Make the controls on your insurance application true, and keep them evidenced.
Get Expert GuidanceMost businesses think they’re compliant. The real test isn’t whether you think you’re covered, it’s whether you could prove it on the spot:
Being protected and being able to prove it aren’t the same thing. Applications have got a lot more demanding, and insurers want specifics rather than a yes. A claim is assessed against what you declared, and “we had that in place” is a much weaker position than a policy document, a patch report and an audit trail.
We work on the technical side of that: getting the controls genuinely in place, documenting them and keeping evidence that stands up, whether the person asking is an insurer or a prospective customer.
A policy is not the same as protection, and a declaration is not the same as evidence. Cover gets challenged for ordinary reasons: multi-factor was enabled for most staff but not the account that was compromised. Backups existed but had never been restored from. A leaver kept access for months. The controls were described accurately when the form was filled in, and had quietly drifted by the time they mattered.
Underinsuring is the other half of the problem. Businesses buy controls they do not need because a questionnaire mentioned them, and skip the ones that would have made a difference. Working out which risks actually apply to your business, and in your sector, is cheaper than paying for the wrong protection.
Every IT365 client goes through The Assure Way, and it is what gets your business protected and Cyber Essentials ready as standard. That covers the technical baseline most insurers ask about first: firewalls, secure configuration, access control, malware protection and patching. On Elevate you also get our full standardised policy set, and your Customer Success Manager reports on service performance, patching, licensing and budget, which is the paper trail an assessor asks for.
Infinite Assurance is where the work becomes specific to you. Your vCIO writes policies tailored to how your business actually operates, covering information security, Microsoft conditional access and workstation hardening, plus incident detection and response. Those policies sit under an IT strategy that tests and audits them, so you hold evidence they were working rather than a document saying they should. It is also what takes you beyond the baseline to Cyber Essentials Plus or CIS standard, which carry more weight with insurers than the baseline does. Passing an accreditation on controls we put in and monitor is the strongest version of that evidence, because the certificate and the audit trail behind it come from the same place.
Insurance questionnaires and security standards use different language for the same controls. We map what your insurer or broker is asking against what you actually have, so you can see which answers are solid, which are optimistic and which are gaps. That covers the control and requirement mapping and the maturity view the current page mentions.
A written assessment of where your business is exposed, based on how it operates rather than a generic checklist. It tells you which gaps matter enough to close before your next renewal and which are noise, so remediation spend goes where it reduces real risk.
Closing the gaps, then keeping proof they stayed closed. On Infinite Assurance your vCIO owns the policies and the IT strategy that audits them, which is what turns a one-off tidy-up into evidence you can produce at renewal or at claim.
It varies by insurer, but the same controls come up: multi-factor authentication, particularly on email and remote access; patching within a stated timeframe; control over who has administrator rights; backups that have been tested rather than just configured; and staff security awareness training. Increasingly they ask for a recognised certification too, most often Cyber Essentials. We go through your specific questionnaire with you rather than guessing at it.
It can. What you pay is an underwriter’s decision and it moves with the whole market, not only with your controls, so we will not promise you a number. What does carry weight is certification you can evidence. If you can show an insurer you have passed Cyber Essentials, and that you passed it on the controls we put in and monitor for you, you are answering their questionnaire with proof rather than good intentions. Businesses in that position tend to see easier renewals and fewer questions at claim, and failing an assessment or having a claim challenged costs considerably more than the work to avoid it.
No. We are not brokers and we do not sell or advise on policies. We work on the technical side, alongside whoever arranges your cover. In practice that means your broker asks the questions and we make sure the answers are accurate and evidenced. Plenty of our clients put us and their broker in the same conversation, which tends to be the quickest way through an application.
The baseline comes with every package, because the tooling gets you Cyber Essentials ready either way. Elevate adds the standardised policy set and the service and patching reports that evidence it. The advisory work itself, the tailored policies and the audits that keep them honest, sits on Infinite Assurance with your vCIO. If you are mid-application and not sure where you stand, start with a conversation rather than a package.
Our packages offer clear value and predictable costs. Choose based on the size and risk profile of your business, or make an enquiry and we will help you find the right fit.
Before your next renewal is a much better time to find the gaps than after a claim. Talk to us about a risk assessment of where your business stands.