Cyber insurance buyer’s prep

You’re about to shop for cyber insurance. Do this first.

Coalition, Cowbell, and At-Bay each score MFA, EDR, backups, vendor concentration, and AI-vendor exposure differently. Show up to your carrier’s application with the answers already assembled, backed by cryptographic evidence, not a checkbox on a self-attested form. Lower premium, faster approval, fewer exclusions.

Renewal in the next 90 days? The posture-delta report your broker attaches to the application is our sharpest 30-day ROI.

Why now

Five pressures changed how cyber insurance gets underwritten in the last twelve months.

Revenue used to be the primary underwriting input. Now it’s a coefficient. Controls attestation is the primary input, and every major carrier reads the attestation differently.

  1. 2020–22Hard market · premiums up 60–100% YoY · capacity contraction · multiple carriers exit
  2. Jun 2023FTC Safeguards Rule effective · SEC Item 106 cyber disclosure effective Dec 2023
  3. 2024Controls-based underwriting fully displaces revenue-based across every major cyber carrier
  4. Now2026 applications add AI-vendor + model-risk questions · state cyber-insurance rulemaking advancing in CT / VA / IL
  1. Controls-based underwriting displaced revenue-based.

    Every major cyber carrier (Coalition, Cowbell, At-Bay, Beazley, AXIS) now underwrites off MFA enforcement, EDR coverage, backup segregation, patch cadence, and vendor concentration. Revenue and industry are just risk-adjustment coefficients on top. Your posture IS your price now.

  2. The application is a 40-question controls audit.

    Coalition's app runs ~35 controls questions across identity, endpoint, backup, email, and vendor. Cowbell adds vendor-concentration and AI-model exposure. At-Bay adds business-email-compromise-specific controls. The days of naming your revenue and getting a quote are over.

  3. Ransomware sublimits and exclusions keep tightening.

    Since the 2020–2022 hard market, carriers have added ransomware sublimits (often 25–50% of aggregate), state-affiliated-actor exclusions, dependent-business-interruption caps, and cyber-fraud sublimits. What you thought was covered may not be, and the controls you can attest to determine which sublimits apply.

  4. State regulators now require carrier posture attestation.

    NY DFS 23 NYCRR 500 requires covered entities to attest to specific controls (MFA, encryption, IR planning) annually. NAIC's Insurance Data Security Model Law is now adopted or in-progress in 25+ states. Your carrier is being audited on which policyholders it wrote, which means your controls attestation is the carrier's audit trail too.

  5. AI-vendor exposure is the new question on the application.

    2026 cyber applications now ask which third-party AI vendors you use, what data flows to them, how they're contractually bound, and whether you have model-risk management. If your team started using Copilot / Gemini / Claude at work without governance, that's a new question you don't have an answer to.

The three moments cyber insurance actually prices

Application. Renewal. Claim. Same posture. Three different questions.

You touch cyber insurance three times per policy year, first at application, again at renewal, and (God forbid) at claim. Each is a point where your posture, and how well it’s documented, decides what you pay and whether the coverage actually responds.

Application

The 40-question controls audit.

2026 cyber apps aren’t forms, they’re audits. Every question about MFA, EDR, backups, vendor concentration, AI vendors, and IR maturity feeds an automated underwriting engine. Self-attested checkbox scores worse than a concrete answer + evidence. Your posture, and how well it’s documented, sets your tier at Day 5.

40+ questions · auto-tier at Day 5 · evidence beats attestation
See what shifts the tier
Renewal

The delta report your broker attaches.

At renewal, the underwriter reads the delta since last binding. Improvement locks in rate. Slippage (a control weakened, a tabletop skipped, a new AI vendor added without governance) drives rate hikes and sublimit tightening. Continuous evidence collection means the delta is quantitative and pre-attached, not reconstructed from screenshots the week the app is due.

90-day renewal window · YoY delta drives 15–25% of premium
See the posture-delta report
Claim

The forensic evidence trail.

