Vulnerability scanning
In one sentence
Automated checks that look for known weaknesses across your systems so you can fix them first.
A vulnerability scanner probes your devices and internet-facing services for known weaknesses and reports what to fix. CISA offers free Cyber Hygiene vulnerability scanning to US organizations.
Why it's on your cyber insurance application
Recommending free CISA scanning is a no-cost remediation step that also builds trust.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
Patching & vulnerabilities
How are security updates applied to your systems and software?
Why carriers ask: Unpatched, internet-facing software is now a leading initial-access vector. Applications ask about patch cadence and end-of-life systems specifically.
If the answer is no: Have whoever manages IT produce a list of what's patched automatically vs. manually. That list becomes your patch-management policy's appendix.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.