Skip to content

Cyber-Insurance Renewal Pack

Walk into your cyber-insurance renewal with every control the questionnaire asks for - hardened, evidenced when it mattered, and guaranteed before your date.

No cost, no obligation - you keep the report either way.

Track record

40%90%+

Microsoft Secure Score, regulated finance teams

  • Every questionnaire control hardened and evidenced
  • Mapped control by control, ready to submit
  • Guaranteed complete before your renewal date

The problem

A cyber-insurance questionnaire no longer accepts 'everyone signs in with a second step' as an answer. Insurers now want evidence that each control was enforced when it mattered - multi-factor authentication (MFA) covering every account, administrators included, privileged access, endpoint protection, tested backups, a written incident-response plan. For finance and insurance teams especially, a failed renewal, a premium shock, or a coverage exclusion is a board-level event. And it arrives on a fixed date you cannot move. The work is rarely a single product; it is a coherent identity, device, and data posture, hardened to the baseline your insurer actually checks, evidenced control by control, and finished before the deadline.

What's Included

  • Identity, device, and data controls hardened to the baseline on your insurer's or auditor's questionnaire: a second sign-in step on every account, administrators included; admin rights held by as few people as possible; sign-in rules that block a risky login before it succeeds; company devices managed and protected; and backups proven by an actual restore
  • An evidence pack mapping each control to the exact question it answers, ready to submit - exported settings, coverage reports, and dated screenshots showing the control was on and covering everyone, rather than an assurance the insurer has to take on trust
  • Microsoft Secure Score uplift with a prioritised, risk-ranked remediation plan - Microsoft's own measure of how well your tenant is configured, moved by fixing what carries the most risk first, with anything deliberately left recorded and explained
  • A short board-ready summary of what was already safe, what was fixed, and what to monitor - written in plain English for the people who sign the policy, not the people who configure the tenant

What This Assumes

  • You provide the insurer or auditor questionnaire that defines the in-scope controls, and a named owner on your side
  • Microsoft licensing sufficient for the controls in scope - typically Microsoft Entra ID P1 or P2, Microsoft Defender for Endpoint, and Microsoft Intune; any add-on needed is flagged at scoping
  • Administrative access and agreed change windows to apply and evidence the controls

Not Included

  • Systems outside Microsoft 365 and Microsoft Azure that the questionnaire also covers
  • Penetration testing, live incident response, and non-technical controls such as HR, physical security, and written policies you own
  • The broker or insurer negotiation itself - we harden and evidence the estate; you or your broker submit the questionnaire

Baselines & Accreditations

We specialise in aligning your estate with the baselines and accreditations that matter most to your business.

  • Cyber Essentials & Cyber Essentials Plus

    The UK government-backed scheme insurers increasingly expect - and, from April 2026, one that demands stronger technical proof of control effectiveness and mandatory MFA.

  • Microsoft Security Baseline

    Microsoft's recommended security configuration for Windows, Microsoft 365, and Microsoft Entra, applied and enforced as a consistent tenant baseline.

  • CIS Controls & Benchmarks

    Center for Internet Security Controls and configuration Benchmarks, mapped to your Microsoft 365 estate.

  • NIST Cybersecurity Framework

    The NIST Cybersecurity Framework (CSF 2.0) - a risk-based structure for governing, identifying, protecting, detecting, and responding across your estate.

  • ISO 27001

    The international standard for an information security management system (ISMS), with the technical controls in place to support certification.

  • SOC 2

    System and Organization Controls 2 - the trust-services criteria (security, availability, confidentiality) your customers and auditors expect.

Partners

We work with specialist tooling partners for audit and independent verification, so the picture of your posture is evidence-based rather than opinion.

Automated posture audit

Audit & reporting

Automated posture audit against recognised baselines, giving a clear, evidence-based picture of where you stand before the questionnaire lands.

Continuous compliance monitoring

Third-party verification

Continuous compliance monitoring and independent verification, so evidence stays current between renewals.

