Cyber insurance & attestation
Your renewal hinges on controls you are not sure you have
The carrier questionnaire asks whether you enforce phishing-resistant MFA, keep admin rights limited, run endpoint detection on every machine, and prove your backups restore. Answer wrong and the premium jumps or coverage is denied. Answer "we think so" and you are exposed the day you actually need to claim.
What this looks like in real life
A 60-person engineering firm got its cyber-insurance renewal questionnaire three weeks before the policy lapsed. The form asked, in plain yes-or-no boxes, whether every admin used phishing-resistant MFA, whether privileged access was time-bound, and whether backups had been test-restored. The IT lead had rolled out MFA "for most people" two years earlier and genuinely did not know the rest. Tick the wrong box and a future claim could be denied; answer honestly and the premium could jump or coverage vanish.
What was at risk
- A renewal answer the firm could not actually stand behind at claim time.
- Global admin accounts with standing access and no documented MFA enforcement.
- A broker waiting on answers with the policy days from lapsing.
What the engagement produced
An Identity Secure Score, every carrier control mapped to met or gap with the evidence attached, and a short remediation list that closed the three real gaps before the renewal date, so the questionnaire could be answered with proof instead of a guess.
The fixed-price answer
One diagnostic resolves it
One fixed fee, agreed before any work starts. The number moves with tenant size and how many sites or mailboxes are in scope. Compact scopes cover smaller single-tenant environments where they apply.
The diagnostic
Identity & Insurance Evidence Pack
An Identity Secure Score, a heat-mapped risk matrix, and an executive remediation roadmap, mapped to the MFA mandate and insurance gates.
What you walk away with
What the evidence looks like
A representative deliverable. Yours is built on your own tenant.
Senior-delivered
One senior engineer scopes it and runs it, start to finish.
Read-only access
Settings and permissions only are inspected. No files are opened and no data is moved.
Fixed scope
A defined deliverable and a definition of done, agreed before anything starts.
Not sure this is the one?
Talk through the problem. The reply confirms whether this assessment fits, or points you to the one that does. The engineer who scopes it is the one on the call.
Talk through the problemWhat happens next
- 1Describe the situationA few short fields: company size, environment, and what is going wrong.
- 2A reply within one business dayA first read of what you sent, and if it is a fit, a private scheduling link.
- 3A fixed-fee proposalNamed scope, price and definition of done. No obligation.
$5,950
Prepare for a Cyber-Insurance Audit