Cyber insurance readiness
Be ready before the renewal form arrives.
A cyber proposal form asks about MFA, backups, privileged access, EDR and incident response — and wants a date and a document against each answer. Sentinel holds the controls underwriters ask about, the evidence behind each one, and the gaps you still have to close. Months before the renewal, not the week the form is due.
Self-service signup opens shortly — we will set you up in the meantime
- Controls
- 22
- Underwriter controls, itemised
- Trial
- 14 days
- No card required
- From
- $99/mo
- Published price

Screens captured from a Sentinel workspace on 10 September 2026. Northstar Manufacturing Ltd. is a fictional example — a 180-person manufacturer in Ontario, Canada — not a customer, and its scores are computed by the product from its records rather than typed in for the picture.
Read this before anything else on the page
CyberWave helps you prepare for underwriting and security questions, organise evidence, identify possible gaps and plan remediation. CyberWave is not an insurer or an insurance broker, does not bind coverage, does not interpret policy coverage as legal advice, and does not guarantee coverage, premium reduction, claim payment or insurer acceptance. You remain responsible for complete and truthful representations to your insurer or broker.
We prepare evidence. Your insurer prices risk. Your broker places cover.
How it starts
A renewal does not arrive as a project. It arrives as a form with a date on it.
By the time the proposal form is in your inbox, the deadline belongs to somebody else. What is left is the part nobody schedules: finding out what you can actually show.
- Your broker
“Complete the proposal form and send it back with your supporting evidence.”
Ninety-odd questions about controls you mostly have, and a covering note asking for the documents behind them.
Deadline: the submission date
- The underwriter
“When did you last restore from a backup?”
Not the schedule, not the retention policy. The date — and something that shows it happened.
Deadline: before they will quote
- Your IT lead
“MFA is on everywhere, except a few service accounts.”
Which is the accurate answer, and the one the form has no box for.
Deadline: already on your desk
- Your finance director
“What happens if we answer no to that one?”
A question nobody in the building can answer, asked three days before the form goes back.
Deadline: the renewal date
The questions
The underwriter’s questions, answered from the record.
The subject matter barely moves between insurers: MFA, EDR, backups and restore testing, email security, patching, incident response, training, vendors, encryption. Each answer in the example workspace is drafted from the control and its evidence, and carries a status — Approved, Draft, or Missing evidence — so the answers you cannot yet support are visible to you first.

Scoping answers
Yes · Partial · No- YesMulti-factor authentication (email, remote/VPN, admin)
- YesEDR / next-gen AV deployed & monitored
- PartialBackups immutable/offline AND restore-testedBackups are immutable and off-site. The Q3 restore test has not been run yet; the Q2 report is the last dated proof.
- YesEmail filtering / advanced threat protection
- PartialPatch cadence with critical-vuln SLACorporate assets meet a 14-day critical SLA. The OT line-controller gateway is vendor-managed and currently excluded.
- YesDocumented & tested incident response plan
- YesSecurity awareness training + phishing sims
- PartialCritical vendor / third-party risk reviewsEight of ten suppliers assessed and approved. Two high-criticality suppliers have not provided assurance reports.
- YesEncryption at rest & in transit
Underwriters do not price yes and no. They price partial.
Yes is easy and no is survivable. Partial is the answer that comes back with follow-up questions, and it is the one you are most likely to discover in the week the form is due.
Gap discovery
The concerns an underwriter reads first, and the evidence that would close them.
The readiness engine reports 5 underwriter concerns and 4 missing critical evidence items for the example workspace, 96 days before its renewal. Found in September, each one is a task with an owner. Found in the week the form is due, each one is a disclosure.


