Click to toggle navigation menu.

Category: Security Controls & Compliance

What Underwriters Now Verify About Your Vendor Risk Program

By Ryan Windt | Head of Growth Marketing | Updated June 2026 For most of the last decade, cyber underwriting focused almost entirely on what was inside your own walls: your MFA, your backups, your endpoint protection. That made sense when most attacks targeted the insured directly. It makes much less sense now, when some […]

What Underwriters Actually Verify About Your Logging and Monitoring

By Ryan Windt | Head of Growth Marketing | Updated June 2026 Most controls underwriters check are about keeping attackers out. Logging and monitoring is different. It is the control that determines what happens once someone gets in, and increasingly it is the one that separates a contained incident from a catastrophic claim. When forensics […]

How NIST CSF 2.0 Shapes Cyber Insurance Underwriting and Coverage

By Ryan Windt | Head of Growth Marketing | Updated June 2026 When a business tells a cyber underwriter “we follow NIST,” that sentence does almost nothing on its own. Underwriters do not price policies on framework names. They price on the specific controls a framework produces and on whether you can prove those controls […]

How Underwriters Evaluate Network Segmentation for Cyber Insurance

By Ryan Windt | Head of Growth Marketing | Updated June 2026 Ransomware works by spreading. An attacker gains initial access through a phishing email, a compromised credential, or an unpatched vulnerability, and then moves laterally through the network looking for systems to encrypt, data to exfiltrate, and backups to destroy. The faster they can […]

The Security Controls Underwriters Check Before They Quote You

By Ryan Windt | Head of Growth Marketing | Updated June 2026 Every cyber insurance application asks about security controls. The questions vary by carrier, but the controls they care about most have been largely consistent for the past three years: MFA, EDR, immutable backups, email security protocols, privileged access management, and incident response capabilities. […]

Immutable Backups and Cyber Insurance: What Underwriters Actually Want to See

By Ryan Windt | Head of Growth Marketing | Updated June 2026 If you have read anything about qualifying for cyber insurance in the last two years, you have seen the phrase “immutable backups” somewhere in the requirements list. It appears in underwriting questionnaires, in policy conditions, in carrier declination letters, and in post-incident forensic […]