Outcomes

  • A renewal or audit passed on the questionnaire's own terms - evidenced, not asserted
  • Every scoped control mapped to the question it answers, ready to submit
  • A measurably stronger posture - we have taken regulated finance teams from the low Secure Score ranges (around 40%) to over 90%
  • No last-minute scramble the week the questionnaire lands

Who It's For

  • Finance, insurance, and other regulated teams on Microsoft 365 with a cyber-insurance renewal or audit date approaching
  • Organisations whose last renewal was painful - more questions, higher premiums, or controls they could not evidence
  • IT and security leads who need the renewal handled as a fixed-price outcome, not an open-ended project

How to Start

Most engagements begin with the free audit and go no further until you have seen where you stand.

Posture Audit

Free

An automated posture audit of your Microsoft 365 estate against the baselines above, followed by a call to talk through what your renewal will hinge on.

  • A take-away report showing where your posture stands against each baseline
  • The controls your insurer or auditor is most likely to press on, identified with you
  • A conversation about what closing the gaps before your date would involve

No cost, no obligation. We onboard a limited number of new estates each month, and return your findings within 5 working days of read access.

The Cyber-Insurance Renewal Pack

from £16,000 / $20,500

A fixed-price engagement timed to your renewal or audit date: the controls insurers and auditors now demand, hardened and evidenced before the deadline.

  • Identity, device, and data controls hardened to your insurer's or auditor's questionnaire
  • An evidence pack mapping each control to the question it answers, ready to submit

The Renewal Guarantee: every scoped control hardened and evidenced before your date, or we keep working free until it is. And where a control is entirely ours to deliver - MFA coverage, a Secure Score target, a tested restore - if it does not meet the agreed standard, we refund that part of the fee.

Renewal, Handled

from £25,000 / $32,000

Everything in the Renewal Pack, plus the questionnaire completed from your evidence, your broker and underwriter liaised with, and the renewal submitted and defended - the whole renewal off your plate, not just the technical hardening.

  • Everything in the Cyber-Insurance Renewal Pack - every scoped control hardened and evidenced before your date
  • Your insurer's or broker's questionnaire completed from the evidence pack, ready for sign-off
  • Broker and underwriter liaison, and the renewal submitted and defended on the technical detail

For teams that want the whole renewal handled, not just the estate hardened. We cannot guarantee an underwriter's decision, so this tier's guarantee is on readiness and submission: every scoped control evidenced and the questionnaire submission-ready before your date, or we keep working free.

Continuous Evidence

from £3,500 / $4,500

An ongoing retainer that handles next year's renewal for you - the evidence kept current between renewals and regenerated for the date, so the renewal is never re-bought as a fresh pack and never a scramble.

  • Next year's renewal handled inside the retainer - evidence regenerated and submitted for the date, not re-scoped as a new engagement
  • A fixed amount of expert time each month on the highest-priority security work
  • A forward plan of security initiatives, reprioritised every month

Start on a 90-day term, not a year - a full quarter to see the value before it rolls to month-to-month. Month one: a posture baseline and a first evidence pack. Pre-pay the year for eleven months' price, timed to land the evidence just before your renewal.

Engagement Model

A fixed-price engagement timed to your renewal or audit date: a defined scope, named deliverables, and a price agreed before any work starts. No day rates, no open-ended time and materials. And the outcome is guaranteed, not just the effort: every control we scope in is hardened and evidenced before your date, or we keep working at no extra charge until it is. And where a control is entirely ours to deliver - full MFA coverage, a Secure Score target, a tested backup restore - we go further: if it does not meet the agreed, evidenced standard, we refund that part of the fee. The risk that the controls actually land sits with us, not you. And once your date is passed, the pack graduates into Continuous Evidence - our monthly retainer - so next year's renewal is handled inside it, evidenced and submitted for the date, never re-bought as a fresh pack or scrambled again.

Pricing: from £16,000 / $20,500 - larger engagements are tailored to scope.

We govern the AI we deliver with

This work is delivered AI-accelerated, so AI tooling reads configuration and log data from your estate along the way. It is fair to ask how that is governed - and the answer is published: which providers we use and on what commercial terms, what client data never reaches a model, that a named architect signs off every output, and that AI tooling holds no standing write access to client systems.

Read our AI policy

Related

Get started

Find out where you stand, free

Most engagements start with a no-cost posture audit against the baselines that matter to you. If a fixed-fee roadmap is the right next step, we'll say so - and if it isn't, we'll say that too.