Reference

Cyber insurance posture glossary

Plain-language definitions of the terms that appear on cyber insurance applications, in policy wordings, and in the practice of measuring insurance posture. Each entry links to a deeper guide where one exists.

Insurance and legal terms are described here for orientation only; definitions vary by policy and state law, and nothing on this page is insurance or legal advice. For how these terms fit together, start with what is insurance posture.

A

Attestation

An attestation is a dated, named statement by an organization that a specific control or practice is in place, made when the fact cannot be read directly from a system. Restore testing, tabletop exercises, and written incident response plans are typical attested facts. In Insurance Posture Analyzer, answers are drawn from extracted documents and attestations, and read-only scans cross-check each answer that maps to a scannable control.

C

Canonical question library

A canonical question library is a deduplicated set of cyber insurance application questions built from many carrier forms, so one set of evidenced answers can pre-fill most of what each carrier asks while preserving per-carrier wording. Insurance Posture's library is written in our own wording to reflect the control topics that recur across US cyber application and ransomware supplemental forms; no carrier's form is republished. See the cyber insurance questionnaire guide for a question-by-question walkthrough.

Coinsurance

Coinsurance is a policy provision under which the insured bears a stated percentage of a covered loss alongside the insurer. In cyber policies it most often appears on ransomware and extortion coverage, where a carrier may pay only a portion of an extortion loss and the insured bears the rest. Some carriers have applied coinsurance to risks with specific control gaps.

Compliance posture

Compliance posture is the state of an organization's controls measured against a compliance framework such as SOC 2, ISO 27001, or HIPAA. It differs from insurance posture in what the controls are measured against: an auditor's criteria rather than a carrier's application questions. An organization can hold a clean audit report and still be unable to evidence the specific controls a carrier underwrites.

Condition precedent

A condition precedent is a contractual requirement that must be satisfied before an insurer's obligations under the policy attach. Some cyber policies attach application answers, or the continued operation of named controls, as conditions precedent to coverage. How such provisions are interpreted and enforced varies by policy wording and jurisdiction.

Cyber insurance questionnaire

A cyber insurance questionnaire is the carrier-issued application, renewal application, or ransomware supplemental. Its answers are representations the carrier relies on, and some policies attach them as conditions precedent. Most questionnaires concentrate on six control areas: MFA, backups, EDR, privileged access, email security, and incident response. See the full questionnaire guide and the requirements breakdown.

D

Declination

A declination is a carrier's decision not to offer a quote on a submitted risk. In cyber underwriting, declinations are often tied to specific unmet controls, such as incomplete MFA coverage, missing backup immutability, or exposed remote access. A declination is one possible outcome of a submission; others include modified terms such as higher retentions, sublimits, or coinsurance.

Drift (control drift)

Control drift is the gap that develops when the live state of a security control changes after it was documented or attested, so a statement that was true when written is no longer true in the environment. A conditional access exclusion added in June can silently falsify an MFA answer attested in March. Drift matters for insurance posture because application answers are representations, and scheduled rescans exist to surface drift before submission rather than during a claim investigation.

Drift brief

A drift brief is a broker-ready report listing the application answers a live environment contradicts, together with the evidence for each finding. Its purpose is to let an organization close or disclose gaps before the application is signed, and to give the broker an evidence-backed picture of the risk. Insurance Posture Analyzer produces a drift brief with the evidence files in one place.

E

Evidence-checked answer

An evidence-checked answer is a cyber insurance application answer that has been cross-checked against configuration data collected from the live environment, rather than answered from memory alone. An answer stating that MFA is enforced for administrators is evidence-checked when it is compared against the tenant's actual conditional access policies and role assignments. The share of answers that are evidence-checked is the core measure of insurance posture.

External scan (carrier scanning)

An external scan is an assessment of an organization's internet-facing surface: open ports, exposed remote access such as RDP, certificate hygiene, and email authentication records. Many cyber carriers run external scans during underwriting and score applicants before quoting. An external scan sees only what is visible from the outside; it cannot read internal control state such as MFA policy coverage or backup immutability, which is why carriers also rely on application answers.

I

Insurance posture

Insurance posture is the measurable state of an organization's security controls as cyber insurance carriers evaluate them: the share of carrier application answers that are backed by verifiable evidence rather than answered from memory. A strong insurance posture means what the application says matches what an incident responder would find in the environment. Full definition and category scope: what is insurance posture.

R

Ransomware supplemental

A ransomware supplemental is an additional questionnaire many carriers issue alongside the main application, focused on the controls most relevant to ransomware loss: MFA coverage across email, remote access, and privileged accounts; backup immutability and restore testing; EDR deployment; and remote access exposure. Its answers carry the same weight as the main application's. The requirements guide covers these controls in detail.

Read-only scan

A read-only scan collects configuration state from an environment using credentials that grant read access only, so the scan can verify control state without the ability to change anything. Insurance Posture's scanner reads the real control state inside Microsoft 365, Entra ID, and Azure this way: it sees what an external scan cannot, and it makes no changes to the environment. Access model details: security.

Renewal readiness

Renewal readiness is the percentage of a carrier's renewal application an organization can answer with evidence collected from its live environment at the time of renewal. It is the practical, dated expression of insurance posture: not whether controls existed once, but how much of this year's application is provable today. A 90-day pre-renewal plan is laid out in the renewal readiness checklist.

Representation

A representation is a statement of fact made on an insurance application that the carrier relies on when deciding whether to offer coverage and on what terms. Answers on a cyber insurance questionnaire are representations. The legal effect of an inaccurate representation depends on its materiality, the policy wording, and applicable state law.

Rescission

Rescission is an insurer remedy that treats a policy as void from inception, typically sought on the ground that a material misstatement appeared on the application. Carriers have pursued rescission or denial over application answers in cyber disputes, as in Columbia Casualty v. Cottage Health (2015) and Travelers v. International Control Services (2022). Whether rescission succeeds depends on materiality and state law.

Retention (self-insured retention)

A retention, or self-insured retention, is the amount of a covered loss the insured bears before the insurer's payment obligation begins, functioning similarly to a deductible. In cyber underwriting, retention levels are among the terms carriers adjust based on the risk presented, so the same organization can see different retentions quoted depending on the control state its application evidences.

S

Security posture

Security posture is the state of an organization's security controls measured against a security framework such as CIS or NIST. Insurance posture measures the same environment against what a carrier asks on its application, where each answer is a representation the carrier relies on. An organization can hold a strong security posture and a weak insurance posture if it cannot prove the specific controls carriers underwrite.

Sublimit

A sublimit is a lower limit within a policy's overall limit that applies to a specific coverage, such as ransomware payments, social engineering losses, or dependent business interruption. A policy with a high headline limit can still cap a specific loss type at a fraction of that amount. Sublimits are among the terms carriers set based on the risk the application presents.

Measure the terms, not just define them

Connect a read-only account and see your own insurance posture: which application answers your live Microsoft 365, Entra ID, and Azure environment backs with evidence, and which have drifted.

Assess your posture