This is the report exactly as the tool produces it, on a firm that does not exist, whose answers were written to look like an ordinary file: a few solid points, a few clear blind spots. You see its full shape, every section, the score and its method, the outline of the remediation plan. Twenty blocks carry their complete text here; the rest are listed by count, section by section, in the table at the foot of the page.
The firm, its answers, its scores and its exposure ranges are invented. They exist to show the shape and depth of the document, not to describe a real company or to provide an analysis that could be used as it stands. This page publishes only part of the report's blocks. No insurer is named and no cover is advised.
Identifier CRA-SPECIMEN · issued 15/06/2026 · Cabinet Vallonet & Associes
Analysis support document for insurance professionals.
Constitutes neither insurance advice, nor an audit, nor a guarantee of placement. Public AlgoPolis CRA v1.0 methodology. French version prevails.
Verdict established by the methodology, on the basis of the score, the blocking points and the reliability of the answers.
Main strengths. Data processed and compliance (60/100) ; People and training (59/100) ; Technical security (58/100)
Critical weaknesses. Incident history and existing coverage (36/100) ; Third-party dependencies and supply chain (39/100) ; Cyber governance and organization (41/100)
| Line of business | Legal and accounting professions |
| Headcount | 50 to 249 |
| Annual revenue | €2M to €10M |
| Share of activity dependent on IT | Over 75% |
| US or UK exposure | No |
| Physical sites | 2 to 5 |
| Regular remote work | About half |
| Able to operate in degraded mode for more than 48 hours | No |
| Categories of personal data processed | Ordinary customer data, Employee data, Banking and payment data |
| Individuals covered by the data held | Fewer than 10,000 |
| Incidents declared over 36 months | Funds transfer fraud |
| Cyber policy already in place | No |
The dotted vertical line marks the 70-point threshold for the verdict “placeable on standard terms”. Bars legible in black and white.
A security policy exists but has not been updated recently. An old document rarely covers current practice, remote work, cloud tools or stronger authentication, and its staleness may be raised during review. Updating it before the submission goes out is a limited effort for a real gain in credibility.
Cyber does not reach executive management, not even once a year. The risk is therefore treated as a delegated technical matter, with no arbitration at the level where budgets and priorities are decided. Submissions with this characteristic prove statistically weaker on the technical sections, which underwriters know and check.
Multi-factor authentication is only partly deployed across the critical surfaces: email, remote access and administrator accounts. Partial deployment leaves attack paths that go around the protection, and underwriters treat it as an absence with mitigating circumstances rather than as a control in place. Extending it everywhere, a matter of a few days' work, is the single action with the best ratio of cost to effect on insurance terms.
The backups in place have not been through a real restore test in the past twelve months. A backup that has never been restored remains a promise whose value is discovered only in the middle of a crisis, the moment when partial restore failures are a constant feature of severe losses. A documented full test turns this declared point into a verifiable one and improves the negotiating position on both the deductible and the data restoration sub-limit.
No dual approval procedure governs changes of bank details or unusual payments. This is the textbook scenario for funds transfer fraud by impersonating a supplier or a company officer, whose frequency and cost per event make it one of the leading sources of loss for companies of this size. Since the corresponding coverage frequently carries low sub-limits, putting in place a systematic callback to the known number is at once the most effective protection and a direct argument for negotiating that sub-limit.
Cybersecurity awareness training reached only some employees. Attackers do not choose their targets among the people who were trained, and one click is enough to open the intrusion; the value of partial training is therefore well below its apparent coverage. Extending it to the whole workforce, including non-technical functions and company officers, completes the arrangement at low cost.
The managed services contract covers exit rights and security commitments only in part. The areas left uncovered, return of configurations, response times, incident notification, then rest on the vendor's goodwill, which becomes a problem in precisely the situations where those clauses matter. A contractual review at the next renewal, or an amendment, closes this exposure at limited cost.
