Cyber Insurance Readiness
A Gadriel-authored readiness checklist aligned with common cyber-insurance underwriter questionnaires. It is not a standard, not an audit, and not a guarantee — it is a structured way to show underwriters the technical hygiene of the codebase.
Related: Compliance overview · CMMC Level 1.
At a glance
| Property | Value |
|---|---|
| Slug | cyber-insurance-readiness |
| Aliases | cyber-insurance, insurance |
| Controls | 12 |
| Manual-only | 10 |
| Machine-assessable | 2 |
| Direct mapping key | (none — structural gap) |
Disclaimer. Cyber Insurance Readiness does not guarantee insurability, approval, premium, coverage, or claim payment. It surfaces technical evidence that commonly appears on underwriter questionnaires — nothing more.
Generating the report
bashgadriel code report --compliance cyber-insurance-readiness
Outputs: .security/compliance/cyber-insurance-readiness.{md,typ,pdf}.
What Gadriel evaluates
Only two controls are predicated (dependency hygiene / SBOM and secrets management). The remaining ten (MFA enforcement, EDR presence, offsite backups, incident-response tabletop cadence, employee training, network segmentation, etc.) are organizational and render as NOT ASSESSABLE with reviewer prompts.
Use the workbook as a pre-fill for underwriter questionnaires.