When a claim gets contested, the carrier’s investigator asks: prove your controls were operating at the time of the incident. SHA-256-hashed, RFC 3161-timestamped evidence bundles mean you can prove state at any past point, not reconstruct from screenshots after the fact. Claim-grade defensibility is a different bar than application-time attestation.

SHA-256 + RFC 3161 · defensible years after the incident
See what claim-grade means

The outcomes

Lower premium. Faster approval. Fewer exclusions. Same coverage, different conversation.

Five outcomes, one per pressure above. Each one is what a prepared cyber insurance buyer walks out with, and what your broker can attach to whichever carrier writes the quote.

Renew

The renewal that comes back at last year's number.

Continuous evidence collection means the carrier sees your posture the same way at renewal that it saw at binding, no surprise gaps, no 30% renewal hike because your controls slipped and no one caught it. Delta report attached to the renewal application before your broker asks for it.

Reduce

The premium quote that comes in 15–25% lower.

Coalition, Cowbell, and At-Bay each score MFA enforcement, EDR coverage, backup testing, and vendor concentration differently. Show up with attestation for the specific control families each carrier weights, backed by cryptographic evidence, not a checkbox on a self-attested application.

Attach

An evidence bundle underwriters actually read.

SHA-256-hashed, RFC 3161-timestamped controls attestation packet exported straight from the platform. What Coalition asks for in the app, what Cowbell verifies in the follow-up call, what At-Bay wants during the pre-bind review, assembled once, attached to whichever carrier your broker recommends.

Answer

The 40-question application, answered in one afternoon.

The cyber insurance application isn't a form anymore, it's a controls audit. Continuous evidence collection means every answer is already in the platform. Your broker gets the completed application same-day instead of two weeks of follow-up emails.

Defend

Claim-grade evidence when the carrier's investigator arrives.

When a claim gets contested, the carrier's forensic investigator asks: prove your controls were operating at the time of the incident. Hash-chained evidence bundles with cryptographic timestamps mean you can prove state at any point in the past, not reconstruct from screenshots after the fact.

Continuous readiness, not annual scramble

Two weeks off the app cycle. Fifteen percent off the premium.

Most companies rebuild the posture story from scratch every time the broker or an underwriter asks, scramble for the MFA export the week before the renewal call, hunt for the last tabletop report before the pre-bind, reconstruct which AI vendors got added last quarter before the app is due. That work is real, unbilled, and repeats every twelve months. Running the program continuously eliminates most of it, which is where the two weeks of calendar time and the ~15% of premium come from.

You (once per policy year)

Broker downloads the bundle. Attaches it.

  • 1Broker pulls the current bundle from the platform. Controls attestation, MFA export, vendor map, IR plan, AI-vendor register, tabletop after-action, all current, all signed.
  • 2Attaches it to the carrier’s application. Every one of the 40 questions is cross-referenced to a specific exhibit inside the bundle.
  • 3Signature chain travels with it. Cryptographic hash proves nothing was modified in transit.
~30 minutes of broker timeUsed to be: 2–3 weeks of your team’s evidence-scavenger-hunt
Underwriter (on receipt)

Auto-verifies. Auto-tiers. Quotes.

  • ✓Signatures verify against the platform’s identity chain. No forged screenshots, no cherry-picked exports.
  • ✓Freshness under 30 days. Automated underwriting engine reads the timestamps and moves the application straight to tier-1 without follow-up.
  • ✓Cross-reference map lets the underwriter jump from Q17 straight to the specific exhibit backing it. No two-week email chain chasing evidence.
  • →Auto-tier assignment. Quote-ready. Bind-approved.
~3 minutes of underwriter timeUsed to be: 10 days of follow-up email chain with your broker

Same signed evidence, both sides win. Your team stops losing three weeks per year. Your carrier stops chasing you for two. Which is where the 15% off the premium comes from, the carrier prices in what it can actually verify.