Third parties hold permanent access to the information systems without their security having been assessed before contracting. Each of these accesses extends the attack surface into environments the company does not control, and many documented intrusions pass through the compromise of a legitimate supplier. Listing these accesses, limiting them to what is strictly necessary and protecting them with strong authentication are the first measures, ahead of formal assessment of new entrants.
The company processes banking or payment data. Such data has direct resale value for attackers, which raises the likelihood of being targeted, and its compromise triggers specific obligations toward issuers and payment schemes, whose contractual penalties come on top of the usual costs of a breach. Compliance with the requirements applicable to payment processing will be verified during review.
Sensitive data is processed without encryption at rest across the board. If a device were stolen or data exfiltrated, that data would be immediately usable, which maximizes both the cost of notifying and supporting the individuals concerned and the regulatory exposure. Encrypting databases and backups is among the measures with the best effect on the breach scenario, and can generally be switched on within the tools already in use.
The company was targeted by funds transfer fraud, successful or attempted, in the past three years. This history establishes that the company sits in the line of fire for this type of attack, generally because its payment processes or its public information allow it. The fraud sub-limit of the future policy, frequently low by default, must be negotiated in light of that precedent, and dual approval of payments becomes in this context a requirement rather than a recommendation.
A continuity plan exists but has not been tested recently. Plans that were never exercised almost always fail in part on the day, on details only the exercise reveals: out-of-date contact numbers, forgotten dependencies, underestimated timings. A half-day tabletop exercise is enough to turn the document into a verifiable capability and to make it an underwriting argument.
Indicative ranges established from public sources and conservative coefficients, combining sector, size, dependence on information systems and the answers in the file. They constitute neither a prediction nor a commitment. The coefficients are detailed in the methodological appendix of the PDF. Amounts are in euros.
Loss of profits estimated between €18,000 and €22,800 per day of downtime.
Based on the number of individuals concerned.
Wide range in the absence of systematic dual authorization.
Finding: multi-factor authentication is not in place across email, remote access and administrator accounts. Insurance implication: most underwriters treat this as a prerequisite whose absence degrades the terms or blocks placement altogether, compromised access being the leading intrusion vector observed. Recommended action: extend MFA across all three surfaces, a matter of a few days at low cost, favoring phishing-resistant methods for privileged accounts. Expected benefit in negotiation: the removal of the file's main blocking point, and a signal of responsiveness worth using from the first exchange.
Source: Coveware by Veeam, Quarterly Ransomware Reports, Q4 2024 to Q4 2025 (ransoms paid: medians $110,890 to $400,000, averages $377,000 to $1.13M depending on the quarter; payment rate 20 to 26%; compromised remote access, the leading vector)
Finding: no real restore has been tested in the past twelve months. Insurance implication: the ability to recover, which bounds the length of interruption and therefore business interruption, remains merely declared. Recommended action: carry out a full restore test of a critical server or volume, timed and documented. Expected benefit in negotiation: a dated test report is among the most convincing pieces a mid-market file can present, because it is rare and verifiable.
Source: Sophos, State of Ransomware, 2025 (average recovery cost excluding ransom $1.53M; 53% of organizations recovered in less than a week; median demand $1.32M)
The risk appears placeable with reservations: the fundamentals are partly in place but one or more of the market's usual prerequisites are missing. Addressing the priority actions identified in this report before presenting to an underwriter is recommended, or presenting them together with a firm timetable, failing which they will translate into loadings, higher deductibles or targeted exclusions.
Cyber application forms converge on a common core of questions. This section anticipates them: for each theme, the standard wording you will receive, the current state of your client's file, and what to prepare before the form arrives. The aim is twofold: never to discover a question in the meeting, and to avoid improvised answers that commit the disclosure of the risk.
The form's standard question. “Is multi-factor authentication deployed on email, remote access and privileged accounts? State any exceptions.” This question appears on virtually every form, often on the first page, sometimes as a contractual undertaking.
Status of the file. Partial, with the scope of exceptions to be specified (email “Yes, for everyone”; remote access “Partially”; administrator accounts “No”).
