Evidence-based software risk assessment for cyber underwriting

CodeBridge assesses the customer’s software environment and delivers a signed, evidence-based report. The report identifies security vulnerabilities that could be exploited, material third-party software dependencies and architectural risks that may increase the impact or duration of a cyber incident. It translates technical findings into clear, underwriting-relevant evidence, supporting a cyber premium that can be explained, justified and defended. This guide outlines our assessment methodology, shows how each finding informs risk pricing, and explores how the same approach can be applied consistently across an entire portfolio rather than a single insured.

Delivered to support underwriting timetable

Codebridge’s assessment process is designed to fit within the practical timeframes of a cyber insurance renewal or new policy placement. We work with customers, brokers and insurers to understand the required decision date and plan the assessment around it. Where the scope and access requirements allow, our team can complete the work in weeks, not months, helping ensure the technical evidence is available when it is needed for underwriting. The assessment is carried out within the customer’s own environment, with controls in place to protect sensitive information. The result is a signed, evidence-based report that provides insurers with clear, traceable findings to support pricing, coverage and risk decisions.

Our workflow for reporting is:

Mobilise and map

Codebridge establishes a secure assessment environment within the customer’s systems. Sensitive software and data remain under the customer’s control.

We then build a detailed view of the software environment, including:

  • Application code and how key components interact
  • Third-party and open-source software dependencies
  • Cloud infrastructure, configuration and deployed services
  • Internet-facing applications, authentication points and other exposed entry points

Assess technical risk

Our team assesses the software environment for vulnerabilities and conditions that could contribute to a cyber incident, business interruption or a more severe loss.

This includes:

  • Identifying vulnerabilities that may be exploitable from the internet or other accessible entry points
  • Reviewing how separate components could create risk when combined
  • Assessing software architecture against common system-failure patterns
  • Testing relevant public-facing applications and access controls in a controlled, authorised manner
  • Tracing material findings to the relevant code, configuration or system component

Deliver underwriting evidence

Each finding is assessed against the factors that matter to cyber risk:

  • Likelihood of exploitation
  • Potential business and operational impact
  • Expected remediation effort and cost
  • Implications for policy terms, limits, exclusions and pricing

Codebridge provides a signed report and underwriting-ready evidence pack. We can also review the findings with the insurer and its risk engineering team, helping translate technical risk into clear and defensible underwriting decisions. Every material finding is traceable to the relevant file, line of code, configuration or system setting. The report records what was assessed, how the work was performed and the conclusions reached, creating an evidence trail suitable for insurer review, reinsurance scrutiny, regulatory enquiries or dispute resolution.

How the findings help inform cyber pricing

Codebridge’s report gives insurers a clearer picture of the software risks behind a cyber insurance application. It does not tell an insurer what premium to charge. Instead, it provides independent, traceable evidence that insurers can use alongside their own underwriting criteria and pricing models.

What Codebridge assesses

What the report helps explain

How it supports underwriting

Exploitable vulnerabilities

Which security weaknesses could realistically be reached and used by an attacker, and how serious they are

Helps validate the information provided in the insurance application and adjust pricing where appropriate

Combined software risks

Whether individual components could create a more serious risk when used together

Helps insurers account for risks that may be specific to the customer’s environment and consider appropriate terms or coverage limits

Third-party software

The use of open-source and third-party components, including age, licensing and known security issues

Helps insurers understand supplier and dependency-related exposure, including whether specific conditions, limits or exclusions may be needed

System resilience

Whether the system’s design could make an outage more likely, longer-lasting or more costly

Helps assess potential business-interruption exposure, including appropriate waiting periods and coverage limits

Personal-data protection

The type and volume of personal information held, where it is stored and how it is protected

Helps assess potential privacy and notification costs following a data breach

Cloud environment and costs

Whether cloud services, data growth or unmanaged resources could increase the scale or cost of an incident

Helps estimate the potential financial impact of disruption and supports more informed pricing decisions

Codebridge provides the evidence; the insurer makes the underwriting decision. Each finding is documented clearly and can be traced back to the relevant code, configuration or system component. This gives insurers a reliable record to support their pricing decisions and provides an evidence trail for internal review, reinsurance and regulatory scrutiny.

Assessing an entire cyber portfolio, not just one customer

Checking one customer at a time is useful, but it only goes so far. For an insurer writing a lot of policies, the better option is a subscription. Codebridge checks every customer in the book, refreshes it every three months or every month, and charges per policy at a price that fits standard rates.

One customer at a time

  • Runs when a policy is written or renewed.
  • $75,000 to $200,000 per customer.
  • A snapshot of one day.
  • Best for the biggest and most important accounts.