The next three questions

We watch where underwriting is going. Not just where it’s been.

Every new question on next year’s cyber application starts as a rule in a regulator’s Federal Register comment period this year. We read those drafts. When a question graduates from proposed rule to actual application field, the platform’s evidence exports have already been updated. Your bundle stays application-ready before the ask lands.

2027

How do your agentic-AI decisions maintain human-in-the-loop attestation for material actions?

Regulatory signal
NIST AI RMF gen-2 draft in Fed Register comment · OMB M-24-10 human-oversight requirements cascading to SEC-registrant vendor risk · EU AI Act Art. 14 human-oversight extending to US carriers via cross-border data flows.
2027

What is your quantum-safe crypto migration plan for tenant data at rest and in transit?

Regulatory signal
NIST finalized post-quantum crypto standards FIPS 203 / 204 / 205 in Aug 2024 · CNSA 2.0 requires PQC in national-security systems by 2033 · commercial cascade via NAIC and state cyber-insurance rulemaking now scoping.
2028

How do you defend against deepfake-enabled voice-cloned executive fraud on wire transfers?

Regulatory signal
Arup HK $25M deepfake video-call fraud (Feb 2024) · FBI IC3 BEC + synthetic-media trend line · first carrier ransomware-specific and BEC sublimits already differentiating on deepfake controls.

Deliverables

Ten building blocks. All application-ready.

Platform delivers the continuous evidence + attestation infrastructure. Other20 delivers the advisory work that turns evidence into a carrier-ready application. Each tile names what you walk away with when the program is running.

vCISO Lite platform
Controls attestation packet
Auto-generated from continuous evidence collection across identity, endpoint, backup, email, vendor. Mapped to the specific questions Coalition / Cowbell / At-Bay ask on their 2026 applications. Refreshed every renewal cycle.
vCISO Lite platform
Underwriter evidence bundle
SHA-256-hashed, RFC 3161-timestamped export. What Coalition asks for in the app + what Cowbell verifies in the follow-up call + what At-Bay wants at pre-bind, assembled once, exportable to whichever carrier wins the quote.
vCISO Lite platform
Quarterly posture-delta report
What changed since last quarter. What changed since last renewal. What's improved vs. what's slipped. Broker attaches this to the renewal application; underwriter reads the delta line first.
vCISO Lite platform
Vendor-concentration map
H-index-scored third-party register showing top-N vendors by data-access scope. Cowbell weights concentration heavily; Coalition tracks it as a risk factor; At-Bay wants delta over 12 months. All three questions, one artifact.
vCISO Lite platform
AI-vendor register + model-risk policy
Which AI vendors (Copilot, Claude, Gemini, embedded features), what data flows to them, what contractual scope, retention terms. Direct answer to the 2026 carrier-application question your team can't fill in from memory.
Other20 advisory
IR plan authoring
Real vCISO writes the IR plan for your specific environment, not a template. Playbooks for ransomware, business email compromise, AI-vendor breach, insider risk. Named contacts, escalation ladder, first-24-hour runbook.
Other20 advisory
Tabletop exercise cadence
Facilitated exercise your leadership actually participates in. After-action report attached to the evidence bundle. Documented cadence answers the At-Bay pre-bind question directly: "When was your last tabletop?"
Other20 advisory
Application completion service
Other20 completes the carrier application on your behalf using platform evidence. All 40 questions answered concretely, follow-up-call script prepared, evidence pack pre-attached. Broker gets a ready-to-quote package instead of a two-week email chain.
Other20 advisory
Pre-quote posture assessment
Before you apply, Other20 walks your posture and identifies the specific gaps each carrier will score down. Ship the quick fixes first; go into the application already positioned for the top-tier premium bracket.

Is this you?

Six situations this program was built to help.

If two or more describe your last twelve months, the pre-quote posture assessment is worth the thirty minutes.

