(602) 677-0779 Book an assessment

Free Assessment ยท Gilbert, Arizona

Your renewal questionnaire is now a technical audit

Cyber insurance used to be a form you signed. It is now an inspection. Carriers want proof of multi factor authentication, endpoint detection and backups that have actually been restored, and they want evidence rather than your word for it.

Get a free assessment

Written findings in two business days. No obligation, and the report is yours to keep.

Or call (602) 677-0779. We reply within one business day, usually the same day.

What you receive

A written report, not a verbal impression

Findings in plain English, each rated red, amber or green, each mapped to the question a carrier, an auditor or a client will eventually ask you.

Alongside it, a fix first list ranked by risk and by what it costs to close, so you can decide what to do now, what to budget for, and what to leave alone.

It costs nothing, takes about 90 minutes, and the report is yours to keep, share with your broker, or hand to the IT provider you already have.

Sample findings

  • MFA enforced, all users and adminsAnswer yes with confidence
  • EDR on serversEndpoints only, answer carefully
  • Backup restore testNo record, fix before signing
  • DMARC at enforcementAnswer yes with confidence
  • Local admin rights6 users, review
  • Written incident response planNone, fix before signing

An illustrative extract. Green means answer yes with confidence. Amber means answer carefully. Red means fix it before you sign anything.

The eight controls showing up on 2026 questionnaires

  • Phishing resistant MFA on every account touching business data: email, VPN, remote desktop, cloud admin consoles, banking and your line of business system. SMS codes are increasingly rejected for privileged accounts.
  • EDR on every endpoint and every server, not legacy antivirus, monitored around the clock.
  • Immutable, isolated, restore tested backups, with the test date documented.
  • Email authentication at enforcement. SPF, DKIM and DMARC set to reject, plus an out of band verification step before anyone wires money.
  • Patch management with records showing it happened.
  • Restricted administrative rights. Not everyone is a local admin.
  • Security awareness training with completion records.
  • A written incident response plan, ideally one you have tested.

Why the gap is usually documentation, not security

  • Most businesses can honestly answer yes to five or six of the eight. The other two or three cost you.
  • A cyber insurance application is a binding attestation. Answering inaccurately, even by accident, can affect whether a policy pays out. Insurers have gone to court over exactly this kind of mismatch between what a business said and what was actually running.
  • The gap between having MFA and being able to prove MFA is enforced everywhere the carrier asked about is where coverage goes to die.

Straight answers

Questions about the assessment

Is this really free, or a sales call with a report attached?

It is free and you keep the report. We do it because a fair share of businesses that see their environment written down decide they want it handled properly. The rest get a useful document and we get a referral later. That maths works for us.

When should we do this?

Thirty to sixty days before your renewal date at minimum. Some fixes take time to deploy and document, and the evidence has to exist before you attest to it. If your renewal is inside two weeks, call rather than fill in the form.

Will you talk to our insurance broker?

Happily. Bring them onto the call. The best outcome is your broker, your IT provider and you looking at the same document a few months before renewal instead of the week of.

Are you an insurance broker?

No. We are a managed IT provider. We tell you what your environment looks like and what carriers are asking for. Your broker advises on coverage, limits and policy language. The two jobs work best together and we are not trying to do theirs.

Do you need admin access to our systems?

For the deepest read, yes, and most of it can be done read only. If you would rather we work from screen shares while your own person drives, that works too. Tell us on the first call.

We are a small office. Do carriers really check?

Increasingly, yes. Questionnaires have got longer for everyone, and small businesses are targeted precisely because attackers assume the controls are weaker. Size does not exempt you from the attestation you signed.

Find out before somebody else does

The worst time to discover a gap is when a claim is being examined. The second worst is the week of renewal.

Orca IT Solutions is a managed IT and cyber security provider, not an insurance broker or agent. This page describes security controls commonly requested on cyber liability applications and is general information, not insurance advice. Requirements vary by carrier, industry and policy. Consult your broker regarding coverage, terms and the accuracy of any application you sign.