surable

Phishing

In one sentence

Fake emails, texts, or sites designed to trick you into revealing passwords or clicking something harmful.

Phishing lures a person into handing over credentials or running malware by imitating a trusted sender. Variants include spear-phishing (targeted), smishing (text), and vishing (voice). Training and email filtering are the main defenses.

Why it's on your cyber insurance application

Applications ask about email filtering and whether you run phishing-awareness training and simulations.

How the Readiness Check scores it

The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.

Security awareness training

How often do employees receive security awareness training?

Why carriers ask: Documented, recurring training is a standard application question and an attestation item. 'We tell people to be careful' does not count as documented.

If the answer is no: Start simple: a 30-minute session this month using ready-made materials, an attendance sheet, and a calendar reminder for next quarter.

Email security

What protections sit in front of your business email?

Why carriers ask: Business email compromise drives more claims than ransomware. Carriers ask what filtering and anti-spoofing protections sit in front of your inbox.

If the answer is no: Move email to Microsoft 365 or Google Workspace if self-hosted; enable their anti-phishing protections and SPF/DKIM/DMARC.

The written evidence carriers accept

A “yes” on the application needs a document behind it. In the Readiness Pack, those documents are:

Guides that cover this

Related terms

Would you pass this question today?

The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.

← All terms