Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. The NIS2 directive formalized in European law, at its article 21, ten categories of mandatory measures for essential and important entities. What does that change about the status of insufficient cyber hygiene?
It is no longer only an aggravating factor at underwriting, it becomes a sanctionable regulatory breach
Cyber hygiene is the non-negotiable base: updates, multi-factor authentication on sensitive access, managed and tested backups, network segmentation, phishing awareness, identity and privileged access management. For the insurer it is the first filter, the level below which a risk becomes unwritable or is written on very restrictive terms: a submission with no multi-factor authentication on remote access and no backup tested in eighteen months is typically offered a doubled deductible and a sub-limit, with a return to normal terms conditioned on remediation. NIS2 adds a second consequence, independent of the contract. And the base moves with the threat: continuous behavioral monitoring and least privilege were not part of it in 2020, they are today.
Glossary entry · hygiene-cyber2. A cyber questionnaire has always asked whether the company has a patching policy. Why does the software bill of materials change the nature of that question?
Because it replaces a declaration whose answer is always yes with an inventory verifiable against documents
A question whose answer is always yes has zero discriminating value: two companies producing identical answers to the same questionnaire can carry security debts of entirely different orders. The bill of materials makes it possible to ask what the estate actually contains, component by component, version by version, and that answer can be verified. But its reach goes beyond individual selection, and this is the point that matters most to an insurer: generalized, it makes accumulation measurable. It becomes possible to establish how many insureds depend on the same library and to estimate the cost of a critical vulnerability before it happens, whereas during the great widely-distributed vulnerability episodes the market discovered its exposure after the fact.
Glossary entry · nomenclature-logicielle3. A company tests its patches for six weeks before deploying them, so as not to cause an outage. What does that choice buy, and what does it cost?
It buys stability, at the price of an extended exposure window on a flaw already known and already being exploited
Patch management aims to reduce the exposure window, the span during which a known flaw stays exploitable for want of being fixed, and attackers rush into it as soon as the vulnerability is published. But the tension is real and has no clean solution: deploying without enough testing can introduce a malfunction, even an outage, and that outage has systemic reach when the defective patch propagates across an entire estate. Testing too long extends exposure on a flaw whose existence is public. Six weeks is a trade-off, not negligence, and it is the trade-off itself that underwriting must assess rather than the existence of a policy.
Glossary entry · gestion-correctifs4. In 2023, the MOVEit vulnerability was exploited at scale by the Clop group before a patch was widely deployed, affecting hundreds of organizations. Why do underwriters care as much about detection speed as about patching cadence?
Because an unknown flaw escapes patch management by construction, and a widespread flaw hits several insureds at once
A zero-day flaw is unknown to the vendor, hence unpatched: the victim has zero days to prepare, and the hygiene measure that forms the pillar of underwriting requirements, patch management, can do nothing about it. What remains is the second line: the ability to detect and contain an unknown exploitation, which is a control of a different nature. And a zero-day in a very widespread product does not merely defeat individual defenses, it turns a technical defect into an accumulation event, every insured using the product being hit inside the same window. This is why such flaws trade at high prices on a market where researchers, states and malicious actors meet.
Glossary entry · faille-zero-day5. An insurer observes that the loss ratio of its insureds running an endpoint detection and response agent is markedly lower, and makes it an underwriting criterion. What does the July 2024 CrowdStrike incident add to that reading?
That the control which reduces the individual loss can itself become a shared dependency across the portfolio
An endpoint detection and response agent continuously collects system events, analyzes behavior in real time, can isolate or remediate automatically, and leaves detailed telemetry valuable for investigation. Its deployment correlates with shorter detection and containment times, which is why some insurers contractually require it to write high limits, or grant a premium reduction for it. But July 2024 showed the other face: a single agent deployed on millions of machines becomes a systemic risk vector. The control that improves each risk taken alone installs, at portfolio scale, exactly the shared dependency accumulation analysis exists to uncover. Both readings are true at once, and they do not cancel out.
Glossary entry · edr-xdr6. A submission declares a zero trust architecture. What does it actually reduce, and what does the declaration alone fail to establish?
It reduces the extent of a loss by limiting lateral movement, but its implementation is progressive and the declaration does not say how far it goes
The model breaks with the castle-and-moat approach, which protected a perimeter and trusted by default whatever was inside. With the perimeter dissolved by the cloud, remote work and the proliferation of devices, every access request is authenticated, authorized and assessed on identity, device state and context, regardless of position in the network. The aim is to limit lateral movement: an attacker who compromises a workstation cannot roam freely toward sensitive resources. It is therefore a severity control rather than a frequency one, and a strong maturity signal. But microsegmentation and least privilege roll out in stages, over years: zero trust describes a trajectory rather than a state reached at once, and a declaration with no measure of progress says very little.
Glossary entry · architecture-zero-confiance7. Why can the presence of a threat hunting capability, internal or contracted, justify a lower deductible?
Because it reduces attacker dwell time, which is the main variable of a claim's severity
Threat hunting starts from an uncomfortable premise: an attacker may already be present without having triggered any automated alert, particularly if living off the land by using only legitimate system tools. The hunter frames hypotheses about an adversary's likely tactics and procedures, then tests them against logs, endpoint telemetry and network data, using frameworks such as MITRE ATT&CK. The approach is human and iterative, complementing tools rather than replacing them. It guarantees nothing, and that is precisely why it is worth something: what it reduces is dwell time, the period during which a present attacker deepens the loss, and that period is the variable that decides severity once the intrusion has happened.
Glossary entry · threat-hunting8. A broker submits two documents: a penetration test report listing forty vulnerabilities, and a red team report. What does the second provide that the first does not?
A demonstration of a compromise's real impact on the organization's mission, rather than an enumeration
A red team is mandated to attack a system under rules of engagement set in the contract, combining technical intrusion, social engineering and sometimes physical access. It differs from a penetration test in its strategic dimension: the object is not to list vulnerabilities but to show what a compromise does to the mission. The blue team tries to detect and contain, and an exercise combining both is called a purple team. Forty listed vulnerabilities do not say which of them chain together to reach a critical asset, and it is that chain underwriting wants to see. A documented exercise therefore counts as evidence of diligence and can weigh on pricing, including at a renewal where the insurer raises the deductible against a contractually agreed remediation plan.
Glossary entry · red-teaming9. The European Cyber Resilience Act gave technical security debt a due date, a creditor, a unit of measure and a penalty scale. What does that change, and what does it not change?
It changes its status, making it measurable and due, while changing nothing about the nature of the danger it represents
The term is not a metaphor. Like a financial debt, security debt results from a trade-off between present and future, it bears interest since the cost of remediation grows with the component's age and the number of systems depending on it, and it falls due on a date the debtor does not choose. Its peculiarity lay in its accounting invisibility: no balance sheet, no shared unit, no maturity, and omitting it was no irregularity at all. A company could therefore present perfectly faithful accounts while carrying a liability whose size nobody, itself included, knew. The regulation supplies the four missing attributes, among them the unit of measure that is the software bill of materials. An obsolete library left unmigrated because migrating would cost three months stays exactly as dangerous: it has merely become visible and dated.
Glossary entry · dette-securite-technique