Resources

Cyber Submissions Should Arrive With Exposure Data, Not Just an ACORD Form

Resources

Cyber Submissions Should Arrive With Exposure Data, Not Just an ACORD Form

Resources

Cyber Submissions Should Arrive With Exposure Data, Not Just an ACORD Form

A typical small commercial cyber submission is an application form and some self-attested answers. Does the business use MFA? Yes. Are backups tested? Yes. The underwriter prices on those answers and hopes they hold.

The problem with self-attestation

Self-attested answers are the weakest data in the underwriting file, and they are the data most likely to decide a claim. If an answer turns out to be wrong after a loss, the dispute is expensive for everyone: the insured, the broker and the carrier.

The better question is not "does the applicant say they have MFA" but "what does their external exposure actually look like today".

What Sternwake attaches

Sternwake is an independent US brokerage, appointed by HSB, with a producer licensed in every state across all lines. Every business that places cyber through Sternwake receives a complimentary cyber risk assessment from Astragar. The result travels with the submission.

Standard submission

Sternwake submission

ACORD application

ACORD application

Self-attested controls

Self-attested controls, checked against observed exposure

No view of internet-facing assets

External exposure and exploitable findings

No financial context

Exposure expressed in dollars

The application tells you what the insured believes. The assessment tells you what an attacker would see.

The application tells you what the insured believes. The assessment tells you what an attacker would see.

In plain language

Carriers placing through Sternwake see measured exposure before they quote, not only what the applicant ticked on the form.

Why it matters to distribution teams

  • Better first-pass decisions. Underwriters spend less time chasing clarifications on clean risks.

  • Fewer surprises at claim. Gaps are visible before binding, when they are cheap to fix.

  • A conversation starter. The assessment gives the insured a reason to improve, which supports renewal.

  • A route for declined risks. A business that is declined today can see what to fix and come back.

Two routes, one data layer

Route one is available now: an appointment for Sternwake to place your products. Route two is in development: Astragar, where businesses see their cyber exposure in dollars, is building a one-click "get quotes" request with a small group of launch carriers, who will receive the same exposure data in-platform.

Next step. Interested in an appointment, or in shaping the launch carrier programme? See the carrier partner overview →

For any comments or information please reach out to info@astragar.com

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

©Astragar All rights reserved.