Whole book subscription

  • Codebridge watches every customer, all the time.
  • Usually $2,000 to $6,000 per policy per year.
  • Refreshed every three months, and again straight away if something happens.
  • Best for standard mid-size cyber policies and high-volume books.

The subscription is what actually moves the loss ratio over time. When a new type of attack appears, or a widely used supplier is compromised, the insurer can see which customers in the book are affected and act while the policies are still live, instead of finding out from the claims.

Common worries, and the answers

A thorough review needs to look across the parts of the software that are most likely to affect value, risk, maintainability, and future change. The exact scope depends on the engagement, but the goal is always the same, to identify material issues before they become a commercial problem.

1

“Will customers agree to this level of software review?”

Yes, when the process is clear, controlled and designed around their security requirements. Codebridge performs the assessment within the customer’s own environment, helping keep sensitive code and data under the customer’s control. If needed, we can also work with the customer’s security team to explain the process and address concerns before the assessment begins.

2

“This will slow underwriting down.”

It does not need to. Codebridge is flexible and works around reasonable renewal and placement timeframes, ensuring the required software-risk evidence is available when underwriting decisions need to be made. Our assessment approach is designed to support the underwriting process, not delay it.

3

“How is this different from outside scanning services already in use?”

Services like BitSight, SecurityScorecard and Black Kite look at a company from the outside, the way an attacker first would. That is useful, but it stops at the front door. Codebridge looks inside, the code, the borrowed libraries, and the way the system is built. That is where the two-part problems live, and outside scanners cannot see any of it.

4

“Will the regulator accept this approach?”

A signed, evidence-based report helps insurers show how cyber risk was assessed and underwriting decisions were made. Codebridge documents what was reviewed, how the assessment was completed and the findings that informed the decision, creating a clear, traceable basis for pricing, policy terms and risk-management actions, while supporting internal governance, reinsurance discussions and regulatory review.

5

“What if the customer fixes the problem before the policy is written?”

That is the best possible result. The insurer gets the evidence, and the risk goes down at the same time. Codebridge records the problem and the fix side by side in the report. The customer’s price reflects the better position, and the insurer covers a genuinely safer company. The only loser is the risk itself.

A real example: pricing a renewal on proof

An Australian payments company came up for renewal. About $40 million in revenue, around 200 staff, moving money across borders. They wanted $50 million of cover. The year before, the price had been set from the form and an outside scan, and the insurer now believed it was too low for how much the company had grown. The broker asked for the whole thing to be done again, properly.

Codebridge installed its tools in the customer’s own cloud on day one. By the end of week two, the team had found:

  • Two serious security holes an attacker could reach, both in borrowed code the customer did not even know they were using.
  • One two-part problem: a PDF renderer and an image handler that, running in the same request, allowed an outside address to reach the company’s internal systems from the inside.
  • Three ways the system would fall over under the growth the company had already forecast for the following quarter.
  • Less personal data exposed than the form had suggested, which actually worked in the customer’s favour.

Here is what the insurer did with that. They held the base price. They capped what they would pay for the two-part problem at 25 percent of the total cover. They pushed the business interruption waiting period out by 24 hours. They tightened the cap on data breach notification costs. The final price came out 12 percent above what the form alone would have produced. But now it was a policy the reinsurer could see had been priced properly, and the customer started using the Codebridge report internally as its own security record.

Final outcome for the client

The customer secured cyber cover that better reflected their software-related risk. While the premium was slightly higher than initially expected, the detailed assessment gave them greater confidence in the cover and the decisions behind it. For the insurer and reinsurer, the documented evidence supported a clear, defensible view of the risk, pricing and policy terms.

Common questions

No. Codebridge does not insure anything. Codebridge gathers the evidence, the insurer decides what to do with it. That means insurers, brokers, reinsurers and the customers themselves can all work with Codebridge without conflict.

Yes. These reports can generally expected to be produced within three weeks, which fits inside almost every new policy window. Customers often keep the report and use it internally afterwards, whether or not the policy goes ahead.

The assessment is completed within the customer’s own environment, helping keep sensitive code, systems and data under their control throughout the process. Only the agreed assessment findings and final report are shared with Codebridge. Where required, the report can also be generated within the customer’s environment and provided directly to the insurer. Privacy and data protection are built into the assessment approach, not simply addressed through contractual commitments.

Yes. Codebridge is based in Melbourne and works with customers in the US, the UK, Europe and across Asia. Because Codebridge never moves anyone’s code, it does not matter which country it sits in.

Book a consultation with Codebridge.

Thirty minutes with a Codebridge principal. Bring an account the pricing team is stuck on, and we will walk through what the evidence would show and how it would feed the premium.