Carriers underwrite like auditors now. We show you where you stand — and help you get insurable, usually in about two weeks.
You don't have a security team. "IT" is one contractor. And then one of these lands — with a deadline.
A renewal or new-policy questionnaire asking about MFA, EDR, immutable backups, incident response — terms nobody on staff can confidently answer.
Your broker says the rate climbed sharply, or coverage was declined outright — and can't tell you exactly how to fix it.
A customer or prime contractor won't sign until you attest to security controls you've never had to document before.
Most businesses already have decent security. What they can't do is produce the screenshots, the tested-restore log, the training records, the written plan. We don't sell you software — we make your controls provable, which is what underwriting actually grades.
Across carriers the requirements have converged on eight controls. We map your business to every one — against the real questionnaire.
Enforced on email, remote access, and admin accounts — with proof.
Modern detection on every endpoint. Traditional antivirus is rejected.
Offsite, immutable, with a documented test restore in the last year.
A written plan, tested with a tabletop exercise, kept current.
A written policy with SLAs and evidence of consistent application.
Annual, all-staff, with completion certificates on file.
A documented least-privilege model, admin accounts separated.
Review of key SaaS vendors' SOC 2 and a current data-access inventory.
Productized and flat-fee. You know the price, the timeline, and the deliverables up front — no surprises, no upsells, no long-term contract.
This is a business-risk conversation, not an IT sales pitch. It's run by a network-security practitioner who has spent a decade inside exactly the systems insurers ask about — and who has nothing to sell you but the readiness itself.
Our independence is the product. We're the assessor, never the operator — the Switzerland in the room.
Answer 15 questions. The moment you finish, you get:
No — and that's deliberate. You're always the attesting party. We prepare every answer with you and assemble the evidence behind it, then you review, adopt, and sign. It protects you, and it protects the integrity of your policy at claim time.
The Readiness Audit runs on a two-week clock. If your renewal is sooner than that, the Triage gets you a defensible position and a fix list in a few days.
Never. We don't resell tools and we don't run your IT. When you need to buy something, we tell you what fits and step back — our recommendation isn't tied to a commission.
Your IT provider keeps the lights on; they're rarely set up to translate your environment into an underwriter's language and evidence pack. We do that one job, fast, and hand the documentation to you and your broker.
Flat fees, published up front: Triage from $1,000, the two-week Readiness Audit from $3,500, hands-on Remediation from $5,000, and an annual retainer from $1,500/month. No hourly surprises.