Skip to content

Compliance

Cyber insurance: proving insurer requirements

Insurers ask about MFA, patch management, backups and your attack surface, and increasingly check the answers themselves. Prove them with continuous monitoring instead of estimating.

Reportsscheduled by email
PDFExecutive reportWeekly, Monday 07:00
PDFVulnerability reportMonthly
PDFPentest reportAfter every test
Management, head of IT

What insurers typically ask

The answers become part of the contract. You can evidence the first seven points with blacklens.io; the last one needs other tools.

MFA on remote access

Missing MFA on VPN, RDP or Microsoft 365 is the most common starting point for ransomware.

Patch deadlines

Insurers expect defined deadlines, often 14 days or less for critical vulnerabilities.

Exposed RDP

RDP reachable from the internet is an exclusion criterion for many insurers.

External attack surface

Many insurers now scan the perimeter themselves. Know the result before they do.

Credentials on the dark web

Leaked passwords lead straight into the network, stolen session cookies even despite MFA.

Scans and pentests

Regular testing proves that you know and handle your risks.

Cloud and service providers

Public storage, over-privileged accounts and weak third parties raise the risk of loss.

EDR, backups and training

Delivered by other tools. blacklens.io does show exposed backup interfaces and infected devices.

Not legal or insurance advice. Conditions differ by insurer and policy; clarify details with your broker or insurer.

Answers based on data, not self-assessment

The questionnaire asks about the current state. With continuous monitoring you answer with today's state, not that of the last audit.

Newly discovered assets+4 since yesterday
beispiel-gmbh.atRoot domain
vpn.beispiel-gmbh.atFortiGate SSL-VPN 7.0.12Critical
dev-old.beispiel-gmbh.atGitLab 15.2Shadow ITHigh
mail.beispiel-gmbh.atExchange Server 2019Medium
203.0.113.24OpenSSH 8.9NewInfo

Visuals show sample data.

Four steps before renewal

  1. 1

    Register your domains

    First results on the external attack surface are available within 24 hours.

  2. 2

    Connect identities and network

    Entra ID or Google for MFA status, Sentry as a VM for the internal patch state.

  3. 3

    Close entry points

    Fix exposed services, exploitable vulnerabilities and leaked credentials first.

  4. 4

    Attach reports

    Generate executive, vulnerability and pentest reports on schedule for the renewal date.

Premium, deductible and insurability

A provable security level affects premium, deductible and coverage amount in practice. There is no guarantee; the decision lies with the insurer. What you can influence is the quality of your evidence.

  • Prerequisite for acceptance

    Some insurers require MFA, no exposed RDP and tested backups upfront.

  • Early warning lowers the risk

    Spot stealer logs and leak site entries before they turn into a loss.

  • Proof in the event of a claim

    Activity log and finding history show what was in place at the time of the incident.

Progresslast 90 days
Critical findings143
Exposed services3821

Frequently asked questions

That is your insurer's decision. What blacklens.io does: you answer the questionnaire with provable data instead of estimates, attach current reports and reduce the entry points that insurers rate as the main risk. In practice this improves your negotiating position; we cannot guarantee a premium.

Know what the insurer sees, before they see it

Start with your domains and receive an executive report within 24 hours that you can attach to your application.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings