Standards & Security Baseline
The security baseline insurers expect, and every business actually needs.
Cyber insurance carriers have made the bar clear. These controls are what it now takes to write or renew a policy, and what a business needs to operate without remaining exposed to constant attack and breach attempts. We build to that standard by default.
3rd Element Consulting holds every client environment to a documented, CIS Controls-aligned security baseline, which is implemented, tested, and evidenced rather than left as a recommendation.
The pattern
This is the bar the market has set.

Cyber insurance carriers now ask directly about MFA, email protection, immutable backups, patching, endpoint security, training, and incident response. They ask because these are the controls that consistently determine whether an attack becomes a breach. Our cyber insurance readiness work helps businesses answer those questions with evidence, not assumptions.
The controls are non-negotiable because the risk is not theoretical. Without them, a business is genuinely exposed to constant attack and breach attempts. Our plain-language guide to cyber insurance IT requirements explains what carriers ask for and why. We build every environment to that bar by default. For how the CIS Controls relate to the NIST framework, see CIS Controls vs NIST CSF. To see where your email authentication stands today, run our free Email Security Check.
The six control areas
What the baseline requires.
6 areas, swipe or use arrows
Email Security
A solution that screens and evaluates all email. SPF, DKIM, and DMARC implemented correctly. External emails tagged. MFA enabled.
Authentication & MFA
Each user has a non-shared login, runs least privilege access, and has MFA on all accounts.
Encryption & DLP
Data encrypted in motion and at rest. Data categorized by sensitivity level and monitored for loss prevention.
Backup & Recovery
Backups that test continually, are encrypted, immutable and air-gapped, recover quickly, and are stored off site and/or in the cloud.
Vulnerability Management
Automated patching cadence for endpoints and software. Allow needed software and block all others. Control what software can access.
Security & Training
Security awareness training for all users, endpoint security on all devices, a managed SOC, and Zero Trust principles applied.
How the baseline stays real
The controls only work when someone owns the operation behind them.
- Identity. MFA everywhere, conditional access, admin role hygiene, and offboarding that actually finishes.
- Endpoint. Modern endpoint protection, hardening, and patching on every supported device.
- Microsoft 365. A defined security configuration for tenants we manage, not whatever the defaults happen to be.
- Backup. Coverage, monitoring, ransomware-aware design, and restore testing on a defined cadence.
- Monitoring. Alerts handled by people, with documented response procedures.
- Documentation. Current, accurate documentation of what exists, how it is configured, and who has access.
- Incident response. A written plan, tested often enough to be real.
- Review. Quarterly review of the baseline against the environment, with anything out of compliance surfaced to leadership.
The six control areas are the baseline. The work below is how we keep them implemented, monitored, documented, and reviewed instead of letting them become answers on a questionnaire that no longer match the environment.

The DLP exception
DLP may not be necessary for every business. AI changes that answer.
Data loss prevention is the single item in this baseline that may not be necessary for every client. The moment AI tools enter the environment, DLP becomes necessary. AI gives data another path out of the business, whether through a prompt, an uploaded document, or an integration that can reach more than leadership realizes.
Our AI Readiness and Governance work looks at what tools are already in use, what data they can reach, and what needs to be controlled. The AI Governance briefing explains how policy, enforcement, training, and ownership fit together once AI is part of daily work.
The written plan
Insurers now typically require an incident response plan too.
Technical controls reduce the chance that an attack becomes a breach. A written incident response plan tells the business what happens when something still gets through, who makes decisions, who contacts the carrier, and what happens first. Carriers increasingly expect that plan in addition to the six control areas, and they may ask whether it has been tested.
Use our Incident Response Plan Template as a starting point. For the broader recovery sequence, system priorities, and restore targets, read what an IT disaster recovery plan includes.
Why this matters
A baseline is what makes every security claim honest.
This is not about passing one application and moving on. It is about actually being protected whether an insurer, client, or regulator is checking that day or not. With a maintained baseline, leadership can answer security, insurance, and customer questions from evidence. Without one, every answer depends on what someone assumes is still in place.
Who we work best with
Built for companies that want IT held to a standard.
Something brought you here. If you're with an organization of about 10 to 250 employees, headquartered in or operating across Central PA, that depends on its technology to operate and is ready to hold its IT to a written standard, you've probably outgrown whoever was managing IT before or something specific made the gap visible.
A strong fit
- Leadership is ready to treat IT as part of how the business runs.
- Teams tired of explaining the same problems to the same provider.
- Operations where downtime, lost data, or a security event would put the business at risk.
- An internal IT person who can't be a specialist in every area and doesn't have visibility into how other organizations solve the same problems.
How we work
- We price for the outcome, not the lowest monthly rate. If price is the only deciding factor, we're probably not the best match.
- We'll tell you when something needs attention, even if you didn't ask.
- Every client runs to a security baseline: MFA, patching, and tested backups. We don't make exceptions, because we're accountable for the result.
Baseline resources
Check the controls. Write the plan.
Use the Microsoft 365 checklist to review a core part of the baseline, then build the written incident response plan cyber insurers increasingly expect.
Common questions
Questions leadership usually asks first.
What if our environment cannot meet a control today?
Can we customize the baseline?
Can you help with cyber insurance questions?
What is an IT Environment Review?
Continue reading
Related work and reading.
Client Story: The Acquisition IT Work That Keeps Coming Back
The baseline is what each newly acquired site gets brought up to, which is what makes the integration repeatable.
Read more: Client Story: The Acquisition IT Work That Keeps Coming BackClient Story: One Company, One Standard, Across Every Office
What it looks like when every office, in every country, is held to the same documented baseline.
Read more: Client Story: One Company, One Standard, Across Every OfficeCyber Insurance Readiness
Translate carrier questions into controls and evidence before renewal or claim time.
Read more: Cyber Insurance ReadinessCyber Insurance IT Requirements
What carriers are asking for, what they verify, and why each control matters.
Read more: Cyber Insurance IT RequirementsAI Readiness & Governance
The data, access, policy, and DLP decisions that become necessary when AI enters the environment.
Read more: AI Readiness & GovernanceAI Governance Briefing
How written policy, technical enforcement, training, and ownership work together.
Read more: AI Governance BriefingIT Disaster Recovery Plan
The written recovery sequence that turns backups and responsibilities into a workable response.
Read more: IT Disaster Recovery PlanManaged IT Services
The ongoing ownership that keeps the baseline in place and produces evidence over time.
Read more: Managed IT ServicesNext step
Get a clearer view of your IT environment.
Find out what is working, where the risks are, and what needs attention next.
