Skip to content
Insurer-grade evidence

Prepare cybersecurity evidence for external review.

Five security controls that may be considered during an insurance review, how to implement them, and how to maintain evidence you control and can share with your chosen recipient.

Fig Group provides compliance software and evidence reporting. It does not provide, arrange, distribute, place, or advise on insurance, and it does not promise any insurance outcome.

Why Maintained Evidence Matters

Prepare current records before an external reviewer asks for them

The request

Detailed control questions

Insurers, brokers, and underwriters may ask for information about technical controls, governance, incident readiness, and risk management. The exact requirements are set by the recipient.

The response

Insurer-grade evidence

Structured, dated, and traceable records can help your organisation respond clearly when an external reviewer requests supporting information.

The challenge

Evidence in the right format

For many organisations the challenge is collecting current evidence without rebuilding it from screenshots and documents. Fig Group maintains the underlying records and lets the customer control each export.

Five Controls to Evidence

Common review topics and how Fig Group helps you maintain the underlying records

1

Implement Multi-Factor Authentication Everywhere

MFA is commonly requested in cyber insurance reviews. Apply it to remote access, email, administrative consoles, cloud platforms, and VPN connections, with particular attention to privileged accounts.

How Fig Group collects evidence

Fig Group can organise MFA records from supported connected identity providers. Check account coverage and the last successful source update before exporting a report for an insurer, broker or underwriter you choose.

2

Establish a Documented Patch Management Programme

Set patch deadlines according to your risk, contractual requirements and the insurer’s actual questionnaire. Keep a record of critical and high-severity findings, exceptions, remediation dates and verification; a written cadence alone does not prove patches were applied.

How Fig Group collects evidence

Fig Group tracks patch status across your infrastructure, generates compliance reports against your defined SLAs, and flags overdue patches. Customers can include these records in an evidence export when requested.

3

Encrypt Data at Rest and in Transit

Review encryption at rest and in transit for the systems in your application scope, including endpoints, cloud services, databases and backups. Record exceptions and the methods used; the insurer decides which controls and evidence its policy requires.

How Fig Group collects evidence

Fig Group can organise encryption status reported by connected endpoint and cloud sources. Validate source coverage and exceptions against your policy before presenting a coverage percentage externally.

4

Build and Test an Incident Response Plan

External reviewers may ask whether an incident response plan has been tested, whether roles and responsibilities are defined, and whether procedures address events such as ransomware, data breaches, and business email compromise.

How Fig Group collects evidence

Fig Group includes incident response playbooks, tracks tabletop exercise completion, and maintains an audit trail of incidents and response actions. Customers decide whether to share these records externally.

5

Run Regular Vulnerability Scanning and Remediation

Point-in-time penetration tests are valuable, but insurers increasingly expect continuous vulnerability management. This means regular automated scanning of internal and external assets, prioritised remediation based on exploitability and business impact, and documented evidence of vulnerability closure rates over time. Organisations that can show a declining trend in open vulnerabilities demonstrate proactive risk management.

How Fig Group collects evidence

Fig Group can consolidate findings from supported scanners, prioritise and assign remediation work, and retain dated verification records. Review the scanner scope and latest scan before sharing a trend report.

Frequently Asked Questions

Common questions about customer-controlled evidence sharing

Does using Fig Group reduce cyber insurance premiums?

Fig Group does not promise or calculate premium savings. Insurance providers make their own underwriting and pricing decisions. Fig Group helps customers maintain insurer-grade compliance evidence that they may choose to share with an insurer, broker, or underwriter.

Which controls do cyber insurance underwriters care about most?

Questionnaires vary by insurer and policy. Common topics include multi-factor authentication, patching, endpoint and email security, backup and recovery, encryption, incident response and staff awareness. Ask your chosen insurer or broker which controls and evidence it requires.

Do I need Cyber Essentials certification for an insurance review?

Requirements vary by provider and policy. A customer can share its Cyber Essentials certification and supporting compliance records when requested, but the insurer or underwriter decides what is required and how it is assessed.

How can Fig Group evidence be used during an insurance review?

Customers can export records covering MFA, patch compliance, vulnerability findings, incident response documentation, and encryption status, then choose whether to share them with an insurer, broker, or underwriter. Fig Group does not complete or submit insurance applications.

Can framework evidence be included in an external review?

Yes. Customers can export evidence associated with frameworks such as ISO 27001, SOC 2, Cyber Essentials, and NIS2. The recipient decides whether the certification or evidence is relevant to its review.

What evidence should I prepare before my insurance renewal?

Start early enough to resolve missing evidence before your renewal deadline. Depending on the insurer’s request, gather current MFA, patch, vulnerability, incident-response, encryption and training records, plus any certifications you hold. Fig Group can organise available connected records for customer-controlled export; confirm source coverage, dates and missing evidence before sharing.

Does Fig Group influence an insurer's decision?

No. Fig Group supplies compliance software and evidence reporting. It does not advise on, arrange, distribute, place, bind, underwrite, or administer insurance, and it does not determine pricing, terms, acceptance, or renewal outcomes.

Can I share Fig Group reports with an insurance broker or carrier?

Yes. You can download standardised reports and choose whether to share them with your insurer, broker, carrier, or underwriter. Fig Group does not select the recipient or transmit an insurance application on your behalf.

Build Insurer-Grade Compliance Evidence

Keep security and governance records current, then choose what to export and share with your insurer, broker, or underwriter.