← EasyWayIT.com
EasyWayIT — Tampa Bay

The 8-Point Cyber-Insurance &
Contract-Security Check for Contractors

Your carrier and your GCs now require these controls in writing. Score your firm in 4 minutes — before a denied claim, a halted jobsite, or a prequalification review finds the gap.

Applies to: General contractors, subs & trades (Tampa Bay) Updated: 2026 Aligned to: Cyber-insurance application requirements, GC/owner prequalification & subcontract security flow-down
Two things changed for contractors. First, cyber-insurance carriers now require written attestations — MFA, tested backups, an incident-response plan — to issue or renew a policy, and they can deny the claim if the controls you attested to weren't actually in place. Second, more GCs and project owners are flowing security requirements down into subcontracts and prequalification. Ransomware on a contractor halts active jobs, and liquidated-damages clauses start running daily. Tick each box you can honestly say yes to — and confirm what you'd be attesting to is real. Score 1 point each.
1
MFA on email & remote access
  • Multi-factor authentication is on for email, remote access, and any cloud/project systemsThe #1 control on every cyber-insurance application. If even one is a password alone, your attestation is exposed.Most common gap
2
Tested, immutable backups
  • Backups run automatically, are tested, and can't be encrypted by ransomwareA backup nobody has restored from is a guess. Immutable/offline copies are what get a halted jobsite running again.Most common gap
3
A written incident-response plan
  • A written, tested plan covers who you call, how you contain it, and how you notifyCarriers ask for it on the application; a halted project is the worst time to be writing one.
4
Endpoint protection on field + office devices
  • Managed endpoint/antivirus protection runs on every laptop, desktop, and field tabletThe jobsite laptop on public Wi-Fi is as much a way in as the office server.
5
A written information-security policy
  • A short written policy documents how your firm protects its data and systemsThe document a GC's prequalification packet or an insurer asks to see. "We have a guy" isn't a policy.
6
Documented staff security training
  • Office and PM staff completed phishing/security-awareness training this yearMost ransomware starts with one clicked email. With a record you could show a carrier.
7
Vendor / subcontractor data oversight
  • You've confirmed the platforms and partners holding your project data are securedProject-management, accounting, and cloud-storage vendors. Their breach becomes your delay.
8
Your attestation matches reality
  • Everything you've attested to on your cyber-insurance application is actually in place — reviewed in the last 12 monthsThis is the item that decides whether a claim pays. An attestation that doesn't match reality is a denied claim waiting to happen.The signature item
What's at stake — put it on the ledger. This isn't about a fine.
  • A denied cyber-insurance claim — if the attested controls weren't real, the policy you pay for doesn't pay.
  • A halted jobsite — ransomware stops active work while liquidated-damages clauses run daily.
  • Lost prequalification — GCs and owners drop firms that can't prove security from the bidder list.
Self-Assessment Score
Checked items
__ / 8
MFA + tested backups?
Yes  /  No
Date completed
___________
Closing the gaps without becoming an IT expert. Items 1, 2, 3, 4 and 8 are exactly what a managed security provider delivers as a package — the controls and the documentation that satisfies a carrier or a GC — for a fixed $99/computer a month plus $75/month for the documented security program (about $370/month for a small office), against a downside measured in a denied claim or a liquidated-damages week. Scored below 8? Book a 15-minute gap review — no system access; we work from your answers.