← Back

Meridian Medical Group: Security Roadmap

Cyber-Insurance Readiness · Q2 2026 · Prepared by Summit IT Partners

Current readiness: 83 · Strong   6 improvements identified, ordered by how much each one moves the score and how much underwriters care.

Do now Highest-impact gaps. Start these in the next 30 days.
1
Endpoint protection (EDR)no
Is modern EDR (not just legacy antivirus) deployed on all endpoints and servers?
Why it matters: Carriers increasingly mandate EDR on 100% of endpoints; signature AV alone often fails underwriting.
How to fix: Deploy EDR (Defender for Endpoint, CrowdStrike, SentinelOne) fleet-wide with alerting.
Do next Meaningful gaps. Plan these into the next quarter.
1
Multi-factor authenticationpartial
Is MFA required for all administrative and privileged accounts?
Why it matters: Admin account takeover is the highest-impact breach path underwriters probe.
How to fix: Require phishing-resistant MFA for every admin and remove standing global-admin rights.
2
Backupspartial
Are backup restores tested at least quarterly?
Why it matters: Untested backups fail when needed; carriers ask for evidence of test restores.
How to fix: Schedule and document quarterly restore tests.
3
Patch & vulnerability managementno
Do you run regular vulnerability scans of your external footprint?
Why it matters: Exposed, vulnerable services are what attackers and underwriters both look for.
How to fix: Run monthly external vulnerability scans and remediate critical findings.
4
Incident responsepartial
Do you have a written incident response plan?
Why it matters: An IR plan is a common application question and speeds claim response.
How to fix: Document an IR plan with roles, contacts, and step-by-step actions.
Later Lower-impact cleanup. Schedule as time allows.
1
Network securitypartial
Is your network segmented (guest, servers, user VLANs) rather than flat?
Why it matters: Flat networks let attackers move laterally unchecked.
How to fix: Segment critical systems and restrict lateral traffic.
This readiness report is an educational self-assessment based on the CIS Controls (IG1) and security controls commonly requested by cyber-insurance underwriters. It is not insurance, legal, or professional advice, does not guarantee eligibility for or approval of any insurance policy, and is not affiliated with or endorsed by any insurance carrier. Coverage decisions rest solely with underwriters. Verify all responses with a qualified professional.