To prepare. Have the vendor draw up the exact list of covered scopes and of exceptions, with the reason for each. An approximate “yes” on this point is the leading ground for contesting coverage after a loss.
The plan ranks actions by time horizon rather than by technical domain. The costs are indicative orders of magnitude for a company of the size concerned, to be quoted precisely by the vendor; they are prudent in the sense the methodology gives that word. The impact column separates what unblocks placement from what improves the terms: the thirty-day actions clear the blocking points, the ninety-day actions consolidate the file, and the hundred and eighty-day actions prepare a better renewal.
Horizon. 30 days
Action. Switch on multi-factor authentication for email, remote access and administrator accounts, handling the exceptions one by one.
Indicative cost. Generally under EUR 2,000 excluding licenses already held; often included in the office suites already in place.
Impact on insurability. Unblocks placement: an almost universal prerequisite whose absence leads to a decline or to degraded terms. Once done and evidenced, it removes the file's main black mark.
Statut et lecture. This section places the file against what can be observed of market expectations: the requirements that recur across insurer application forms, and the points of attention documented by industry publications, national cybersecurity agencies, risk management associations and international broker reports. It is qualitative and sourced; it makes no claim to a statistical ranking, which no public data would honestly support. It closes with the placeability verdict carried over from the executive summary.
Only terms actually used in this report appear below.
Multi-factor authentication (MFA). Confirming a sign-in with a second element on top of the password, a code or an app on a phone, a physical key. It neutralizes most account takeovers based on a stolen password.
Remote desktop (RDP). A function allowing one computer to be operated from another. Exposed directly to the internet, it is the intrusion route most commonly exploited by ransomware.
VPN. An encrypted tunnel giving access to the company network from outside. It reduces the exposure of internal services, provided it is itself protected by multi-factor authentication and kept up to date.
Ransomware. Malicious software that encrypts an organization's data and systems, accompanied by a ransom demand, often doubled with data theft and a threat to publish.
Phishing. A fraudulent message imitating a legitimate sender in order to obtain a click, a password or a payment. The leading initial vector of incidents.
EDR. Current-generation protection for workstations and servers, detecting attack behavior and not only known viruses, generally monitored by analysts.
Security monitoring (SOC). Continuous watch over security logs and alerts, in-house or outsourced, making it possible to detect an intrusion in progress and respond.
Logging. Centralized recording of system events. A precondition for detection and for reconstructing the facts after an incident.
Restore test. An actual restore of a server or volume from the backups, timed and documented, which turns backup from a promise into a demonstrated capability.
End-of-life system. A system no longer receiving patches from its publisher, accumulating vulnerabilities that stay open for good; tolerated by underwriters only where isolated and documented.
Penetration test. A simulated attack carried out by an outside firm to identify exploitable vulnerabilities. Its value at underwriting depends on the remediation plan that follows it.
Funds transfer fraud. Diversion of a payment by impersonating a supplier or a company officer, typically through a false change of bank details. It is neutralized by a systematic callback to the number already on file.
Business continuity plan. A document organizing how activity continues or restarts after a major loss, order of priority, fallback resources, responsibilities. Its value depends on it being tested.
Incident response plan. A short document setting out the emergency contacts, the first steps and the order of notifications in the event of an attack, kept reachable outside the systems.
Degraded mode. The ability to carry on part of the activity without IT, through fallback procedures, often manual. It directly reduces business interruption.
Business interruption. Gross margin lost because activity stops or is reduced following a loss. The largest single item in the cost of a major cyber incident.
Indemnity period. The maximum period over which business interruption is indemnified. It must cover actual recovery, often more than one hundred days for a major loss.
Coverage limit. The maximum amount payable under the policy, across all heads of loss unless stated otherwise.
Sub-limit. A specific ceiling, below the limit, applying to a given coverage: fraud, data restoration and contingent business interruption in particular.
Deductible. The share of a loss borne by the insured, expressed as an amount (monetary deductible) or as a duration of outage (time deductible) for business interruption.
