What stage is your organization?
WORKSHOPPING
Do I need
Cyber Insurance?
Should I self-insure?
APPLYING
Cyber Insurance is becoming increasingly difficult to decipher. What measures can I take to boost my security posture in the eyes of the Insurer?
POLICY HOLDER
How do I avoid losing my policy?

Do you need Cyber Insurance but the process and cost seem daunting?
How do you determine if you are insurable?
Nth Generation helps organizations achieve superior policies by leveraging the same framework and tools the insurance underwriters are utilizing.
Results are based on well-established best-practice frameworks providing validation of the scores.
Concerned about your security posture as you sort out what's best for your organization?
Nth can empower you to shore up the primary security controls necessary to mitigate ransomware and security incidents.
Do you have Cyber Insurance and are experiencing a significant increase in fees?
Are you aware that experts predict a 15 to 50% increase in cyber insurance premiums in 2022? Source
We can help you make sense of it all.
Is your organization truly prepared to shoulder the exorbitant cost of recovery, including revenue loss, liability claims, legal fees, public relations triaging, and/or other related expenses due to a breach or cybersecurity incident?
Is cyber insurance appropriate for your organization?

The Struggle is Real
-
Cybersecurity insurance is a necessity for most organizations.
-
Increasing demand and threats of attacks have made insurance companies much more hesitant to offer claims.
-
Being denied cyber insurance from several carriers is now more common with the current climate of cyber risks.
-
Insurance carriers are scrutinizing applications and writing in exclusion clauses to attempt to mitigate their financial risk.
Nth Generation is here to help o o o

Cyber Insurance Readiness Assessment (CIRA)
1
BASIC
CIRA Basic assesses your organization by utilizing a wide variety of external sources of information.
Using open-source intelligence (OSINT), Nth Generation scours through the information that both hackers and insurance carriers utilize, such as: Google, social media, forums, leaked data dumps, VirusTotal, Censys, Cymon, Shodan and others.
Your Organization only needs to provide a domain name.
2
ADVANCED
CIRA BASIC +
By including the External Penetration Test, validation can be made as to potential vulnerabilities, patch requirements, or other remediation steps that should occur before soliciting insurance coverage.
The inclusion of the CIS Controls Gap Assessment provides a top-down best-practice based view of the organization that aligns with a widely adopted Cybersecurity framework.
Your total time investment is minimized to: a) Providing a domain name; b) Having a team session(s) lasting approximately 2-4 hours, and c) Providing in-scope information for the External
Penetration Test.
3
COMPLETE
CIRA BASIC + ADVANCED +
More and more insurance agencies understand that organizations may have a strong external posture but may have substantial security weaknesses inside of the perimeter boundaries.
By assessing the internal security posture organizations gain a holistic view of the overall information security vulnerabilities and posture of the entity.
Your total time investment remains relatively low: the requirements for the Advanced CIRA + providing in-scope internal network details.
4
PREMIUM
CIRA BASIC + ADVANCED + COMPLETE +
-
Ransomware Readiness Assessment SM (RRASM)
This CIRA tier also includes:
A holistic view of your organization’s information security posture, susceptibility, resilience and auditability should a ransomware incident occur.
Providing everything that “CIRA COMPLETE” offers in conjunction with our Ransomware Readiness Assessment SM (RRA SM), organizations can validate the quality of the implementation of the security technologies or countermeasures they’ve invested in and highlight areas which may need to be improved upon to reduce the risks associated with a ransomware incident.
Your time investment consists of the CIRA COMPLETE requirements + approximately 8-12 hours to conduct the RRASM assessment.
Approximately another 8-12 hours are needed by a subset of the team to conduct the RRA assessment. In-scope internal and external network details will also need to be provided.



