The insurance-informed model

Our Approach: The Insurance-Informed Model

Most cyber security advice is written by people who have never seen a claim.

That is the difference this page is about. Fourarmed came out of Castlemead, an insurance broker, and the two businesses still work alongside each other. We assess and improve security, while Castlemead arranges cover that reflects the improved position. Between us you can get your risk understood, reduced, evidenced and then insured, without acting as the translator between two industries that use different words for the same thing.

You are under no obligation to use both, and plenty of clients have brokers they are happy with. However, the model shapes the advice even when only one half of it is in play.

What the Insurance Background Changes

Three practical consequences

We know which controls hold

Underwriters see the aftermath of a great many incidents. They know which measures were present but useless, which ones made the difference, and which claims fell apart because the business could not prove what it had said. This provides a different evidence base from a certification standard, and it produces a different set of priorities.

We quantify impact

Every audit includes a business interruption assessment, because an underwriter prices your downtime whether or not you have calculated it. A board asked to approve spending on backups will act on a number of days and a cost per day in a way it will not act on "high risk".

We recommend what gets implemented

Insurance-shaped advice is practical, risk-rated and cost-conscious by nature, because an insurer cares about outcomes and not about completeness.

The Four Pillars

Each stage produces the input for the next
  1. Audit

    Establish where you stand across systems, controls, software and people, with a fixed price agreed upon before we start and a report written for two audiences. See cyber security audit.

  2. Accredit

    Turn the findings into a recognised standard, principally Cyber Essentials and Cyber Essentials Plus, so your customers and your insurer have something concrete to work with.

  3. Monitor

    Keep the picture current between assessments, with continuous monitoring, vulnerability scanning and scheduled testing, and produce the evidence trail that renewal and client questionnaires depend on.

  4. Develop

    Bring your staff up to a level where they catch what the technology missed, and measure whether it worked. See cyber security training.

Most clients enter at stage one and work through the stages at their own pace. Some arrive at stage two with a tender deadline, and we work backwards from there.

Supply Chain Expertise

A lot of our clients inherit their requirements

If you supply the MOD, or a prime such as BAE, Leonardo or Rolls-Royce, cyber obligations cascade down to Tier 2 and Tier 3 suppliers and arrive as a condition of trading. Castlemead's ADS Group membership means we understand how those requirements move down a chain, what a prime is actually asking for, and how to satisfy it without over-engineering the answer.

The same pattern is now showing up outside defence. Only 15% of UK businesses review the cyber risk of their immediate suppliers, rising to 48% of large ones, so if you sell upmarket you are increasingly the supplier being reviewed.

How We Work

Three principles, in case they help you decide
  • We would rather tell you that you need less. If a conversation ends with us recommending three free changes and no engagement, that is a good outcome. It happens fairly often, and those businesses tend to come back when they need something bigger.
  • We do not sell products. We are not resellers and we take no commission on tooling, so when we recommend a control it is because we think you need it. Where a product is the right answer, we will say what to look for and leave the buying to you.
  • We write for a named reader. Every report is aimed at a specific person who needs to do something with it, which changes what goes in and what gets left out.

Where This Leads

The practical test of the model

The practical test of the model is what happens at renewal, when a client sends a security questionnaire, or on the worst day. Our work is designed to leave you holding evidence at that point.

There is more on what underwriters look for in our guide to cyber insurance requirements, and more on the two businesses in about Fourarmed.

Free initial conversation

Sent here before a first meeting?

This page carries the positioning in full so the service pages do not have to. If it sounds like a fit, the next step is a free initial conversation about your business, your systems and what has brought you to this point.