ITC Vegas 2026 · Meet Astragar
See cyber risk as it really is.
Astragar turns live cybersecurity evidence into quantified business and financial risk, helping insurers understand what they are actually underwriting.
We bring together vulnerabilities, sensitive data, controls and AI-agent activity to show what can go wrong, what it could cost, and what is reducing the risk.
Cyber Risk Quantification
Data Risk
Control Evidence
AI Agent Risk
The insurance problem
Cyber insurance still relies on too much assumption.
Questionnaires
Questionnaires tell you what should be true.
Security questionnaires and declarations provide useful information, but they are largely point-in-time and self-reported.
Security tools
Security tools tell you what is technically wrong.
CVSS scores, vulnerability counts and security ratings rarely tell an underwriter what those weaknesses could actually cost.
Astragar
Astragar shows you what the evidence says.
We connect vulnerabilities, sensitive data, business-critical assets and controls to quantify potential financial impact and the residual risk that remains.
The Astragar evidence model
From security evidence to underwriting evidence.
Each layer answers a question an underwriter actually needs answered. Together they show what risk is really being insured.
01
Vulnerabilities
What’s exposed?
02
Sensitive Data
What’s actually at risk?
03
Business Assets
What does the organisation depend upon?
04
Controls
What’s reducing the risk?
05
Financial Impact
What could an incident cost?
06
Residual Cyber Risk
What risk are you actually insuring?
What risk are you actually insuring? That is the question Astragar is built to answer.
Capabilities
One platform. Multiple layers of cyber evidence.
Data risk
Sensitive data, valued.
Discover sensitive data automatically and quantify its financial value.
Why insurers care
Understand the potential severity behind a data breach rather than simply knowing that a vulnerability exists.
Vulnerability risk
Vulnerabilities, prioritised.
Identify vulnerabilities and prioritise them according to the value and sensitivity of the assets they expose.
Why insurers care
Separate vulnerabilities that genuinely affect loss potential from thousands that may have little material impact.
Control evidence
Controls, evidenced.
Test controls across multiple frameworks and maintain evidence of compliance and control effectiveness.
Why insurers care
Move beyond asking whether a control exists towards evidence of whether it is actually operating.
AI agent risk
AI agents, monitored.
Aeguard monitors AI agents, including attribution, permissions, behavioural activity and tamper-evident activity logging.
Why insurers care
Gain evidence around an emerging exposure that conventional cyber questionnaires were never designed to assess.
Quantification
Cyber risk, quantified.
Bring vulnerability, data, control and AI-agent evidence together to estimate potential business and financial impact.
Why insurers care
Translate cyber posture into information that can actually support risk selection, pricing and portfolio decisions.
Insurance use cases
What could this change for cyber insurance?
Underwriting
Make better-informed risk decisions.
Supplement questionnaires with evidence of the organisation’s actual cyber posture and financial exposure.
Potential outcome
Better risk selection and clearer Accept / Refer / Decline decisions.
Renewal
Show what has changed.
Compare risk, controls and exposure over time rather than repeating essentially the same annual assessment.
Potential outcome
Evidence for differentiated pricing, terms and coverage.
Broking
Match coverage to actual exposure.
Quantified scenarios can help brokers and insureds understand potential loss magnitude.
Potential outcome
Better-informed decisions around limits, sub-limits, retentions and policy structure.
Portfolio
See risk beyond an individual insured.
Aggregate quantified exposure and common risk drivers across insured organisations.
Potential outcome
Identify concentrations and emerging systemic exposures earlier.
At ITC Vegas
Three conversations we’d like to have at ITC Vegas.
01
Carriers & Reinsurers
Can better cyber evidence improve underwriting and portfolio decisions?
We are looking to work with insurers interested in testing how vulnerability, data and control evidence could augment their existing underwriting process.
Talk to us
02
Brokers
Can quantified cyber exposure help clients buy better-matched cover?
We’re exploring how brokers can use quantified risk and control evidence during placement and renewal.
Talk to us
03
Innovation Partners
Help us build the next generation of cyber insurance evidence.
We are looking for a small number of partners interested in pilots using real-world cyber risk data and insurance workflows.
Explore a pilot
Pilot
Don’t buy another platform. Test the idea first.
Start with one book, one portfolio, one business unit or one underwriting question. A pilot can test whether Astragar’s evidence improves an existing cyber-risk decision without requiring a platform rollout.
For example
Question
Which vulnerabilities materially change the financial exposure of this insured?
Astragar
Analyse vulnerabilities + sensitive data + assets + controls.
Output
Quantified inherent and residual risk with the principal drivers identified.
Decision
Test whether that evidence changes underwriting, pricing, coverage or remediation decisions.
Small scope. Real data. Measurable outcome.
The vulnerability isn’t the risk.
A vulnerability matters because of what it exposes, what depends on it, what controls surround it and what happens to the business if it is exploited.
Astragar connects those dots.
Going to ITC Vegas?
Let’s spend 20 minutes looking at a cyber risk the way an underwriter would. Bring us a vulnerability, risk scenario or underwriting problem. We’ll show you how Astragar would approach it.
Book a meeting at ITC Vegas
Shailesh Chirputkar
Co-founder & CTO, Astragar
Cyber risk. Evidenced. Quantified. Insurable.