You're shopping cyber insurance for the first time and don't know which carrier or how the application will score you.

Your renewal is 60–90 days out and last year came in 30% higher than the year before. Broker says "controls", you don't have a clear answer.

A carrier declined to quote or non-renewed you. You need to close the gaps that got flagged before the next application.

An enterprise customer requires you to carry cyber insurance. You need coverage in place fast, at defensible limits, without over-paying.

Your team started using AI vendors (Copilot, Claude, Gemini, embedded features) and you have no answer for the AI-vendor questions on the 2026 application.

You already have a policy but the sublimits (ransomware, dependent-BI, cyber-fraud) are so tight the coverage may not respond to your actual risk profile.

Advisory hours · higher tiers

A real vCISO on the pre-bind call. Not “we’ll ask our engineer.”

Underwriter pre-bind calls with a vCISO present, answering the technical questions in real time instead of your team scrambling to loop in whoever actually knows. Denial-letter walk-through and remediation planning when a carrier says no. AI-vendor governance strategy that stands up to the 2026 application question. Broker relationship coordination when your renewal window opens. Claim-time forensic evidence attestation when an incident hits and coverage response depends on how well you can prove state at time-of-incident. Ultra tier includes 4 hours/month of vCISO consulting; Fractional CISO SKU adds a dedicated 8-hour-per-week engagement. Real people, real hours, priced by engagement.

Frequently-raised questions

What cyber-insurance buyers ask on the first call.

  • Do I need to switch carriers to use vCISO Lite?

    No. vCISO Lite works alongside whichever carrier your broker recommends. Coalition, Cowbell, At-Bay, Beazley, Chubb, AXIS, Corvus, or a specialty MGA. We're posture and evidence infrastructure; the carrier is who writes the policy. Show up to your carrier's application with the answers already assembled, and the carrier's underwriter reads a better story about you.

  • How much premium reduction should I actually expect?

    Depends on your starting posture. If you already have strong MFA + EDR + backup discipline and just haven't documented it well, expect 10–15% reduction from a cleaner application alone. If you have real gaps to close (no formal IR plan, poor vendor documentation, missing model-risk policy for AI use), the delivered posture improvements can drive 20–30% reduction. We'll show you the math in the ROI calculator using your specific inputs.

  • What if my broker doesn't want to work with a compliance platform?

    Most brokers welcome it, you're making their job easier. Instead of chasing you for two weeks to complete the application, they get a ready-to-quote package from us. If your broker specifically doesn't want to work with platform-generated evidence, that's a conversation about whether they're the right broker for a 2026 cyber-insurance market.

  • Is this useful for renewal, or only new applications?

    Renewal is where the ROI is highest. New applications are one-time work; renewals compound. Continuous evidence collection means the posture-delta report is already assembled when the renewal window opens. The broker attaches it to the renewal application; the underwriter sees improvement (or explains variance) instead of guessing.

  • How fast can we get to a defensible position?

    First application-ready evidence bundle in 4–6 weeks for a company that already has the underlying controls (MFA, EDR, backups) in place. 8–12 weeks if we're building the IR plan, tabletop program, and AI-vendor register from scratch. Pre-quote posture assessment happens in the first 2 weeks either way, you'll know before spending money on the platform whether it changes your quote materially.

  • What if we already got denied or non-renewed?

    Common situation and one this is specifically built for. Denial letters typically name the specific controls that failed ("insufficient MFA coverage," "no documented IR plan," "vendor-concentration risk"). Other20 walks the denial letter, ships the fixes that address the flagged controls, and prepares a new application with cryptographic evidence for each fix. Second-application acceptance rate is very high when the platform + advisory team walks the reason for denial.

Your renewal is coming. Get in front of it.

See what the carrier will see before the application goes in. Ship the posture fixes that move premium in the first 4 weeks. Attach the evidence bundle your broker’s underwriter reads in 3 minutes instead of a two-week email chain.