Skip to contentAbout Fig Group
Insurer-grade evidence

Prepare cybersecurity evidence for external review.

Five security controls that may be considered during an insurance review, how to implement them, and how to maintain evidence you control and can share with your chosen recipient.

Fig provides compliance software and evidence reporting. It does not provide, arrange, distribute, place, or advise on insurance, and it does not promise any insurance outcome.

Why Maintained Evidence Matters

Prepare current records before an external reviewer asks for them

The request

Detailed control questions

Insurers, brokers, and underwriters may ask for information about technical controls, governance, incident readiness, and risk management. The exact requirements are set by the recipient.

The response

Insurer-grade evidence

Structured, dated, and traceable records can help your organisation respond clearly when an external reviewer requests supporting information.

The challenge

Evidence in the right format

For many organisations the challenge is collecting current evidence without rebuilding it from screenshots and documents. Fig maintains the underlying records and lets the customer control each export.

Five Controls to Evidence

Common review topics and how Fig helps you maintain the underlying records

1

Implement Multi-Factor Authentication Everywhere

MFA is commonly requested in cyber insurance reviews. Apply it to remote access, email, administrative consoles, cloud platforms, and VPN connections, with particular attention to privileged accounts.

How Fig collects evidence

Fig collects MFA deployment evidence from Azure AD, Microsoft 365, Google Workspace, and other identity providers. Customers can export a report showing which accounts have MFA enabled and choose whether to share it with an insurer, broker, or underwriter.

2

Establish a Documented Patch Management Programme

Unpatched systems are involved in a significant proportion of successful breaches. Insurers want to see that you have a defined patching cadence: critical vulnerabilities remediated within 14 days, high-severity within 30 days, and routine patches applied within 90 days. Beyond the policy, they want evidence that you actually follow it.

How Fig collects evidence

Fig tracks patch status across your infrastructure, generates compliance reports against your defined SLAs, and flags overdue patches. Customers can include these records in an evidence export when requested.

3

Encrypt Data at Rest and in Transit

Encryption is a baseline expectation for any organisation applying for cyber insurance. This means full-disk encryption on all endpoints, TLS 1.2 or higher for data in transit, and encryption of sensitive data stores including databases and backups. Insurers view encryption as a fundamental control that significantly limits the blast radius of a breach.

How Fig collects evidence

Fig verifies encryption status across endpoints and cloud services, documenting compliance with your encryption policy. Reports show encryption coverage percentages and highlight any gaps.

4

Build and Test an Incident Response Plan

External reviewers may ask whether an incident response plan has been tested, whether roles and responsibilities are defined, and whether procedures address events such as ransomware, data breaches, and business email compromise.

How Fig collects evidence

Fig includes incident response playbooks, tracks tabletop exercise completion, and maintains an audit trail of incidents and response actions. Customers decide whether to share these records externally.

5

Deploy Continuous Vulnerability Scanning and Remediation

Point-in-time penetration tests are valuable, but insurers increasingly expect continuous vulnerability management. This means regular automated scanning of internal and external assets, prioritised remediation based on exploitability and business impact, and documented evidence of vulnerability closure rates over time. Organisations that can show a declining trend in open vulnerabilities demonstrate proactive risk management.

How Fig collects evidence

Fig runs continuous vulnerability scans, prioritises findings by severity and exploitability, assigns remediation tasks, and tracks closure rates. Trend reports provide a dated record of how findings were managed.

Frequently Asked Questions

Common questions about customer-controlled evidence sharing

Does using Fig reduce cyber insurance premiums?

Fig does not promise or calculate premium savings. Insurance providers make their own underwriting and pricing decisions. Fig helps customers maintain insurer-grade compliance evidence that they may choose to share with an insurer, broker, or underwriter.

Which controls do cyber insurance underwriters care about most?

The controls that consistently appear in underwriting questionnaires are: multi-factor authentication (particularly on privileged and remote access), patch management with defined SLAs, endpoint detection and response, email security and anti-phishing measures, backup and recovery procedures, encryption, incident response planning, and security awareness training. MFA and patch management are the two most heavily weighted.

Do I need Cyber Essentials certification for an insurance review?

Requirements vary by provider and policy. A customer can share its Cyber Essentials certification and supporting compliance records when requested, but the insurer or underwriter decides what is required and how it is assessed.

How can Fig evidence be used during an insurance review?

Customers can export records covering MFA, patch compliance, vulnerability findings, incident response documentation, and encryption status, then choose whether to share them with an insurer, broker, or underwriter. Fig does not complete or submit insurance applications.

Can framework evidence be included in an external review?

Yes. Customers can export evidence associated with frameworks such as ISO 27001, SOC 2, Cyber Essentials, and NIS2. The recipient decides whether the certification or evidence is relevant to its review.

What evidence should I prepare before my insurance renewal?

Start preparation at least 60 days before renewal. Gather: a current MFA deployment report showing coverage percentages, patch compliance reports for the past 12 months, vulnerability scan results showing trending improvement, a copy of your incident response plan with evidence of tabletop exercises, encryption status reports, security awareness training completion rates, and any compliance certifications you hold. Fig can generate all of these reports on demand.

Does Fig influence an insurer's decision?

No. Fig supplies compliance software and evidence reporting. It does not advise on, arrange, distribute, place, bind, underwrite, or administer insurance, and it does not determine pricing, terms, acceptance, or renewal outcomes.

Can I share Fig reports with an insurance broker or carrier?

Yes. You can download standardised reports and choose whether to share them with your insurer, broker, carrier, or underwriter. Fig does not select the recipient or transmit an insurance application on your behalf.

Build Insurer-Grade Compliance Evidence

Keep security and governance records current, then choose what to export and share with your insurer, broker, or underwriter.