DSE Cybersecurity · Regulated readiness lane

Answer the questionnaire with evidence.

A cyber insurance application asks control questions your team answers from memory, under renewal pressure, with a signature attached. This engagement turns those answers into evidence: what is actually in place, what the honest answer is, and what you would need to change to answer differently next cycle. DSE is not an insurance broker, agent, or producer, does not place coverage, and cannot speak for any carrier.

For organizations preparing a cyber insurance application or renewal. Readiness and advisory work. Not insurance advice, not a coverage opinion, not a guarantee of eligibility, premium, or claim outcome.

Entity scope

Who this is for, and who it is not for.

This lane has no regulator and no rule. It is scoped by a commercial event: an application, a renewal, or a carrier's post-quote control condition. That makes the honest scoping statement more important, not less.

In scope

First-time applicants

Organizations buying cyber cover for the first time who have discovered that the application asks about controls nobody has documented and nobody owns.

In scope

Renewals with new questions

Existing insureds facing a longer questionnaire than last year, or a broker relaying that the market wants proof rather than a checkbox.

In scope

Post-quote conditions

Organizations that received a quote conditioned on specific controls being in place by a date, and who need a plan and evidence rather than an assertion.

In scope

Signers who want to be accurate

The officer who has to sign the application and would like the answers to be true, traceable, and defensible if the file is ever read back to them.

In scope

Regulated firms with overlap

Firms whose underwriting questions overlap an obligation they already carry, where the same evidence should serve both rather than being assembled twice.

In scope

Boards asking the question

Leadership that wants a plain read on where the organization stands against what the market is asking for, before the renewal conversation rather than during it.

This lane is not for you if: you want coverage placed, quoted, marketed, or negotiated, which is a licensed broker's or producer's work and is not what DSE does; you want a coverage opinion, a policy-wording review, or advice on whether a specific loss would be covered, which belongs to your broker and your counsel; you want help with a live claim, a claim denial, or a coverage dispute, which is claims advocacy and counsel's work; you want a guarantee that you will be offered terms, that your premium will fall, or that a future claim will be paid, because no consultancy can offer that and we will not imply it; or you want us to complete and sign the application for you. The answers on the application are your representations to the carrier. We help you make them accurate. We do not make them for you.

Underwriting requirements are set by each carrier, differ between carriers, and change between cycles. We do not speak for any carrier, do not represent any carrier's current appetite, and do not claim to know what any specific underwriter will accept.

The honest framing

There is no rule here. That is the point.

The other lanes in this practice are anchored to a citation. This one is not, and we will not manufacture one. Cyber insurance eligibility is governed by each carrier's underwriting, not by any federal regulation. What we can do is make your control evidence real, organize it against a published control framework, and reuse it wherever an actual obligation does exist.

01

We organize against NIST CSF 2.0

Findings and evidence are structured against the NIST Cybersecurity Framework 2.0 functions so the same work answers a questionnaire, a customer diligence review, and a board question. Framework alignment is an organizing choice, not a compliance outcome, and it is not an endorsement by NIST.

02

We use CISA CPGs as a floor

The CISA Cross-Sector Cybersecurity Performance Goals give a public, vendor-neutral baseline of practices to check against. They are a voluntary reference, not a rule, and we describe them that way.

03

We reuse regulated-lane evidence

Where you already carry an obligation, the evidence should serve twice. A written risk assessment, an incident response plan, access-control records, and recovery evidence built for a rule are usually the same artifacts an application asks about.

04

We separate answer from aspiration

Each question gets the answer your evidence supports today, not the answer you intend to be able to give. Where the honest answer is no, that is recorded as a gap with an owner and a date, not softened.

05

We record what evidence exists

An answer with no artifact behind it is flagged. The point of the engagement is that if anyone later asks how you knew, there is a document, a date, and an owner.

06

We do not run the controls

DSE does not provide continuous monitoring, managed detection and response, or a 24x7 SOC. Where a questionnaire asks about a capability we do not operate, we help you scope the requirement and select a provider you contract directly.

Where an obligation does exist, we say which one. An organization in scope of 16 CFR part 314, 17 CFR 248.30, or 45 CFR part 164 subpart C already owes specific artifacts. Those citations are worked in their own lanes, and this engagement maps the overlap so the same evidence is produced once.

Sample output

Answer, evidence, gap, owner.

