Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. How are the three measures that dominate intrusion statistics recognized, and why is that test better than a framework score?
They CLOSE a path instead of watching it: authentication on all remote access, offline backup, network segmentation. A framework measures conformity to practices, one underwrites resistance to an attack
Closing or watching is the test that sorts, and it explains why two submissions with the same score carry incomparable risks. The answer tying them to frameworks reverses the reasoning: it is because they work that they appear everywhere, and their presence in a framework proves nothing about implementation. The one invoking cost against premium describes a commercial argument, sometimes true, foreign to the ranking. The one on verifiability without system access is factually wrong, and it is interesting because it describes what one would wish: the module says precisely that an audit does not test the real restoration of a backup.
Glossary entry · tarification-exposition2. Which measure does nothing to the probability of entry and yet decides the difference between three days and six weeks of interruption?
Offline backup, disconnected or immutable: it closes the path by which an attacker destroys the ability to rebuild, and it is a SEVERITY measure and not a frequency one
Separating what reduces frequency from what reduces severity decides where a budget goes, and in cyber, where frequency is hard to estimate and severity observable, severity measures are often the better use. Patching and authentication are frequency measures, and the two answers naming them attribute to them an effect on duration they do not have once the attacker is in. Detection is the very example of WATCHING a path without closing it: it shortens the reaction, it does not restore the ability to rebuild. None of these three is useless, and none decides the gap between three days and six weeks.
Glossary entry · sinistralite-attritionnelle3. The module keeps one indicator that says something about the organization and not just its tooling. Which, and why is it hard to overstate?
The time to apply a critical patch, asked for as a FIGURE over the last twelve months: a company patching within seventy-two hours has a current inventory, a working decision chain, and teams allowed to stop production
A delay is a dated, checkable fact, while a policy is an intention. That is what makes it hard to overstate: it presupposes evidence the company either has or does not. Budget as a share of revenue measures spending and not results, and two companies at the same ratio may have bought very different things. The number of incidents detected is ambiguous in both directions, since a high figure can signal good detection or poor protection. The reporting line describes a favorable condition, often cited and never measurable, whereas the delay is precisely its observable effect.
Glossary entry · declaration-de-risque4. A company has outsourced its production to a host and its administrative access to a managed service provider. What does the underwriter learn by noting it, beyond this submission?
Something about its PORTFOLIO: the same provider sits behind dozens of insureds, and that dependency is not reduced by the company's own measures
Dependency is read twice, once for the insured and once for the portfolio, and it is the second reading that questionnaires never perform. The answer on recovery against the provider describes a real and usually disappointing prospect, outsourcing contracts being capped, and above all one foreign to the question. The one setting aside the declared measures goes too far: a company keeps its own workstations, accounts and backups, and its measures count. The one concluding better control states a defensible opinion about some providers and misses the point: the subject is not the third party's quality, it is that the insured delegated part of its attack surface to someone whose practices and updates it does not control.
Glossary entry · spof-accumulation-cyber5. The module offers three questions that usefully replace an audit report. What do they have in common?
Each bears on a verifiable, dated fact rather than a declared state: when did you last truly restore, how many accounts escape the second factor, who can stop production without asking permission
An audit report describes a state on a date, over a declared scope, from interviews and samples; these three questions ask for an event that happened or did not. The answer on uncovered domains is factually wrong, frameworks all addressing backup and access: what they do not do is verify. The one insisting on numerical form keeps a trait of two questions out of three and gives them a contractual weight they do not have, since they serve to underwrite and not to be held against anyone. The one placing them on the frequency side is half wrong, restoration being the archetype of a severity measure.
Glossary entry · bonne-foi