Does your cyber insurance renewal ask questions you can't actually answer?
An independent network security assessment for small businesses across Chester County PA, northern Delaware, and northern Maryland.
Your cyber insurance renewal asks whether every admin account has multi-factor authentication, whether your backups can survive a ransomware attack, whether you have actually tested a restore, and whether every computer runs security software. You sign the application saying yes. If one of those answers is wrong when you file a claim, the insurer can deny it or void the policy. I check every answer, on site, before you sign.
A $1,000,000 ransomware claim, denied.
On its insurance application, a real company said it required multi-factor authentication across the business. It did not. After a ransomware attack, the insurer found that answer was false, and a court cancelled the policy back to day one. The company had paid every premium and still collected nothing. One wrong answer erased the coverage. Making sure your answers are true, before you sign, is exactly what this assessment does.
Source: Travelers v. International Control Services, 2022, Insurance Journal.The answers on your application are the whole ballgame.
A trusted vendor emails new bank details. It is a thief.
A bookkeeper gets an email that looks like it came from a familiar vendor or supplier, asking to update the bank account on an unpaid invoice. The next payment, often five or six figures, lands with a criminal instead. Business email compromise cost US victims about $2.8 billion in 2024. Contractors, manufacturers, medical offices, and professional firms that pay by email are all targets, which is why wire transfer verification is one of the controls I check.
Source: FBI Internet Crime Complaint Center Annual Report, 2024.The bill lands hardest on a business your size
Reported cybercrime losses in the US reached $16.6 billion in 2024. Most ransomware now lands on smaller organizations, the ones least able to absorb the forensics, downtime, breach notification, and lost billable hours that follow. General liability covers none of it, and a carrier will not write a cyber policy until the controls are already in place.
Source: FBI Internet Crime Complaint Center Annual Report, 2024.Most owners answer from memory. Almost nobody verifies it first.
If you have a policy
Most owners answer the renewal from memory, or from what they assume their IT provider is handling. A single wrong answer, discovered at claim time, is all a carrier needs to deny the claim or void the policy. The time to check is before you sign, not after a breach.
If you have no policy at all
The math is simpler. A ransomware event at a 15 person firm runs into six figures once you add forensics, notification, downtime, and lost billable hours. General liability covers none of it. Carriers will not write a policy until the controls are already in place, and building them takes weeks. That work has to happen before you apply.
Answers you can put your name to, not guesswork.
I come on site, document what is actually running, and hand you four things. I am not an insurance agent and I do not sell policies. I document what is in place so every answer on your application is one you can prove.
A written assessment report
Dated and specific to your environment: what you have, what is missing, and what it costs to fix.
A prioritized remediation roadmap
Every gap ranked, with real costs attached, so you fix what matters first instead of guessing.
A cyber insurance answer sheet
Mapped to the standard questions on a carrier application, with a documented answer you can sign your name to.
A 45 minute walkthrough call
I take you through every finding so you understand exactly where you stand before you sign anything.
A written report you can hand to your insurer.
Here is the actual deliverable, shown for a fictional firm: findings by severity, a prioritized remediation roadmap with costs, and a cyber insurance answer sheet, all in one document. Yours is specific to your environment.
Sample for illustration. The company, findings, and figures are fictional examples. Your report is specific to your environment and dated to the day of the assessment.
Over 45 checks, verified and documented, not assumed.
Findings are recorded as observations on the date of the assessment. Every one is mapped to the matching question on a standard cyber insurance application.
Identity and access
MFA coverage, admin account sprawl, dormant and former-employee logins, legacy authentication.
Email security
SPF, DKIM, and DMARC posture, inbound filtering, and hidden mailbox forwarding rules.
Endpoints
EDR coverage, devices with no security agent, patch state, disk encryption.
Network and wireless
Firewall firmware, exposed remote access, segmentation, guest isolation, default credentials.
Backup and recovery
What is really backed up, offsite copies, immutability, and the date of the last restore test.
Documentation and process
Incident response plan, security awareness training, and wire transfer verification.
It works even if you already have an IT provider
Your provider is doing what you hired them to do. This is an independent second opinion, the same way you would not ask your bookkeeper to audit their own books. Plenty of these end with "your provider is in good shape, here are three gaps to close." That is a fine outcome, and you get a document for your insurance file either way.
I do not need your passwords. Ever.
You create named read only accounts, I use those, and you disable them the day I deliver the report. Nothing shared, nothing stored, fully auditable. I also need network access on site and about two hours of your office manager's time.
Common questions about the network security assessment.
What is a Network Security Assessment?
It is an independent, on-site review of over 45 security controls across identity, email, endpoints, network, backup, and recovery. You get a written report of what you have, what is missing, and what it costs to fix, plus a cyber insurance answer sheet and a prioritized remediation roadmap.
How much does it cost, and are there surprises?
It is a flat $750, normally $1,495. That single price covers the on-site work, the written report, the remediation roadmap, the cyber insurance answer sheet, and a 45 minute walkthrough call. No hourly meter and no add-ons.
How long does it take and how much of my time do you need?
Most assessments take a single half day on site. I also need about two hours of your office manager’s time for access and questions, and then a 45 minute call after I deliver the report to walk you through every finding.
Do you need my passwords?
No, never. You create named, read only accounts for the assessment, I use those, and you disable them the day I hand you the report. Nothing is shared, nothing is stored, and the whole thing is fully auditable.
I already have an IT provider. Is this still worth it?
Yes. This is an independent second opinion, the same way you would not ask your bookkeeper to audit their own books. Plenty of these end with "your provider has you in good shape, here are three gaps to close." Either way, you walk away with a document you can put in front of your insurer.
Will this help with my cyber insurance renewal?
That is the point. Every finding is mapped to the matching question on a standard cyber insurance application, with a documented answer you can sign your name to. I am not an insurance agent and I do not sell policies. I document what is in place so you can answer the application from facts.
What if I do not have a cyber policy yet?
The assessment shows exactly which controls a carrier will expect before it will write you, with real costs attached, so you are not applying blind. Building those controls takes weeks, so it is worth starting before you apply rather than after a decline.
What exactly do I get at the end?
Four things: a written report dated and specific to your environment, a prioritized remediation roadmap with real costs, a cyber insurance answer sheet mapped to standard carrier questions, and a 45 minute walkthrough call.
Do you sell the fixes too, or just the report?
The report stands on its own, and you can hand it to any provider to act on. If you would like me to close the gaps, I can, but there is no obligation and no upsell built into the assessment.
What areas do you serve?
I am based in southern Chester County, PA and cover the surrounding region on site: Chester County PA, northern Delaware, and northern Maryland.
Get an assessment on the calendar.
Tell me a little about your business and I will follow up to schedule. Most assessments take a single half day on site. Prefer to call? Both numbers are below.
A registered Delaware business based in southern Chester County, PA, also serving northern Delaware and northern Maryland. Carrying commercial general liability and cyber liability coverage.