Synthetic sample—illustrative only. It contains no client information, no carrier's actual questionnaire, and is not a finding about any organization or a representation of any underwriter's requirements.

The sample table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.

Synthetic control evidence register excerpt
Control topicEvidence producedSupportable answer todayGap, owner, and date
Multi-factor authentication on remote accessPolicy export plus a sample of enrolled accounts; two service accounts outside the policy.Partial. Enforced for staff, not for two automation paths.Close or compensate the two paths. Owner: identity lead. Target: 30 days.
Tested backup restorationBackup job history for 12 months; no record of a completed restore test.No. Backups run; a restore has not been demonstrated.Run a client-executed representative restore and record recovery time. Owner: infrastructure lead. Target: 45 days.
Written incident response planA four-page document last revised two years ago, with two named responders no longer employed.Exists but stale. Roles and decision rights are not current.Revise roles and escalation, then exercise. Owner: security owner. Target: 60 days.

Actual questions, wording, and thresholds are set by each carrier and change between cycles. This sample illustrates the shape of the deliverable, not any carrier's requirements.

Deliverables

What you actually walk away with.

01

Control evidence register

Each control topic on your application mapped to the evidence that exists, the answer that evidence supports, the artifact location, the date, and the owner. This is the document the engagement is built around.

02

Answer-support pack

The supporting artifacts assembled and indexed so the person signing the application can see, for each answer, exactly what it rests on. Assembled for your signer; not submitted by us.

03

Gap list with remediation plan

Every question where the honest answer today is no or partial, with the specific change required, the owner, the effort, and a target date sequenced against your renewal calendar.

04

Obligation overlap map

Where an application topic also maps to an obligation you already carry under 16 CFR part 314, 17 CFR 248.30, or 45 CFR part 164 subpart C, so evidence is produced once and used twice.

05

Broker-ready summary

A concise written summary of posture and in-flight remediation your broker can use in their own conversation with the market. We write it for you to give them; we do not speak to carriers on your behalf.

06

Next-cycle roadmap

What to change over the next twelve months so next year's answers are different, sequenced by risk reduction and effort rather than by which question felt most uncomfortable.

Typical timebox: 2 to 3 weeks after kickoff and timely evidence access. Multi-entity groups and complex estates are scoped separately. Fees are scoped after the diagnostic and confirmed in writing before work begins. This lane rides on the same evidence method as the cybersecurity risk assessment; where recovery and response answers are the weak ones, it pairs with incident response and ransomware readiness. Where remediation implementation follows the readiness cycle, it is scoped separately in writing and may be delivered by a disclosed qualified specialist from DSE's expert network. DSE remains accountable for scope, quality, and integration.

Primary sources

Frameworks we organize against.

There is no primary regulatory source for cyber insurance eligibility, because no federal rule sets it. These are the public control references we organize evidence against, plus the actual obligations that overlap.

We do not publish claim-denial rates, premium averages, market loss ratios, or the share of applications rejected for a given control. Those numbers circulate widely and we could not source them from a primary source, so they do not appear on this page.

Clear boundaries

Evidence work, not insurance.

This is a point-in-time readiness assessment of the systems, people, documentation, and evidence in the agreed scope. DSE is not an insurance broker, agent, producer, adjuster, or carrier, is not licensed to transact insurance, does not place, market, bind, or negotiate coverage, and cannot speak for any carrier or represent any carrier's underwriting requirements. Nothing here guarantees eligibility for cover, the availability of terms, a premium, a limit, a retention, or the outcome of any claim, and nothing here is a coverage opinion or advice on whether a loss would be covered. It is not legal advice, not an audit, not a certification, not an attestation, and not a regulatory examination. It does not guarantee compliance, an enforcement outcome, insurance coverage, eligibility, or a contract award. It does not make your organization secure and does not prevent, detect, or reduce the likelihood of any security incident; it documents risk against a defined scope at a point in time. DSE does not operate a security operations center, does not provide continuous monitoring or managed detection and response, does not perform live incident response or digital forensics and incident response (DFIR), and does not run penetration tests. Where you need any of those, we help you scope the requirement and select a provider you contract directly. Remediation implementation is the one item on this list DSE will perform, and only where it is separately scoped in writing. DSE does not provide claims advocacy. The answers submitted on an application are your representations, made by your authorized signer. Your broker, your counsel, your auditors, your assessors, and your carriers retain their respective roles.