Cyber liability
Technical controls, incident readiness, vulnerability management, and audit history.
Give your chosen insurer, broker, or underwriter a documented view of cyber controls.
Fig organises continuous compliance data into clear, traceable evidence. You control whether to share it with your chosen insurer, broker, or underwriter.
Fig provides compliance software and evidence reporting. Fig does not advise on, arrange, distribute, place, bind, underwrite, or administer insurance.
Evidence picture: High uncertainty
0 of 3 layers selected
Illustrative evidence overview · not a risk score, quote or prediction of premiums
Five connected steps turn live compliance posture into insurer-grade evidence.
Fig monitors your compliance posture across chosen frameworks. Data flows continuously.
Automatically compile control evidence, audit trails, and assessment results.
Organise relevant records into a clear, consistent view for external review.
Choose which records to include and confirm that the export is appropriate for its intended recipient.
Download and share the evidence with your chosen insurer, broker, or underwriter.


Technical controls, incident readiness, vulnerability management, and audit history.
Give your chosen insurer, broker, or underwriter a documented view of cyber controls.
Governance, quality controls, documented procedures, and corrective actions.
Share evidence of how professional and operational risks are governed.
Board oversight, risk ownership, policy approval, and management reporting.
Present a traceable record of governance activity and accountability.
Policies, training, people processes, and issue management.
Export current records for external review when your organisation chooses.
Give each client a clear record they can review and share with their own insurer, broker, or underwriter.
Give each client a structured record of controls, assessments, and audit activity.
Clients decide whether to export their evidence and share it with an insurer, broker, or underwriter.
Maintain evidence continuously so clients can respond to external information requests without starting again.
Fig supplies compliance software and evidence reporting; insurance decisions and services remain with the client and their chosen provider.
Keep control evidence current and export the records your chosen recipient requests.
Present current controls, ownership, testing, and remediation in a consistent format.
Create a customer-controlled export for an insurer, broker, or underwriter when requested.
Keep supporting records current ahead of external reviews and renewal discussions.
Show how suppliers and MSPs are assessed, monitored, and followed up.
Replace one-off evidence gathering with maintained, traceable records.
Everything you need to know about compliance and insurance.
It means structured, dated, and traceable compliance evidence that a customer can review and share with an insurer, broker, or underwriter. It does not mean that Fig has approved the evidence on behalf of an insurance provider or that any insurance outcome is guaranteed.
No. Each insurer, broker, and underwriter sets its own information requirements and makes its own decisions. Fig helps customers organise and export their compliance records.
Yes. You can use Fig to collect and organise control evidence, audit trails, assessment results, policies, and remediation records, then choose what to share with your selected recipient.
Customers may find the same governance and control records relevant to cyber liability, professional indemnity, D&O, or management liability reviews. The insurer or adviser determines what information is required.
Yes. You control what gets exported and who receives it. Fig does not select the recipient or submit an insurance application on your behalf.
Fig records the gap, its owner, remediation activity, and progress. Your organisation decides whether and how that information is shared externally.
That depends on the request and your organisation's disclosure obligations. Review each export before sharing it and take advice from your chosen insurance or legal adviser where needed.
Yes. MSPs can maintain documented controls, audit trails, and monitoring evidence for each client. The client controls whether that evidence is shared with an insurer, broker, or underwriter.
Yes. Clients can log in to a branded view of their own compliance posture and evidence. White-labelling applies only to the Fig Group compliance workspace.
No. Cyber Essentials certification and the compliance platform are separate products. Customers can maintain and export their compliance evidence whether or not they currently hold Cyber Essentials.
No. Customers review and export their own evidence, then choose whether to share it with an insurer, broker, or underwriter. Fig does not select providers or submit applications.
No. Fig does not recommend insurance products or providers and does not advise on, arrange, distribute, place, bind, underwrite, or administer insurance. Customers should use an appropriately authorised insurance provider or adviser.
See how Fig can help your organisation maintain records for customer-controlled sharing.