Enterprise risk management and cyber insurance readiness

Cyber insurance readiness means your cyber risks sit inside enterprise risk management, you have decided which losses to retain and which to transfer, and your insurance application describes controls you actually run. We connect cyber risk to your ERM framework, help you draw the retain-or-transfer line, and prepare the evidence behind the application. We are not an insurance broker and we do not sell insurance.

How cyber risk fits into enterprise risk management

Most corporate risk registers carry cyber as one line, rated by IT, with an impact of “high”. That line hides a dozen different risks with different owners: a ransomware outage in the plant, a leak of customer records, a vendor with admin access to your payroll system.

We break that line apart and score each risk on the same impact scales the rest of ERM uses: financial, operational, regulatory and reputational. Each one gets a business owner and a place against the cyber risk appetite statement. The detail then lives in a cyber risk register with KRIs that rolls up cleanly to the enterprise view.

How to include cyber risk in capital projects

A new ERP, a control-system upgrade or a move to a hosted platform locks in its security posture at the business case. Fixing it after go-live costs more and usually loses the argument.

We add a short cyber gate to project approval. It asks what data the project will hold, which vendors will have access, what recovery the business needs, and what securing it will cost. The answers go into the business case.

Retain or transfer: what cyber insurance is for

Risk financing is the decision about which losses you absorb yourself and which you pay someone else to carry. Insurance suits losses that are large, rare and hard to fund from operations: a major outage, third-party claims, the cost of running a serious incident.

It suits frequent small incidents poorly. Those are cheaper to retain under your deductible and to reduce with controls. Some exposures may sit outside cover altogether, and your broker and counsel are the right people to confirm which.

How to prepare a cyber insurance application

Underwriters ask a consistent set of control questions: MFA, backups, endpoint detection, privileged access, patching, incident response and email security. Each answer has to be true on the day you sign and provable after a claim.

We check every answer against evidence before it goes to the broker: an MFA enrolment report, a restore test, an EDR count against the asset list. Where the honest answer is “mostly”, we help you say so with scope and a dated plan. What cyber insurance applications ask walks through the questions, and why MFA decides your renewal covers the one that most often matters. The file follows our evidence pack.

What you receive

DeliverableWhat it is for
Cyber risks mapped into the ERM registerScored on enterprise scales, each with a business owner
Capital project cyber gateA short set of questions added to project approval
Retain-or-transfer analysisInputs for the conversation with your broker
Application evidence fileOne dated record behind each control answer

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Are you an insurance broker?

No. We are not an insurance broker and we do not sell insurance. Your broker places the cover; we make sure what the application says about your controls is true and backed by evidence.

Can you tell us how much cyber cover to buy?

We do not recommend policy limits or wordings. We give you and your broker the inputs: which losses the organization can absorb, what recovery from a serious incident would involve, and which risks sit outside appetite.

Will this lower our premium?

Nobody outside the insurer can promise a premium, a limit or an acceptance. What changes is that your answers hold up, and you see the control gaps an underwriter would price before the underwriter does.

Is this legal advice?

No. We are not lawyers; we work alongside your counsel on policy wording, exclusions and anything that turns on what a statute requires.

Before your next renewal

Send the renewal date and last year’s application, if you have it. The reply says what we would check and what you would receive. The wider practice is at cyber risk management and governance.

Discuss a scope