QUICK ANSWER
What makes one cyber security business different from another?
Risk can vary according to whether the business provides penetration testing, managed security, monitoring, incident response, advisory work, implementation or other services; what access it has to client systems and data; the value and sensitivity of client environments; and the contractual responsibility accepted.
PROPOSAL INFORMATION
Describe the services, access and responsibility
- Services and percentage of revenue from each.
- Annual turnover and largest clients or contracts.
- Access to client networks, credentials, data or production systems.
- Testing methods and authorisation procedures.
- Managed-service or incident-response commitments.
- Territories and contractual jurisdictions.
- Use of subcontractors or specialist tools.
- Claims, incidents, complaints or known circumstances.
CONTROLS
Evidence authorisation, access control and technical review
Useful evidence can include written scopes, rules of engagement, privileged-access controls, secure handling of client information, peer review, change control, incident escalation, staff competency, subcontractor controls and documented sign-off.
Return to Business Occupations & Risk Profiles or the Commercial Insurance Proposal Guide.
