Comprehensive Cybersecurity Audit Services for Insurance Compliance
Your cyber liability renewal landed with a questionnaire. MFA, EDR, immutable backups, written incident response plan. We work through the questions, show what is already in place, fix what is not, and hand your broker a clean answer.
Carriers are tightening every year.
Most BC and Alberta SMBs got renewal questionnaires in 2025 that were not there in 2022. Premiums double if you cannot show controls. Claims get denied if you stated something on the application that turns out to be untrue. Brokers want a partner they can call.
Premium goes up
Carriers are charging anywhere from 30 to 200 percent more on renewals when controls are weak. Fixing the gaps usually pays for itself inside the first year.
- RENEWAL
- PREMIUM
Coverage gets cut
Ransomware sublimits, social engineering sublimits, contingent business interruption limits. The cheap policy can have a $25k sublimit on the one thing you actually need.
- SUBLIMITS
Claims get denied
If the application says MFA is on everything and it is not, a claim can be denied for material misrepresentation. We document what is actually in place.
- MISREP
- EVIDENCE
What you get from the audit.
A structured audit that gives your broker the answers they need and gives you a clear picture of where you stand. Deliverables, evidence needs and review steps are agreed before work begins.
Completed questionnaire
We answer every question on your insurer's application, in their language, with evidence references. Broker-ready.
- CARRIER FORMAT
Gap report
Plain-English list of what is missing, what risk each gap creates, and what it costs to close. Sorted by carrier weight.
- PRIORITIZED
Remediation plan
Timeline, owner, and dollar cost for each fix. Some you can do in an hour, some take a quarter. We tell you which is which.
- BUDGETED
Evidence pack
Screenshots, policy excerpts, configuration exports. The artefacts your carrier or auditor will ask to see.
- AUDIT TRAIL
Broker letter
One-page summary your broker can attach to the submission. Saves them work, makes them look good to underwriting.
- BROKER READY
12-month watch plan
Quarterly check-ins so the controls do not drift. Renewal next year is a confirmation call, not a panic.
- ONGOING
From questionnaire to broker-ready answer.
Timing depends on scope, access, document availability, broker deadlines and review. We agree the work plan before starting, including the client time required.
Send us the questionnaire
Forward the carrier's application or renewal questionnaire. We sign an NDA on request.
Discovery call (60 min)
We walk through your environment together: identity, endpoints, email, backups, vendors, incident history.
Evidence collection
We pull configuration and policy artefacts from Microsoft 365, your endpoint agent, your firewall, and your backup tool. Read-only, no agents installed.
Gap report and fixes
Draft answers, gap list, remediation cost estimate. You review. We adjust.
Hand-off to broker
Final questionnaire, evidence pack, and a one-page broker letter. You submit the materials; the insurer and broker make the renewal decision.
The controls carriers ask about.
Carrier questionnaires overlap in some common areas, but requirements vary by insurer, policy, industry and renewal. We score the controls that are in scope as in place, partial, missing or not applicable, and identify which evidence still needs confirmation.
Multi-factor authentication
Across email, remote access, VPN, admin consoles, financial systems. Phishing-resistant for privileged accounts.
- MFA
- PRIVILEGED
Endpoint detection and response
EDR or XDR with active monitoring. Not just antivirus. Microsoft Defender for Business counts when configured.
- EDR
- MONITORED
Backups
Off-site, encrypted, tested, and immutable. We confirm a restore actually works, not just that backups run.
- 3-2-1
- IMMUTABLE
Email security
DMARC, anti-phishing, attachment sandboxing, link rewriting. Plus user training that has actually happened.
- DMARC
- TRAINING
Patching and asset inventory
Are workstations and servers actually patched within carrier-required windows? Do you know what you own?
- PATCH
- INVENTORY
Incident response plan
Written, current, with named contacts. Tested at least once a year. Many carriers require this in writing.
- WRITTEN
- TESTED
Privileged access management
Separate admin accounts, no shared logins, just-in-time admin where possible. Audit logs retained.
- LEAST PRIV
Vendor and supply chain
Third-party access reviewed. MSP and SaaS contracts in place. Breach notification clauses present.
- THIRD PARTY
Logging and monitoring
Critical systems logging to a place that survives a ransomware event. Alerts go somewhere a human reads.
- SIEM
- ALERTING
Fixed fee. No surprises.
Audit is a fixed-price engagement. Remediation is quoted separately so you can choose what to fix in-house and what to outsource.
Up to 25 users
One office, one Microsoft 365 tenant, one firewall. Most professional firms and trades sit here.
- $2,450
- 5 BUSINESS DAYS
26 to 75 users
Multiple offices, a couple of business systems, more vendor sprawl. Most regional businesses.
- $4,200
- 7 BUSINESS DAYS
76 to 200 users
Multi-site, on-prem servers in play, regulated industry. Quoted after a 15-minute scoping call.
- FROM $6,800
- 10 BUSINESS DAYS
Things people ask us.
If your question is not here, ask. We will review your message and confirm the next step.
Do you work with my broker?
What if we are not your client yet?
Can you guarantee renewal?
What carriers do you see most?
How long is the audit valid?
Do you sign an NDA?
Your renewal is closer than you think.
Renewal deadlines vary by policy and broker. Start early enough to allow for evidence collection, remediation decisions, and review before the submission deadline.
Frequently asked questions
What do cybersecurity audit services typically involve?
Our cybersecurity audit services focus on the controls relevant to your insurer's current questionnaire and your business risk. Depending on scope, we can review MFA, backups, endpoint protection, incident response and security awareness, then document observations and open items. The audit does not certify compliance or guarantee coverage.
Why are insurers requiring these audits now?
Insurer requirements differ by carrier, policy, industry and renewal. A current questionnaire or broker request is better evidence than a general trend; North Star can organize requested evidence within an agreed scope. The insurer decides whether coverage is offered and on what terms.
How does an audit help lower insurance premiums?
An audit can help identify controls and evidence to discuss with a broker, but it does not establish lower premiums or savings. Premiums and coverage depend on the insurer's underwriting, application, controls, claims history and other factors.
What happens if we fail the initial audit?
If our initial audit identifies critical security gaps, we provide a detailed remediation roadmap. Our technical team works alongside you to implement the necessary improvements, such as hardening your network or deploying managed EDR. Once the vulnerabilities are addressed, we perform a follow-up verification to ensure you meet the standards required for your cyber insurance application or renewal.