Skip to content

Standards & Security Baseline

The security baseline insurers expect, and every business actually needs.

Cyber insurance carriers have made the bar clear. These controls are what it now takes to write or renew a policy, and what a business needs to operate without remaining exposed to constant attack and breach attempts. We build to that standard by default.

3rd Element Consulting holds every client environment to a documented, CIS Controls-aligned security baseline, which is implemented, tested, and evidenced rather than left as a recommendation.

The pattern

This is the bar the market has set.

3rd Element's NOC dashboard showing live monitoring and alert status.

Cyber insurance carriers now ask directly about MFA, email protection, immutable backups, patching, endpoint security, training, and incident response. They ask because these are the controls that consistently determine whether an attack becomes a breach. Our cyber insurance readiness work helps businesses answer those questions with evidence, not assumptions.

The controls are non-negotiable because the risk is not theoretical. Without them, a business is genuinely exposed to constant attack and breach attempts. Our plain-language guide to cyber insurance IT requirements explains what carriers ask for and why. We build every environment to that bar by default. For how the CIS Controls relate to the NIST framework, see CIS Controls vs NIST CSF. To see where your email authentication stands today, run our free Email Security Check.

The six control areas

What the baseline requires.

6 areas, swipe or use arrows

Email Security

A solution that screens and evaluates all email. SPF, DKIM, and DMARC implemented correctly. External emails tagged. MFA enabled.

Authentication & MFA

Each user has a non-shared login, runs least privilege access, and has MFA on all accounts.

Encryption & DLP

Data encrypted in motion and at rest. Data categorized by sensitivity level and monitored for loss prevention.

Backup & Recovery

Backups that test continually, are encrypted, immutable and air-gapped, recover quickly, and are stored off site and/or in the cloud.

Vulnerability Management

Automated patching cadence for endpoints and software. Allow needed software and block all others. Control what software can access.

Security & Training

Security awareness training for all users, endpoint security on all devices, a managed SOC, and Zero Trust principles applied.

How the baseline stays real

The controls only work when someone owns the operation behind them.

  • Identity. MFA everywhere, conditional access, admin role hygiene, and offboarding that actually finishes.
  • Endpoint. Modern endpoint protection, hardening, and patching on every supported device.
  • Microsoft 365. A defined security configuration for tenants we manage, not whatever the defaults happen to be.
  • Backup. Coverage, monitoring, ransomware-aware design, and restore testing on a defined cadence.
  • Monitoring. Alerts handled by people, with documented response procedures.
  • Documentation. Current, accurate documentation of what exists, how it is configured, and who has access.
  • Incident response. A written plan, tested often enough to be real.
  • Review. Quarterly review of the baseline against the environment, with anything out of compliance surfaced to leadership.

The six control areas are the baseline. The work below is how we keep them implemented, monitored, documented, and reviewed instead of letting them become answers on a questionnaire that no longer match the environment.

A 3rd Element technician working in front of the office's core values wall.

The DLP exception

DLP may not be necessary for every business. AI changes that answer.

Data loss prevention is the single item in this baseline that may not be necessary for every client. The moment AI tools enter the environment, DLP becomes necessary. AI gives data another path out of the business, whether through a prompt, an uploaded document, or an integration that can reach more than leadership realizes.

Our AI Readiness and Governance work looks at what tools are already in use, what data they can reach, and what needs to be controlled. The AI Governance briefing explains how policy, enforcement, training, and ownership fit together once AI is part of daily work.

The written plan

Insurers now typically require an incident response plan too.

Technical controls reduce the chance that an attack becomes a breach. A written incident response plan tells the business what happens when something still gets through, who makes decisions, who contacts the carrier, and what happens first. Carriers increasingly expect that plan in addition to the six control areas, and they may ask whether it has been tested.

Use our Incident Response Plan Template as a starting point. For the broader recovery sequence, system priorities, and restore targets, read what an IT disaster recovery plan includes.

Why this matters

A baseline is what makes every security claim honest.

This is not about passing one application and moving on. It is about actually being protected whether an insurer, client, or regulator is checking that day or not. With a maintained baseline, leadership can answer security, insurance, and customer questions from evidence. Without one, every answer depends on what someone assumes is still in place.

Who we work best with

Built for companies that want IT held to a standard.

Something brought you here. If you're with an organization of about 10 to 250 employees, headquartered in or operating across Central PA, that depends on its technology to operate and is ready to hold its IT to a written standard, you've probably outgrown whoever was managing IT before or something specific made the gap visible.

A strong fit

  • Leadership is ready to treat IT as part of how the business runs.
  • Teams tired of explaining the same problems to the same provider.
  • Operations where downtime, lost data, or a security event would put the business at risk.
  • An internal IT person who can't be a specialist in every area and doesn't have visibility into how other organizations solve the same problems.

How we work

  • We price for the outcome, not the lowest monthly rate. If price is the only deciding factor, we're probably not the best match.
  • We'll tell you when something needs attention, even if you didn't ask.
  • Every client runs to a security baseline: MFA, patching, and tested backups. We don't make exceptions, because we're accountable for the result.

Baseline resources

Check the controls. Write the plan.

Use the Microsoft 365 checklist to review a core part of the baseline, then build the written incident response plan cyber insurers increasingly expect.

PDF · Free download

Microsoft 365 Security Best Practices Checklist

The settings most tenants never turn on. Work through it to close the gaps attackers use most often in Microsoft 365.

Download PDF

Common questions

Questions leadership usually asks first.

What if our environment cannot meet a control today?
We document it. If something cannot meet the baseline right now, because of a legacy system, a vendor dependency, or a planned migration, we write it down, note the risk, and build a remediation path. What we do not do is check it off as complete when it is not. Leadership knows what is in place and what is not.
Can we customize the baseline?
The baseline itself is not negotiable because the threats and carrier requirements do not change when a control is inconvenient. What changes based on the business is how it gets implemented and on what timeline. A manufacturing environment looks different from a law firm, but the controls underneath are the same. DLP is the one item that may not be necessary for every client. Once AI tools enter the environment, it becomes necessary. If something genuinely cannot apply, we document why, record the risk, and identify what compensates for it.
Can you help with cyber insurance questions?
Yes. Most insurance applications ask about controls leadership has never had to think about before. We translate the questions, review the environment against them, and help you answer with evidence instead of guesswork. If there are gaps, we'll tell you what they are and what it takes to close them.  We also work with an insurance partner who specializes in cyber coverage - if you want additional options or a second set of eyes on the technical requirements, we can bring them in without replacing your existing broker relationship.
What is an IT Environment Review?
The IT Environment Review is free and takes about 30 minutes by video or phone. We ask a set list of questions about your environment, answer yours, and send you a written summary afterward.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.