Phishing
In one sentence
Fake emails, texts, or sites designed to trick you into revealing passwords or clicking something harmful.
Phishing lures a person into handing over credentials or running malware by imitating a trusted sender. Variants include spear-phishing (targeted), smishing (text), and vishing (voice). Training and email filtering are the main defenses.
Why it's on your cyber insurance application
Applications ask about email filtering and whether you run phishing-awareness training and simulations.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
Security awareness training
How often do employees receive security awareness training?
Why carriers ask: Documented, recurring training is a standard application question and an attestation item. 'We tell people to be careful' does not count as documented.
If the answer is no: Start simple: a 30-minute session this month using ready-made materials, an attendance sheet, and a calendar reminder for next quarter.
Email security
What protections sit in front of your business email?
Why carriers ask: Business email compromise drives more claims than ransomware. Carriers ask what filtering and anti-spoofing protections sit in front of your inbox.
If the answer is no: Move email to Microsoft 365 or Google Workspace if self-hosted; enable their anti-phishing protections and SPF/DKIM/DMARC.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, those documents are:
Guides that cover this
Cybersecurity 101: the basic precautions insurers actually notice
A plain-English starter guide to the cybersecurity basics that move the needle on a cyber insurance application: MFA, EDR, tested backups, patching, email protection, training, and a written incident response plan — most fixable in an afternoon.
The 7 controls every cyber insurance application asks about in 2026
Cyber insurance applications in 2026 require MFA, EDR, tested backups, patching, email security, security awareness training, and a written incident response plan. Here's each requirement, why carriers ask, and what evidence you need before you sign the attestation.
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.