Send Prime 250 Security Assessment

Required if using Register Account V2. Send security assessment responses to Cowbell. Only valid if Register Account V2 response indicates Prime250 product access.

Query Params
boolean

isFormattedError

Body Params
string
required

Account Id

string
required

How often does the organization perform backups of business-critical data? (Allowable values WEEKLY/MONTHLY/QUARTERLY/SIX_MONTHS/NEVER)

boolean

At least 1 is required if backupFrequency answer is not NEVER

string

At least 1 is required if backupFrequency answer is not NEVER

boolean

At least 1 is required if backupFrequency answer is not NEVER

boolean

At least 1 is required if backupFrequency answer is not NEVER

boolean

Only applicable if quote is renewal

string

Only applicable if quote is renewal

boolean
required

Civil or criminal action or administrative proceeding alleging violation of any federal, state, local or common law?

int32
required

Has the Organization filed any claims due to a cyber event? 0=Never, 1=within last 12 months, 2=with last 2 years, 3=within last 3 years, 4=within last 4 years, 5=within 5years or more

boolean

Are all internet-accessible systems (e.g. web, email-servers) segregated from the organization’s trusted network (e.g. within a demilitarized zone (DMZ) or at a third-party service provider)?

boolean
required

Does the organization have an incident response plan - tested and in-effect - setting forth specific action items and responsibilities for relevant parties in the event of cyber incident or data breach matter?

boolean
required

Do policy holder employees authenticate funds transfer requests (e.g. by calling a customer to verify the request at a predetermined phone number)? Affirmative answer is required to be eligible for Social Engineering endorsement

boolean
required

Do policy holder employees prevent unauthorized employees from initiating wire transfers? Affirmative answer is required to be eligible for Social Engineering endorsement

boolean
required

Does the policyholder agree to be the designated Information Security Contact?

boolean
required

Does policyholder provide mandatory information security training to all employees at least annually? If not, are they willing to implement it during the policy period?

boolean
required

Do policy holder employees verify vendor/supplier bank accounts before adding to accounts payable systems. Affirmative answer is required to be eligible for Social Engineering endorsement

boolean
required

During the last three years, has the organization suffered loss of business income as a result of unscheduled system downtime?

boolean
required

Do you enforce Multi-Factor Authentication (MFA) for all employees, contractors, and partners?

boolean

At least 1 is required if mfaAuthentication is true

boolean

At least 1 is required if mfaAuthentication is true

boolean

At least 1 is required if mfaAuthentication is true

string

At least 1 is required if mfaAuthentication is true

boolean

At least 1 is required if mfaAuthentication is true

boolean
required

Had any past Cyber Incidents (Required to be true if claimHistory is answered with value greater than 0)

string
required

Has the organization filed any claims due to a cyber event in last five years? If yes, attach loss detail herewith.

string
required

How often does the organization apply updates to critical IT-systems and applications? Allowable values WEEKLY/MONTHLY/QUARTERLY/SIX_MONTHS/NEVER)

boolean
required

Is there currently any pending litigation, administrative proceeding or claim against the named applicant, organization and/or any of the prospective insureds?

boolean

Only applicable if quote is renewal

string

Only applicable if quote is renewal

boolean
required

During the last three years, has the organization suffered a security breach requiring customer or third-party notification according to state or federal regulations?

boolean

Has the organization tested a full failover of the most critical servers?

boolean

Do agreements with third-party service providers require levels of security commensurate with the organization’s information security standard?

boolean
required

Does the policyholder have sensitive information stored on the cloud?

boolean
required

Does the policyholder encrypt all emails, mobile and computing devices containing sensitive information (e.g., PII, PHI, PCI) sent to external parties?

Responses

400

Bad Request

401

Unauthorized

409

Conflict

Language
URL
Choose an example:
application/json