Contingent business interruption. Coverage responding to a stoppage caused by a third party's failure, an IT vendor, a cloud host, a software publisher. Often excluded by default or restricted to named suppliers.
Exclusion. A clause removing certain losses from the coverage. Exclusions aimed at state attacks and at unpatched vulnerabilities call for particular attention.
Underwriter. The insurer's professional who assesses the risk, decides whether to accept it and sets its terms.
Proposer. The company seeking the coverage, and whose declarations form the basis of the contract.
DPO. Data protection officer, responsible for GDPR compliance, whose appointment is mandatory for certain activities.
Record of processing activities. A GDPR document listing an organization's processing of personal data, the first document the supervisory authority requests after a breach.
Data breach. A compromise of the confidentiality, integrity or availability of personal data, subject to notification to the supervisory authority within 72 hours under the GDPR where it presents a risk.
Encryption at rest. Encryption of stored data, making stolen data unusable without the key.
IDD. The European Insurance Distribution Directive, governing in particular the distributor's duty to advise its client.
The AlgoPolis CRA (Cyber Risk Assessment) methodology structures the declarative analysis of a company's cyber risk for insurance professionals. It is public, versioned and dated: this version is v1.0. Every report generated states the version used, so that two reports carrying the same version and the same answers are strictly identical. The methodology is neither a standard, nor an audit framework, nor a certification scheme; it organizes declarations according to explicit and traceable rules.
The analysis rests exclusively on the answers given to the questionnaire by the broker or, in collection mode, by the client company itself. No technical verification is carried out. The accuracy of the answers is the responsibility of the party declaring them, as for any insurance application form. The report records where the answers came from, direct entry by the broker or collection from the client, with their date.
The questionnaire has 60 questions across 7 sections: client company profile (8 questions, context, not scored), cyber governance and organization (8), technical security (14), people and training (7), third-party dependencies and supply chain (8), data processed and compliance (8), incident history and existing coverage (7). Answer types are exclusively closed: single choices, scales, lists and multiple selections. Six questions are conditional. A “don't know” option is always offered and always carries a penalty in the scoring, the inability to answer being in itself a signal of maturity.
Every answer carries a score from 0 to 100 defined per option. Every question carries a within-section weighting from 1 to 3 according to how far it discriminates for underwriting. The section score is the weighted average of the questions answered and visible. The overall score weights the sections as follows: governance 15%, technical security 30%, people 15%, third-party dependencies 15%, data and compliance 10%, history and coverage 15%. The profile section is not scored: it sets the context, the rules and the financial exposure.
Fourteen combination rules detect configurations whose severity exceeds the sum of their parts, for instance remote access exposed without multi-factor authentication in the healthcare sector, or the joint absence of resilient backups and of a response plan. Each rule carries a published insurance rationale. Rules may apply a penalty to the overall score; the total of those penalties is capped at 10 points in order to avoid double counting with the base scoring, the most serious configurations being handled by red flags rather than by the score.
Certain configurations produce a blocking flag at the head of the executive summary: no backups at all, remote desktop access exposed without multi-factor authentication, end-of-life systems left unisolated on an unsegmented network, a recent significant incident with no corrective measures, the combination of unprotected remote access and the healthcare sector, and a rate of “don't know” answers above 40% across the technical sections. Each red flag comes with the three priority corrective actions to take before presenting the file to an underwriter.
The rate of “don't know” answers is measured across the technical security, people, and third-party dependency sections. Above 30%, a reliability caveat appears in the executive summary. Above 40%, a red flag is raised, the file is described as not presentable as it stands, and generation of the technical annex is blocked until the collection is completed.
The report is assembled by a deterministic rules engine from a library of blocks written in advance, each carrying an identifier, activation conditions, a level (information, point of concern, red flag) and, where applicable, its sources. Mutual exclusions prevent contradictory blocks from coexisting in the same report. A traceability mode makes it possible to display, for each block inserted, the rule and the answers that triggered it.
