What cyber risk data should underwriters actually rely on?

Discover key cyber risk data insights essential for informed underwriting decisions and effective risk management.

Written by Pontus Bergmark (Super Administrator)

Updated at June 18th, 2026

What cyber risk data should underwriters actually rely on?

A cyber underwriter can receive a cyber scan, a questionnaire response, a security rating, and broker-submitted information for the same applicant. Each source describes a different slice of risk. The data with the strongest underwriting value is fresh, externally observable, attributable, explainable, and relevant to insurance loss. The underwriting question is whether the data shows what is exposed now, why it matters, and whether it belongs to the organisation being assessed.

 

Cyber underwriting relies on data that can show observable exposure, explain the mechanics behind that exposure, and connect the finding to material risk. The strongest external signals are confirmed, current, and tied to the assessed organisation.

Questionnaires, ratings, scans, and broker information can all play a role. Their value depends on what they can evidence. A questionnaire can capture self-reported controls. A rating can support comparison. Broker information can add context. External scanning can show public-facing exposure.

For insurance assessment, the most useful data is the evidence layer: what was observed, when it was observed, where it was found, and why it matters for loss.


Examples of useful underwriting evidence

Fresh external exposure: a live scan shows a public-facing service or vulnerable software that is present at the point of assessment.

  • Attributable footprint: a domain, subdomain, IP, mail server, or cloud service is connected to the organisation being assessed rather than a similarly named or shared environment.
     
  • Loss-relevant finding: an issue such as exposed remote access, weak email authentication, or vulnerable software is filtered for materiality rather than treated as one item in a long technical list.
     
  • Useful internal context: a questionnaire response explains backup practices, training, controls, or incident history that external observation cannot see.

Which cyber signals carry underwriting value?

Data type

What it can show

Main limitation

Live external scan

Current public-facing exposure and confirmed risk signals.

Does not inspect internal controls or private systems.

Questionnaire

Self-reported controls, processes, training, and incident history.

May be incomplete, misunderstood, or difficult to validate.

Security rating

A comparable summary of broad cyber posture.

Can hide finding-level evidence and freshness.

Broker information

Business context, operations, and placement details.

May lack technical depth or consistency.

Public vulnerability context

Severity, exploitation likelihood, and known exploitation status.

Needs to be tied to the insured's actual exposed assets.


The most useful data is the set of confirmed signals that explains material exposure in a form that an underwriting team can interpret consistently. 

How scores are used in cyber underwriting

Scores and ratings are often used to compare organisations quickly, triage submissions, or give a broad view of cyber posture across a book. BitSight's numerical rating and SecurityScorecard's A-F grade are examples of summary-layer outputs.

For underwriting, scores are usually most useful as a summary layer rather than the full evidence base. The detail behind the score still matters: what was observed, how recently it was observed, which assets were included, and why the finding changes the risk view.

Why live external footprint data matters at bind stage

Live external footprint data shows what an applicant exposes to the internet at the point of assessment. That matters because cyber posture changes when software is patched, services are exposed, domains are added, email controls are changed, or a new CVE changes the relevance of visible technology.

For SMB underwriting, live scanning is especially useful when the applicant is not already well represented in a pre-existing data library. From a single domain, an external scan can generate current evidence without requiring the insured to behave like a large enterprise.

Why data freshness changes cyber risk assessment

Cyber risk data loses value when it describes an organisation as it was days or weeks ago. A cached result can miss a newly exposed service, continue showing a vulnerability that has been fixed, or present an old view of the organisation's footprint.

On-demand assessments reduce that gap by observing the applicant at the point of request. KYND assessments are generated on demand, with scan-to-result time under five minutes.

Where this framing does not fully apply

External cyber risk data cannot show everything about an organisation. It does not see internal network controls, employee behaviour, endpoint telemetry, offline processes, or every private cloud configuration.

That limitation is part of the methodology. External data is strongest when the question concerns observable exposure, attack surface, loss-relevant signals, and consistency at underwriting volume. Internal context still matters where the decision depends on controls that external observation cannot see.


Frequently asked questions

Is a security rating the same as cyber risk data for underwriting?

No. A security rating summarises cyber posture, while underwriting data needs finding-level evidence, freshness, and relevance to insurance loss. Ratings can support comparison, but they do not replace the evidence behind the result.

 
 

What is the difference between CVSS, EPSS, and CISA KEV?

CVSS describes vulnerability severity. EPSS estimates the likelihood of exploitation. CISA KEV lists vulnerabilities known to have been exploited. Underwriting value improves when these sources are connected to confirmed exposure on the assessed organisation.

 
 

The data worth relying on has a trail

The strongest underwriting data describes the organisation as it is now. It is current, attributable, explainable, and connected to insurance loss.