Enterprise risk management and cyber insurance readiness
Cyber insurance readiness means your cyber risks sit inside enterprise risk management, you have decided which losses to retain and which to transfer, and your insurance application describes controls you actually run. We connect cyber risk to your ERM framework, help you draw the retain-or-transfer line, and prepare the evidence behind the application. We are not an insurance broker and we do not sell insurance.
How cyber risk fits into enterprise risk management
Most corporate risk registers carry cyber as one line, rated by IT, with an impact of “high”. That line hides a dozen different risks with different owners: a ransomware outage in the plant, a leak of customer records, a vendor with admin access to your payroll system.
We break that line apart and score each risk on the same impact scales the rest of ERM uses: financial, operational, regulatory and reputational. Each one gets a business owner and a place against the cyber risk appetite statement. The detail then lives in a cyber risk register with KRIs that rolls up cleanly to the enterprise view.
How to include cyber risk in capital projects
A new ERP, a control-system upgrade or a move to a hosted platform locks in its security posture at the business case. Fixing it after go-live costs more and usually loses the argument.
We add a short cyber gate to project approval. It asks what data the project will hold, which vendors will have access, what recovery the business needs, and what securing it will cost. The answers go into the business case.
Retain or transfer: what cyber insurance is for
Risk financing is the decision about which losses you absorb yourself and which you pay someone else to carry. Insurance suits losses that are large, rare and hard to fund from operations: a major outage, third-party claims, the cost of running a serious incident.
It suits frequent small incidents poorly. Those are cheaper to retain under your deductible and to reduce with controls. Some exposures may sit outside cover altogether, and your broker and counsel are the right people to confirm which.
How to prepare a cyber insurance application
Underwriters ask a consistent set of control questions: MFA, backups, endpoint detection, privileged access, patching, incident response and email security. Each answer has to be true on the day you sign and provable after a claim.
We check every answer against evidence before it goes to the broker: an MFA enrolment report, a restore test, an EDR count against the asset list. Where the honest answer is “mostly”, we help you say so with scope and a dated plan. What cyber insurance applications ask walks through the questions, and why MFA decides your renewal covers the one that most often matters. The file follows our evidence pack.
What you receive
| Deliverable | What it is for |
|---|---|
| Cyber risks mapped into the ERM register | Scored on enterprise scales, each with a business owner |
| Capital project cyber gate | A short set of questions added to project approval |
| Retain-or-transfer analysis | Inputs for the conversation with your broker |
| Application evidence file | One dated record behind each control answer |
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Are you an insurance broker?
No. We are not an insurance broker and we do not sell insurance. Your broker places the cover; we make sure what the application says about your controls is true and backed by evidence.
Can you tell us how much cyber cover to buy?
We do not recommend policy limits or wordings. We give you and your broker the inputs: which losses the organization can absorb, what recovery from a serious incident would involve, and which risks sit outside appetite.
Will this lower our premium?
Nobody outside the insurer can promise a premium, a limit or an acceptance. What changes is that your answers hold up, and you see the control gaps an underwriter would price before the underwriter does.
Is this legal advice?
No. We are not lawyers; we work alongside your counsel on policy wording, exclusions and anything that turns on what a statute requires.
Before your next renewal
Send the renewal date and last year’s application, if you have it. The reply says what we would check and what you would receive. The wider practice is at cyber risk management and governance.