Texas based. Supporting organizations nationwide.

Govern

Cyber Insurance Readiness

Prepare for cyber liability insurance with a readiness assessment, hands-on security control implementation, and documented evidence for your insurance application.

Available as an assessment and implementation project, with agency producer support and training scoped separately.

Download Cyber Insurance Readiness brochure (PDF)
01Understand gaps against the carrier's security requirements
02Implement and validate the controls in your agreed scope
03Give producers and clients clear, evidence-based answers

What is included

Assessment, implementation, and producer support

Final scope is tailored to your environment, objectives, and constraints. Typically includes:

  • Review of the agency-provided application and carrier security requirements
  • Current-state assessment with internal IT or your existing MSP
  • Control gap report and prioritized remediation plan
  • Scoped implementation of identity, endpoint, email, backup, and other required controls
  • Validation of implemented controls and documentation of exceptions
  • Evidence package and technical support for accurate application responses
  • Producer Q&A support and participation in client security conversations
  • Producer training on cyber risk, security terminology, and readiness discussions

Assessment controls

From questionnaire questions to controls and evidence.

We translate your insurer's questionnaire into a control review, evidence request, and remediation plan. The areas below map to the supplied Chubb CyberSecurity Supplemental Application, form 14-03-1157 (01/2011). Your producer confirms the current application and any additional carrier requirements before work begins.

Information Security Policies Q1, Q2(a-d), Q5-6 | pages 1-2

Security policies and accountability

Review protection of information assets, security officer responsibilities, confidentiality requirements, classification and disposal, acceptable use, internet and social media use, email use, employee acknowledgment, and annual policy review. Contract terms are confirmed with the client's legal team.

Evidence we review: Approved policies, assigned owners, acknowledgment records, review dates, and confidentiality agreement records.

Information Security Policies Q3-4; Web Server Security Q9-11 | pages 1 and 3

Identity and access controls

Review unique user credentials, assigned access rights, least-privilege database access, session lifetimes, and application-specific permissions. Implement agreed identity and access changes and document exceptions.

Evidence we review: Account inventories, access matrices, access reviews, database permission reports, and session configuration evidence.

Personnel Hiring Practices Q1(a-c), Q2; Premises Security Q1-3 | page 2

Personnel and premises security

Assess records of employee and nonemployee screening with HR, and equipment-room access, access-event investigation, and visitor verification with facilities. HR and facilities own screening, physical safeguards, and supporting records; implementation by those teams is tracked in the remediation plan.

Evidence we review: Screening procedures and completion records, nonemployee access lists, physical access logs, visitor records, and investigation procedures.

Web Server Security Q1-6, Q8, Q12 | pages 2-3

Web server and application security

Assess web-system policies, web application firewalls, DMZ or equivalent segmentation, encryption in transit, remote administration protocols, testing during development and deployment and after release, insecure credential transmission, and unnecessary services. Scope configuration improvements and validation with the application and infrastructure owners.

Evidence we review: Architecture and firewall configuration, encryption settings, hardening baselines, development and release testing records, and application security reports.

Web Server Security Q7 | page 3

Vulnerability remediation

Establish the actual time taken to fix discovered vulnerabilities, compare it with agreed targets, prioritize remediation, and validate eligible fixes. A planned deadline is distinguished from measured performance.

Evidence we review: Dated findings, remediation tickets, severity-based targets, exception approvals, and retest results.

Information Security Policies Q2(e-f); Mobile Device Security Q1(a-b), Q2 | pages 1 and 3

Mobile devices and sensitive data

Review protection of sensitive data on mobile devices and removable or backup media, visibility into copying to mobile media and sending through email, and smartphone encryption. Scope device management, data protection, and monitoring controls according to platform and licensing.

Evidence we review: Device and encryption reports, removable-media policies, data loss prevention configuration, and representative alert or audit records.

Service Providers Q1(a-e), Q2(a-e) | page 3

Service provider assurance

Inventory third parties providing backup, website hosting, sensitive-data processing, application maintenance, and infrastructure hosting. Review the security evaluation method and available audit reports with the client. Record what was actually evaluated and preserve the form's requested report type rather than claiming a different report is equivalent.

Evidence we review: Vendor inventory, service descriptions, audit reports, review notes, due diligence records, and unresolved vendor risks.

PCI Compliance Q1 and follow-ups; HIPAA Compliance Q1-6 | page 4

PCI and HIPAA readiness

Review PCI assessment records and corrective actions; document client-confirmed HIPAA applicability, PHI volumes, audit history, control reviews, remediation timing, and business associate agreements. Support readiness and evidence collection. A Qualified Security Assessor performs the formal PCI assessment; the client's legal team confirms legal status and indemnification terms.

