Cyber Readiness Report Card
Use this interactive tool to review cyber policy clarity across coverage questions, carrier services, first-party coverage, and third-party coverage before renewal or a policy review conversation.
Not started
Start by answering the policy review questions below. The result will show whether your cyber policy clarity looks healthy, needs work, or needs attention.
Key coverage offerings and carrier services
Start with the major cyber events and carrier response services you may expect from the policy.
Does the policy address losses stemming from data breaches?
Does the policy address losses from cyberattacks on company systems and networks?
Does the policy address losses stemming from third-party cyberattacks?
Does the policy address losses from domestic and international cyberattacks?
Does the policy address cyberwarfare, terrorism, or related exclusions clearly enough for review?
Will the carrier assist with defending lawsuits or regulatory investigations tied to cyber incidents?
Does the carrier provide a 24/7 data breach or cyber incident helpline?
Is there an option to supplement cyber coverage with excess limits when appropriate?
First-party coverage components
These items relate to costs your organization may face directly after a cyber incident.
Does the policy include legal counsel to help assess breach notification and regulatory obligations?
Does the policy include recovery or replacement of lost, stolen, or compromised data?
Does the policy include notification and call center services after a cyber incident?
Does the policy include lost income from business interruption caused by a cyber incident?
Does the policy include crisis management or public relations services during a cyber incident?
Does the policy include cyber extortion, ransomware, or fraud-related loss review?
Does the policy include forensic services to investigate cyber incidents?
Does the policy address fees, fines, penalties, or regulatory costs related to cyber incidents?
Third-party coverage components
These items relate to claims, disputes, or costs involving customers, vendors, regulators, or other outside parties.
Does the policy include payments to individuals impacted by cyber incidents?
Does the policy include claim, settlement, or judgment costs tied to cyber-related disputes or lawsuits?
Does the policy address defamation, copyright, or trademark infringement allegations connected to cyber incidents?
Does the policy include litigation expenses and responses to regulatory inquiries?
Does the policy include accounting costs associated with cyber incidents?
Do you know which exclusions, sublimits, waiting periods, or retention amounts could affect a cyber claim?
Your Cyber Policy Review Guidance
Answer the questions above to generate practical review guidance.
Section guidance
- Complete the report card to see which coverage sections are healthy, need work, or need attention.
Potential gaps to review
- No “No” responses selected yet.
Questions to confirm
- No “Not sure” responses selected yet.
This report card is provided for general educational and risk management discussion purposes only. It is not legal, cybersecurity, claims, or coverage advice. It does not amend, interpret, or determine coverage under any insurance policy. Coverage depends on the specific policy language, facts, exclusions, limits, sublimits, retentions, endorsements, and applicable law. Review all cyber insurance questions with qualified professionals.