- CriticalPrivileged access managementCI-IAM-02 · Not started · evidence required: Privileged access review record
- CriticalBackup restoration testingCI-BACKUP-02 · Not started · evidence required: Backup restore test report
- CriticalSecurity patch managementCI-VUL-02 · In progress · evidence required: Patch / vulnerability management policy
- HighThird-party cybersecurity due diligenceCI-TPR-01 · In progress · evidence required: Vendor risk review record
- HighSecure remote access and network segmentationCI-SEC-03 · Needs customer input · evidence required: External exposure scan (RDP)
Four of the five concerns are the same four missing files: privileged access review record, backup restore test report, patch / vulnerability management policy, vendor risk review record. Three of those controls are true in practice and short of proof; one is genuinely not in place yet. That distinction is invisible on a proposal form and it is the whole difference between a fortnight of work and a conversation with your broker about a control you do not have.
Whether any of this affects your premium is your insurer’s decision. We make no prediction about it. What changes is that you find out in September, when you can still do something, rather than in December.
The renewal
The broker package, tracked like the work it is.
Carrier, broker, policy number and renewal date on one record; every broker request and underwriter question logged with an owner and a due date; the package marked In Progress until the concerns are closed and readiness and evidence both reach 80% — at which point the product calls it broker-ready, not before.
Remediation lands in the product’s own horizons — Critical Now, Next 30 Days, Next Quarter — 2 critical now, 3 inside thirty days. With 96 days to go, that is a schedule. Five weeks out it is a triage exercise.

Ninety days
What ninety days out actually looks like.
Fewer than ninety days? Start at step one anyway and compress the middle. None of this needs a consultant on site. It needs somebody to own the list, and one place where the answers and their evidence sit together.
- 01
Ninety days out — find the questions you cannot answer
Load last year’s questionnaire, or the one your broker has already sent. Mark every question you cannot answer with a document and a date. That short list, not the whole form, is the project.
- 02
Sixty days out — attach what already exists
Policies, tenant settings, MFA and EDR exports, training records and the last restore test usually exist somewhere. Attach each one to the control it proves, with an expiry date on it.
- 03
Forty-five days out — decide what you will fix
Split what is left into what can be true before submission and what cannot. Close the first group. Give the second an owner, a target date and a written reason.
- 04
Thirty days out — answer from the record
Write each answer from the control and its evidence rather than from memory. Where the accurate answer is “not yet”, say that and attach the plan.
- 05
Two weeks out — assemble the submission
One package: the completed questionnaire, the evidence it refers to, and a short summary of the remediation in flight. Your broker receives one version instead of eleven attachments.
- 06
After the renewal — keep it warm
Stale evidence is flagged from its date, not from memory. Next year the questions are already mapped and the evidence is already dated, so the exercise is a review rather than a rebuild.
Two ways to do this
Run it yourself, or have the package assembled with you.
Both routes end in the same place: a questionnaire answered from evidence, with the gaps named and dated. The difference is who does the assembling.
In the product
Essentials
The entry plan, so the insurance readiness workspace is in every plan above it too. One framework in scope, the control register, the evidence library with status and expiry, and the 22 underwriter controls — enough to carry a renewal on your own.
$99 /month USD
or $1,069.20/year · 2 included users · broker and underwriter packages on Full Platform at $249/month
14-day free trial. No credit card required. No automatic charge.
Done with you
Cyber Insurance Submission Pack
A reviewed, broker-ready evidence and questionnaire package assembled from your workspace.
$499 one-time USD
- Your questionnaire reviewed against the evidence in your workspace
- Answers the evidence does not yet support flagged back to you, in writing
- The package assembled in one set for your broker, with a record of what was sent
- You review and sign off every answer before it leaves your workspace
A service, not a checkout. Professional Services terms.
Plainly
What preparation changes, and what it cannot.
- It does not set your premium, bind or interpret cover, or guarantee that any insurer accepts a submission.
- It does not make an inaccurate answer accurate. Where a control is not in place, the honest answer is no, with the plan attached.
- It is not a security operations service: no SOC, no managed detection and response, no penetration testing, no dark-web monitoring.
Questions
Questions worth asking before a renewal.
Answered the way we would answer them on a call rather than the way a brochure would.
Can CyberWave reduce our premium?
Is this the same as answering the whole ninety-question form?
The renewal is in five weeks and the form is already in my inbox. Is it too late to bother?
Do you fill in the questionnaire for us?
Which plan covers insurance readiness?
Don’t wait for the next questionnaire to discover the gaps.
Bring the renewal that is already booked. Mark the questions you cannot answer with a document and a date, and work outwards from that list.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required
