Skip to main content
ITSIGNSolutions
Confidential client

Turning a declined cyber renewal into a bindable application

The broker came back with four fails: MFA coverage, backup isolation, EDR alerting, and no pentest in two years. We evidenced what was already true, closed the rest in six weeks, and the policy bound.

Financial ServicesGRC Services

6

Weeks to bindable evidence

4/4

Application fails closed

None

Exclusion applied

The challenge

The credit union believed it had MFA and backups. The application asked for evidence. Remote desktop still accepted a password. Backups lived on a share the same domain admin could delete. EDR was licensed on half the endpoints and nobody reviewed alerts. The last test on file was a vulnerability scan labelled as a pentest.

What we did

We ran the insurance evidence review with the broker on the call, then sequenced six weeks of work: MFA on every remote and privileged path, an isolated backup copy with a dated restore test, EDR rolled out and put on a review cadence, and an external-plus-internal pentest with a retest of the highs. The application was rewritten from the evidence pack, not from memory.

The outcome

The policy bound on the original timeline. The underwriter accepted the rebuilt answers without the exclusion that had been threatened. The board now gets a one-page control brief each quarter.

Let's talk about what you are running

A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.