Skip to content
HIFENCE

Cyber Insurance: How to Prepare Your Company in 30 Days Before Requesting a Quote

Picture of Daniel Sarica, the founder of HIFENCE. Daniel Sarica

Published: June 24, 2026

Before you ever get to price, coverage, and exclusions, a cyber insurance conversation makes you explain, concretely, where your company stands on backup, access, vendors, and incident response. And that is often where the areas long left to assumption come to the surface.

Here is the practical part: how to get these things in order, without a big project. This is not a technology shopping list. It is a handful of checks that management should be able to see in one place, and that you can complete in about a month, with no sales pressure.

One thing to say up front: the goal is not to tick a form, it is to know where you stand. The same checks reduce your real risk, help you in a conversation with a large customer or in a compliance effort like SOC 2, and make an eventual insurance conversation much simpler.


What to check, concretely, area by area

Backup and recovery

The question is not “do we have backups?” but “how fast and how completely can we come back?”. To find out, run a real restore test, not just a check that the backup job ran:

  • Pick a set of data that truly matters (a folder from the ERP, a database, production files), not a test file.
  • Restore it to a separate location, without overwriting live data.
  • Time it: how long from “we decide to restore” to “the data is usable”.
  • Verify the restored data — it opens, it is complete, and note how recent it is.

From this test you learn two things management should know: how old the most recent backup is (how much data you would lose) and how long recovery takes (how long you would be down). Also check whether there is an isolated copy that ransomware cannot reach — if your backups sit on the same network, with the same passwords, they can be encrypted along with everything else. And write down what does NOT go into the backup; something usually slips through: local laptops, a SaaS application, some configurations.

Access

A quick review, not a months-long project. Take the critical systems (email, ERP, CRM, file shares, finance, production) and, for each one, clear up three things:

  • Who has access and, separately, who has administrator access.
  • Are there old accounts still open (people who left, contractors whose projects ended)? Compare the list of active accounts against the list of active employees.
  • Are there administrator passwords shared among several people, which you cannot attribute to anyone?

Check remote access separately: who can connect from outside, and whether it is protected with two-factor authentication. Close what is old or unnecessary, and note who approved what stays. It does not have to be perfect; it has to be clear.

Vendors

Many companies look at employees, but less at third parties with access. Make a simple list: the IT provider, the accountant, the agency, the consultants, the software platforms, the integrators. For each one with access to data or systems:

  • What access they have and why.
  • Who approved it and when it was last reviewed.

Flag the ones with broad or privileged access — the IT provider with administrator rights, the platform with access to your data. For the most important ones, ask them the same basic things you check for yourself (backup, access, what they do in an incident). A vendor with access is part of your risk surface, even if you have worked with them for years.

Incident response

Not a long plan. One page, kept accessible and offline (a document sitting on the system that just went down does you no good):

  • Who decides to shut systems down, to notify.
  • Contact numbers: internal IT, IT provider, broker or insurer (if you have one), attorney, leadership.
  • First steps: isolate the affected systems, preserve evidence, delete nothing, pay nothing without advice.
  • Who communicates internally, and when notifying customers or authorities comes into play (for personal data, under state breach notification laws).

Its purpose is simple: in the first hours of an incident, decisions improvised on the spot cost time. One clear page removes half the hesitation.


Answers to avoid

The most expensive answer is checking a box you cannot prove. “We have MFA everywhere,” “the backup is tested” — if these end up in a customer contract or an insurance application and do not match reality, they become contractual and legal exposure, not just a technical gap. And they surface at exactly the wrong moment: at a claim or an audit.

The difference that matters is not between “we have everything” and “we have nothing”. It is between “we don’t know” and “we know what’s missing and have a plan”. The second is perfectly acceptable in a serious conversation. The first is not.

Also avoid the answers that look like answers but are not: “we have IT” to the question of who has access to what; “we’ve worked with them for years” to the question of what risk a vendor brings.


The 30-day plan

Week by week, so it does not turn into a project:

Week 1: Inventory. The list of critical systems, who administers each one, and what stops if it goes down.
Week 2: Backup. A real restore test, with the times written down, plus checking for an isolated copy and for what is not in the backup.
Week 3: Access and vendors. The access review (old accounts, administrators, remote access, shared passwords) and the list of vendors with access.
Week 4: Incident and gaps. The incident page, plus a short list of the uncertain areas and what you will improve next.

At the end you have something that never existed in one place before: a clear picture of what you have, what you do not, what you have tested, and what comes next. That, in fact, is “prepared”.


What can wait for later

Not everything has to be solved this month. These can wait: formal written policies beyond the bare minimum, certifications (SOC 2, ISO 27001, and the like), more advanced tooling. These cannot wait, because recovering and answering honestly depend on them: the tested backup, the clear picture of access, the incident page, and the list of your gaps.
In other words, prioritize by two criteria: what gets you back up after an incident, and what you can prove. The rest comes after.


When outside help makes sense

Many companies have an IT team of one to three people, busy with the day-to-day. Stacked on top of that, these checks are hard to fit in — not because they are complicated, but because they require dedicated time and a role that formally does not exist: someone to hold the complete picture.

This is where an outside partner helps: to run the restore test properly, to get the access review done in a week instead of months, to put the incident page together, and to be a second pair of eyes on the gaps. Not instead of your team — alongside it. This is where we can help with cybersecurity services.

At HIFENCE we do exactly this preparation, together with your internal team: we get the backup, access, vendors, and incident response in order, and give you a clear picture of what you can prove. If you are preparing for a cyber insurance conversation (or simply want to know where you stand before someone else asks), write to us at office@hifence.com.