Start with exposureDescribe the organization the insurer is actually underwriting.
A useful readiness record begins with the business, not a control checklist. Document revenue and operating footprint, workforce and privileged-user counts, customer and regulated data, payment activity, internet-facing services, cloud and software dependencies, remote access, industrial or operational technology, prior incidents, acquisitions, and the maximum tolerable outage for critical services. These facts determine which controls and policy terms matter most.
Map critical services to the technology and suppliers that support them. A payroll platform, identity provider, managed service provider, cloud tenant, payment processor, case-management system, or specialized manufacturer may create a larger loss path than its contract value suggests. Record business owner, technical owner, data handled, administrative access, recovery dependency, and realistic replacement time for each material dependency.
Use a consistent period and scope when answering an application. If one answer describes the parent company, another covers only headquarters, and a third excludes acquired systems without saying so, the completed form may overstate control coverage. Define included entities, networks, cloud accounts, locations, and services before collecting answers, then preserve that scope with the final submission.