THE INSURANCE EVIDENCE FOLDER — smallteamstack.com/templates/insurance-evidence-folder/ Companion to the Cyber-Insurance Readiness Guide. Educational, not insurance or legal advice. Setup: create a folder named insurance-evidence/ with one subfolder per control. Date every file (e.g. 2026-07-mfa-policy.png). Refresh screenshots at renewal. == 1. MFA ON EMAIL (the pass/fail item) == [ ] Screenshot: MFA enforcement policy in the Workspace/M365 admin console [ ] Screenshot: user list showing every account enrolled [ ] Date enforced + who verified it == 2. MFA ON ADMIN ACCOUNTS & REMOTE ACCESS == [ ] Screenshot per platform: admin account security settings showing MFA on [ ] If no VPN/servers: one line stating "no remote-access infrastructure" == 3. PASSWORD MANAGER / UNIQUE PASSWORDS == [ ] Screenshot: member list in the password manager admin view [ ] One line: which plan, since when == 4. BACKUPS — MAINTAINED, SEPARATED, TESTED == [ ] Screenshot: backup dashboard showing last successful backup [ ] Dated note of last restore test: what, how long, result [ ] One line: what is backed up and where it lives == 5. ENDPOINT PROTECTION == [ ] Screenshot per device type: Defender/XProtect status or endpoint console [ ] One line: auto-update policy for OS and browsers == 6. SECURITY-AWARENESS TRAINING == [ ] Dated agenda of the last training session (a documented 30-minute all-hands counts) [ ] The one-pager handed out == 7. DEPARTED-EMPLOYEE ACCESS REMOVAL == [ ] Written offboarding checklist (generator: smallteamstack.com/tools/offboarding-checklist/) [ ] Audit-log entries from the most recent departure == 8. INCIDENT-RESPONSE PLAN & CONTACTS == [ ] One-page contact sheet: who to call (IT help, broker/carrier hotline, bank), who decides, where backups are [ ] Check your policy's notice requirements — many carriers require calling them first THE HONESTY RULE: applications are legal documents; misstatements are the classic reason claims get denied. An accurate "no — planned for Q4" is safer than an optimistic "yes."