is read-only, enforced by Google and Microsoft, granted by you from your own admin console, and revocable in one click. We never hold a password.
Alongside them. Your IT company keeps things running; we read your configuration and logs against the 12 controls insurers actually probe and hand you (and your IT company) a specific, evidence-backed fix list instead of a vague renewal-form panic.
The assessment itself runs in the background against your admin console and public records. Expect a screen-share to connect read-only access, then your scorecard, broker page, and fix-list call within about a week.
A one-page, plain-English summary built to be handed to a broker or insurer: which of the 12 controls pass, which have gaps, and the evidence behind each line — not a sales document, a document your broker can act on.
That is the most common starting point, not a disqualifier. The checkup exists to find exactly where you stand and hand you a prioritized order to close the gaps — most organizations we see improve quickly once MFA and email authentication are addressed first.
We are not appointed with any single carrier and we do not sell insurance. The scorecard and broker page are built to be carrier-neutral, so they travel with you to whichever broker or insurer you work with, at this renewal and the next one.
Fifteen minutes on the phone. We'll tell you honestly where you stand against the 12 controls and whether the full Checkup makes sense before your next renewal.
Get your free insurance-readiness snapshotOr simply call — (940) 281-6672 — and talk to the Security Architect directly.
Supports eligibility, underwriting readiness and risk reduction; does not guarantee premiums, coverage, claim payment or insurer approval.