Two things changed for contractors. First, cyber-insurance carriers now require written attestations — MFA, tested backups, an incident-response plan — to issue or renew a policy, and they can deny the claim if the controls you attested to weren't actually in place. Second, more GCs and project owners are flowing security requirements down into subcontracts and prequalification. Ransomware on a contractor halts active jobs, and liquidated-damages clauses start running daily. Tick each box you can honestly say yes to — and confirm what you'd be attesting to is real. Score 1 point each.
Multi-factor authentication is on for email, remote access, and any cloud/project systemsThe #1 control on every cyber-insurance application. If even one is a password alone, your attestation is exposed.Most common gap
Backups run automatically, are tested, and can't be encrypted by ransomwareA backup nobody has restored from is a guess. Immutable/offline copies are what get a halted jobsite running again.Most common gap
A written, tested plan covers who you call, how you contain it, and how you notifyCarriers ask for it on the application; a halted project is the worst time to be writing one.
What's at stake — put it on the ledger. This isn't about a fine.
- A denied cyber-insurance claim — if the attested controls weren't real, the policy you pay for doesn't pay.
- A halted jobsite — ransomware stops active work while liquidated-damages clauses run daily.
- Lost prequalification — GCs and owners drop firms that can't prove security from the bidder list.
MFA + tested backups?
Yes / No
Date completed
___________
- 8 / 8Rare. Your attestation is honest and your pipeline is protected. Keep the annual review current.
- 5–7Partially covered — but the gaps are exactly the ones a carrier checks after a claim and a GC screens for. Usually a few days of work to close.
- 2–4Typical, and exposed. If you've attested "yes" on these, a claim is at real risk. Fixable, but it needs a real plan.
- 0–1High risk. A denied claim or a halted project would land squarely here. This should be the priority.
Closing the gaps without becoming an IT expert. Items 1, 2, 3, 4 and 8 are exactly what a managed security provider delivers as a package — the controls
and the documentation that satisfies a carrier or a GC — for a fixed
$99/computer a month plus $75/month for the documented security program (about
$370/month for a small office), against a downside measured in a denied claim or a liquidated-damages week. Scored below 8?
Book a 15-minute gap review — no system access; we work from your answers.