Evidence we review: Assessor reports, correction records, PHI inventory, audit findings, remediation dates, and client-approved agreement records.

Written Records Management Q1(a-d), Q2(a-c) | page 5

Written records and secure disposal

Review paper collection, shredding after entry, locked files, restricted storage, clean-desk practices, final disposal, and offsite storage providers. Facilities and records owners operate physical controls; the client's legal team confirms provider responsibility and loss-allocation clauses.

Evidence we review: Records inventory, retention and destruction procedures, disposal receipts, provider contracts, and documented reviews of available provider audit reports.

Data Breach Incident Response Q1(a-e), follow-ups (i-vi), Q2(a-e) | pages 5-6

Incident response and breach readiness

Review response to unauthorized system or data access, denial of service and outages, extortion, and data corruption. Assess leadership approval, legal coordination, annual exercises, remediation of exercise findings, client-approved response cost estimates, plan ownership, and update cadence. Document contacts for counsel, notification, public relations, monitoring, and forensics; those specialist services are separately arranged.

Evidence we review: Approved response plan, contact roster, exercise records, improvement tracker, cost assumptions, recovery procedures, and plan review history.

The assessment documents each applicable response as supported, a gap, not applicable with an explanation, or awaiting evidence. The client approves application statements. Prior-knowledge disclosures, material changes, declarations, signatures, and producer details remain with the applicant and agency. Additional carrier requirements may include MFA, EDR, protected backups, and recovery testing even where this supplemental form does not ask for them directly.

A strong fit for

Support before application, placement, or renewal

01

Businesses preparing to buy or renew cyber liability insurance

02

Applicants with missing controls or unclear questionnaire answers

03

Insurance agencies seeking a technical resource for their producers

Engagement model

From security gaps to a documented application

Security engineers deliver the technical work. Security leadership aligns priorities, risk decisions, and stakeholders. Your agreed scope defines implementation, validation, and handoff responsibilities.

01

Assess

Confirm the carrier requirements, environment, deadline, and existing controls. Deliver a gap report and prioritized plan.

02

Implement

Complete approved remediation with your IT team or MSP, validate changes, and document the controls and remaining gaps.

03

Return to your producer

Provide the client-approved evidence package and technical answers so your insurance agency can move forward with application and placement.

Service details

A technical resource for insurance producers

Bring Encompass into cyber insurance sales conversations to explain security controls, answer technical questions, and help clients understand the work needed to prepare. Producer training can cover common cyber threats, application terminology, discovery questions, and when to bring in technical support. Availability and training cadence are agreed with the agency.

Controls tailored to the actual application

Depending on the carrier and client environment, readiness work may address multifactor authentication, endpoint detection and response, protected backups and restore testing, patching, privileged access, email protection, awareness training, and incident response. We map the work to the actual requirements rather than treating a generic checklist as proof of eligibility.

Clear responsibilities through insurance placement

Encompass delivers security assessment, implementation, validation, and technical documentation. The client reviews and approves application statements. Your insurance agency handles coverage advice, quotes, application submission, and placement; the carrier makes underwriting decisions. Readiness work does not guarantee coverage, pricing, or claim payment.

Questions

Cyber insurance readiness questions

The scoping call covers environment specific questions, dependencies, timing, and deliverables.

Can you implement missing controls before we purchase insurance?

Yes. We can implement agreed controls directly or alongside your IT team or MSP. Assessment and remediation scope, licensing, third-party costs, and timing are confirmed before work begins.

Can you support our producers in selling cyber insurance?

Yes. We provide technical Q&A, join agreed client conversations, and offer producer training so your team can explain readiness needs and connect clients with practical security help. Insurance recommendations and placement remain with the agency.

Do you complete or sign the insurance application for us?

We explain technical questions and provide evidence-based input. The client verifies and approves its representations, and the agency manages submission. Unimplemented controls and exceptions are documented rather than represented as complete.

Does the assessment guarantee that we will qualify?

No. Requirements vary by carrier, business, and policy. The insurer determines eligibility, terms, pricing, and coverage. Our role is to help you implement and document the applicable security controls.

Cyber Insurance Readiness

Security expertise from leadership through delivery.

Tell us the problem, deadline, and where your team needs help. We will scope the security engineering, hands-on assessment or implementation, and leadership support that fits your engagement, with clear ownership and deliverables.