Prepare cybersecurity evidence for external review.
Five security controls that may be considered during an insurance review, how to implement them, and how to maintain evidence you control and can share with your chosen recipient.
Fig Group provides compliance software and evidence reporting. It does not provide, arrange, distribute, place, or advise on insurance, and it does not promise any insurance outcome.
Why Maintained Evidence Matters
Prepare current records before an external reviewer asks for them
The request
Detailed control questions
Insurers, brokers, and underwriters may ask for information about technical controls, governance, incident readiness, and risk management. The exact requirements are set by the recipient.
The response
Insurer-grade evidence
Structured, dated, and traceable records can help your organisation respond clearly when an external reviewer requests supporting information.
The challenge
Evidence in the right format
For many organisations the challenge is collecting current evidence without rebuilding it from screenshots and documents. Fig Group maintains the underlying records and lets the customer control each export.
Five Controls to Evidence
Common review topics and how Fig Group helps you maintain the underlying records
Implement Multi-Factor Authentication Everywhere
MFA is commonly requested in cyber insurance reviews. Apply it to remote access, email, administrative consoles, cloud platforms, and VPN connections, with particular attention to privileged accounts.
How Fig Group collects evidence
Fig Group can organise MFA records from supported connected identity providers. Check account coverage and the last successful source update before exporting a report for an insurer, broker or underwriter you choose.
Establish a Documented Patch Management Programme
Set patch deadlines according to your risk, contractual requirements and the insurer’s actual questionnaire. Keep a record of critical and high-severity findings, exceptions, remediation dates and verification; a written cadence alone does not prove patches were applied.
How Fig Group collects evidence
Fig Group tracks patch status across your infrastructure, generates compliance reports against your defined SLAs, and flags overdue patches. Customers can include these records in an evidence export when requested.
Encrypt Data at Rest and in Transit
Review encryption at rest and in transit for the systems in your application scope, including endpoints, cloud services, databases and backups. Record exceptions and the methods used; the insurer decides which controls and evidence its policy requires.
How Fig Group collects evidence
Fig Group can organise encryption status reported by connected endpoint and cloud sources. Validate source coverage and exceptions against your policy before presenting a coverage percentage externally.
Build and Test an Incident Response Plan
External reviewers may ask whether an incident response plan has been tested, whether roles and responsibilities are defined, and whether procedures address events such as ransomware, data breaches, and business email compromise.
How Fig Group collects evidence
Fig Group includes incident response playbooks, tracks tabletop exercise completion, and maintains an audit trail of incidents and response actions. Customers decide whether to share these records externally.
Run Regular Vulnerability Scanning and Remediation
Point-in-time penetration tests are valuable, but insurers increasingly expect continuous vulnerability management. This means regular automated scanning of internal and external assets, prioritised remediation based on exploitability and business impact, and documented evidence of vulnerability closure rates over time. Organisations that can show a declining trend in open vulnerabilities demonstrate proactive risk management.
How Fig Group collects evidence
Fig Group can consolidate findings from supported scanners, prioritise and assign remediation work, and retain dated verification records. Review the scanner scope and latest scan before sharing a trend report.
Frequently Asked Questions
Common questions about customer-controlled evidence sharing
Does using Fig Group reduce cyber insurance premiums?
Fig Group does not promise or calculate premium savings. Insurance providers make their own underwriting and pricing decisions. Fig Group helps customers maintain insurer-grade compliance evidence that they may choose to share with an insurer, broker, or underwriter.
Which controls do cyber insurance underwriters care about most?
Questionnaires vary by insurer and policy. Common topics include multi-factor authentication, patching, endpoint and email security, backup and recovery, encryption, incident response and staff awareness. Ask your chosen insurer or broker which controls and evidence it requires.
Do I need Cyber Essentials certification for an insurance review?
Requirements vary by provider and policy. A customer can share its Cyber Essentials certification and supporting compliance records when requested, but the insurer or underwriter decides what is required and how it is assessed.
How can Fig Group evidence be used during an insurance review?
Customers can export records covering MFA, patch compliance, vulnerability findings, incident response documentation, and encryption status, then choose whether to share them with an insurer, broker, or underwriter. Fig Group does not complete or submit insurance applications.
Can framework evidence be included in an external review?
Yes. Customers can export evidence associated with frameworks such as ISO 27001, SOC 2, Cyber Essentials, and NIS2. The recipient decides whether the certification or evidence is relevant to its review.
What evidence should I prepare before my insurance renewal?
Start early enough to resolve missing evidence before your renewal deadline. Depending on the insurer’s request, gather current MFA, patch, vulnerability, incident-response, encryption and training records, plus any certifications you hold. Fig Group can organise available connected records for customer-controlled export; confirm source coverage, dates and missing evidence before sharing.
Does Fig Group influence an insurer's decision?
No. Fig Group supplies compliance software and evidence reporting. It does not advise on, arrange, distribute, place, bind, underwrite, or administer insurance, and it does not determine pricing, terms, acceptance, or renewal outcomes.
Can I share Fig Group reports with an insurance broker or carrier?
Yes. You can download standardised reports and choose whether to share them with your insurer, broker, carrier, or underwriter. Fig Group does not select the recipient or transmit an insurance application on your behalf.
Build Insurer-Grade Compliance Evidence
Keep security and governance records current, then choose what to export and share with your insurer, broker, or underwriter.