Exposure is expressed exclusively in ranges, never as a single point, across three scenarios: ransomware with business interruption, data breach, and funds transfer fraud. The coefficients combine sector, size, dependence on the information systems and the answers in the file. Each coefficient carries its source and its year, published in the report's appendix; where no public source offers the necessary granularity, the range is widened and explicitly described as a prudent estimate. No statistic is invented.
The report closes with one of three verdicts: placeable on standard terms, where the overall score reaches 70 with no red flag; difficult to place as it stands, as soon as at least one red flag is active; placeable with reservations in the remaining cases, together with the list of reservations. This verdict describes how presentable the file is against observable market expectations; the underwriting decision belongs exclusively to the underwriter.
The financial exposure sources are reviewed annually as new yearly editions are published, which increments the methodology version. Any change to the weightings, the rules or the thresholds also produces a new version. Earlier versions remain available, and every report remains interpretable against the version it states.
The analysis is declarative and instantaneous: it photographs answers at a given date, with no technical verification and no follow-up over time. The financial ranges combine sources of heterogeneous scope, global, US and French, and do not constitute a prediction. The methodology replaces neither a security audit, nor the insurer's own application form, nor the duty of the insurance distributor to advise its client.
This document is an analysis support tool intended for insurance professionals. It is generated deterministically under the public AlgoPolis CRA v1.0 methodology, from the declarations of the proposer or its broker alone, without technical verification. It constitutes neither insurance advice within the meaning of insurance distribution regulation, nor a personal recommendation addressed to an end insured, nor a security audit, nor a compliance assessment, nor any guarantee of placement or insurability. It replaces neither the insurer's own application form nor the broker's duty to advise its client. The scores, verdicts and flags express how presentable the file is against observable market expectations and do not bind AlgoPolis. The financial ranges are indicative estimates based on public sources cited in the appendix with their year; they constitute neither a prediction, nor an undertaking, nor a contractual basis. The underwriting decision and the setting of terms belong exclusively to the underwriter. The accuracy of the declarations is the responsibility of the party making them; any inaccurate declaration may affect the validity of coverage written on its basis. AlgoPolis cannot be held liable for decisions taken on the basis of this document. The French version of these terms prevails.
Data protection. The answers entered in the questionnaire are processed in your browser: they are neither stored, nor logged, nor passed to third parties by AlgoPolis, and no cookie is associated with your client's data. Saving and resuming are done solely through a file that you export and keep under your own responsibility. When a paid report is generated, the answers are transmitted in encrypted form to an assembly function that processes them in memory, without storage or logging, and retains only a cryptographic fingerprint associated with your file number, from which no data can be reconstructed. The end client's name and the firm's logo, where provided, are inserted locally into the document and take no part in any calculation. As a professional, you remain responsible for the processing of your client's data that you enter, export or transmit, and for the report generated. For any question: the contact stated in the legal notices on algopolis.eu.
Provenance of the answers. This report records, section by section, where the answers came from: collected from the client company through the collection form, or entered and where applicable amended by the brokerage, with their date. Any subsequent divergence between these answers and the declarations made to the insurer must be resolved by returning to the source before signature.
You have just read 20 blocks out of the 62 this report contains. The other 42 follow the same shape, in the same sections, and are not published on this page.
| Section | Published | In total |
|---|---|---|
| Cyber governance and organization | 2 | 3 |
| Technical security | 2 | 7 |
| Human factor and training | 2 | 2 |
| Third-party dependencies and supply chain | 2 | 4 |
| Data processed and compliance | 2 | 4 |
| Incident history and existing cover | 2 | 3 |
| Remediation before placement | 2 | 6 |
| Positioning of the file | 1 | 1 |
| Technical questions to prepare | 2 | 14 |
| Remediation plan at 30, 90 and 180 days | 2 | 9 |
| Position against market expectations | 1 | 9 |
The tool asks sixty closed questions, then assembles the report you have just read an extract of from your client's answers. The questionnaire takes about twenty minutes to complete, and the document comes out in full, in French or in English.
See the Pro area