Cyber insurance,
evidence instead of a self-assessment.
Premiums are moving for firms that can demonstrate continuous monitoring of their external posture. Bring an evidence-backed rating to renewal instead of a form you filled in yourself.
Cyber Insurance, step by step
The renewal questionnaire
A self-assessment the underwriter has no way to verify, and no way to reward.
A rating with evidence
A current, externally-observed score with the findings behind it, produced by a third party.
A better conversation at renewal
You can show what improved during the policy year, with dates attached.

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out
Underwriting stopped taking your word for it
Cyber insurance used to be underwritten largely on a questionnaire. Ransomware losses ended that. Premiums rose sharply, capacity tightened, and insurers moved to assessing applicants from the outside, because the self-reported answers turned out to correlate poorly with who subsequently claimed.
So most carriers and brokers now run external scans on applicants and renewals, whether or not that is described in the process. Your posture is being rated at renewal regardless of whether you have seen the rating, and specific findings (exposed remote access, unsupported software, weak mail authentication, credentials in breach data) move terms directly.
The asymmetry is the problem. The underwriter has a view of your external posture and you generally do not, so you arrive at renewal unable to explain findings you have not seen and cannot verify.
See what the underwriter sees, while you can still act
Rating your own organisation a quarter before renewal converts a surprise into a work plan. Most of what moves terms is unglamorous and quick to fix: an exposed management interface, a lapsed certificate, an SPF record permitting the entire internet to send as your domain, a forgotten staging host running something unsupported.
Those are days of work, not a transformation programme. The reason they persist is not difficulty but invisibility, nobody had a list. Ninety days is enough to clear most of it and to show a trend heading in the right direction, which is itself worth something in the conversation.
It also lets you arrive with evidence rather than assertion. A broker able to show a documented posture improvement over two quarters is in a materially better position than one presenting a completed questionnaire, because the first is checkable and the second is not.
Ratings are also an evidentiary record
Cyber policies increasingly condition cover on the insured maintaining the controls they represented at inception. That creates a specific exposure at claim time: an insurer can ask you to demonstrate that a control was in place before the incident, not merely that it is in place now.
A continuously rated, versioned, evidence-backed history answers that question in a way a spreadsheet cannot. It shows what the external posture was on a given date, with the evidence it was derived from and a timestamp that predates the loss.
We would not claim this decides coverage disputes, that turns on policy wording and facts we cannot see. But the difference between contemporaneous evidence and a reconstruction assembled after a loss is real, and it tends to matter most exactly when the sums are largest.
Rating a book rather than an applicant
Brokers and MGAs increasingly rate portfolios rather than individual risks: to triage submissions, to identify where remediation advice would materially improve terms, and to understand accumulation across a book.
Accumulation is the version most often underestimated. If a large share of insureds depend on the same cloud region or the same managed service provider, a single provider incident is a correlated loss event across the book rather than a set of independent claims. That is a portfolio question, and it is invisible when risks are assessed one at a time.
Pricing here scales with the number of rated companies rather than per seat, which is what makes rating an entire book rather than a sample workable.
What commonly moves cyber insurance terms
| Finding | Why underwriters weight it |
|---|---|
| Exposed remote access (RDP, VPN portals) | A recurring initial access vector in ransomware losses |
| Unsupported or end-of-life software | No security patches available at all |
| Weak or missing mail authentication | Enables business email compromise and impersonation |
| Credentials in recent breach data | Direct, immediately usable initial access |
| Expired or misconfigured TLS | Read as a maintenance signal beyond its direct risk |
| Unmanaged or forgotten assets | Nobody patches what nobody owns |
“Walking into renewal with a third-party rating changed the tone of the whole meeting.”
Cyber Insurance | common questions
Do insurers really scan us before quoting?
Most carriers and brokers now assess applicants externally at quote and renewal, whether or not it is described in the process. Your external posture is being rated regardless of whether you have seen the rating.
How far before renewal should we rate ourselves?
About a quarter. Most of what moves terms (exposed management interfaces, lapsed certificates, weak mail authentication, unsupported software on forgotten hosts) is days of work, and ninety days also lets you show a trend rather than a point fix.
Will a good rating reduce our premium?
We cannot promise that, and anyone who does is guessing at another company's underwriting. What it does is remove specific findings that demonstrably worsen terms, and let you present evidence rather than assertions.
Is this useful after a claim?
Potentially. Policies increasingly condition cover on controls represented at inception, and a versioned evidence-backed history shows what your posture was on a given date rather than reconstructing it afterwards. How that lands still depends on policy wording.
Can brokers rate a whole book?
Yes, and pricing scales with rated companies rather than per seat. Accumulation is the value most often missed, correlated dependency across insureds turns one provider incident into a portfolio loss event rather than independent claims.
What is the single most common finding?
Assets nobody knew were exposed. Everything else tends to follow from that, because unowned infrastructure does not get patched and does not appear in anybody's scanning scope.
Where this connects
Own enterprise visibility →
Find the exposed assets before an underwriter does.
Reports →
Evidence packs suitable for brokers and underwriters.
How scoring works →
Deterministic, versioned and evidence-backed by design.
Put your vendors on the board
Start with ten vendors. Expand when the first alert pays for the year.