Delivered to support underwriting timetable
Codebridge’s assessment process is designed to fit within the practical timeframes of a cyber insurance renewal or new policy placement. We work with customers, brokers and insurers to understand the required decision date and plan the assessment around it. Where the scope and access requirements allow, our team can complete the work in weeks, not months, helping ensure the technical evidence is available when it is needed for underwriting. The assessment is carried out within the customer’s own environment, with controls in place to protect sensitive information. The result is a signed, evidence-based report that provides insurers with clear, traceable findings to support pricing, coverage and risk decisions.
Our workflow for reporting is:
Mobilise and map
Codebridge establishes a secure assessment environment within the customer’s systems. Sensitive software and data remain under the customer’s control.
We then build a detailed view of the software environment, including:
Assess technical risk
Our team assesses the software environment for vulnerabilities and conditions that could contribute to a cyber incident, business interruption or a more severe loss.
This includes:
Deliver underwriting evidence
Each finding is assessed against the factors that matter to cyber risk:
Codebridge provides a signed report and underwriting-ready evidence pack. We can also review the findings with the insurer and its risk engineering team, helping translate technical risk into clear and defensible underwriting decisions. Every material finding is traceable to the relevant file, line of code, configuration or system setting. The report records what was assessed, how the work was performed and the conclusions reached, creating an evidence trail suitable for insurer review, reinsurance scrutiny, regulatory enquiries or dispute resolution.
How the findings help inform cyber pricing
Codebridge’s report gives insurers a clearer picture of the software risks behind a cyber insurance application. It does not tell an insurer what premium to charge. Instead, it provides independent, traceable evidence that insurers can use alongside their own underwriting criteria and pricing models.
What Codebridge assesses | What the report helps explain | How it supports underwriting |
|---|---|---|
Exploitable vulnerabilities | Which security weaknesses could realistically be reached and used by an attacker, and how serious they are | Helps validate the information provided in the insurance application and adjust pricing where appropriate |
Combined software risks | Whether individual components could create a more serious risk when used together | Helps insurers account for risks that may be specific to the customer’s environment and consider appropriate terms or coverage limits |
Third-party software | The use of open-source and third-party components, including age, licensing and known security issues | Helps insurers understand supplier and dependency-related exposure, including whether specific conditions, limits or exclusions may be needed |
System resilience | Whether the system’s design could make an outage more likely, longer-lasting or more costly | Helps assess potential business-interruption exposure, including appropriate waiting periods and coverage limits |
Personal-data protection | The type and volume of personal information held, where it is stored and how it is protected | Helps assess potential privacy and notification costs following a data breach |
Cloud environment and costs | Whether cloud services, data growth or unmanaged resources could increase the scale or cost of an incident | Helps estimate the potential financial impact of disruption and supports more informed pricing decisions |
Codebridge provides the evidence; the insurer makes the underwriting decision. Each finding is documented clearly and can be traced back to the relevant code, configuration or system component. This gives insurers a reliable record to support their pricing decisions and provides an evidence trail for internal review, reinsurance and regulatory scrutiny.
Assessing an entire cyber portfolio, not just one customer
Checking one customer at a time is useful, but it only goes so far. For an insurer writing a lot of policies, the better option is a subscription. Codebridge checks every customer in the book, refreshes it every three months or every month, and charges per policy at a price that fits standard rates.
The subscription is what actually moves the loss ratio over time. When a new type of attack appears, or a widely used supplier is compromised, the insurer can see which customers in the book are affected and act while the policies are still live, instead of finding out from the claims.
Common worries, and the answers
A thorough review needs to look across the parts of the software that are most likely to affect value, risk, maintainability, and future change. The exact scope depends on the engagement, but the goal is always the same, to identify material issues before they become a commercial problem.
“Will customers agree to this level of software review?”
Yes, when the process is clear, controlled and designed around their security requirements. Codebridge performs the assessment within the customer’s own environment, helping keep sensitive code and data under the customer’s control. If needed, we can also work with the customer’s security team to explain the process and address concerns before the assessment begins.
“This will slow underwriting down.”
It does not need to. Codebridge is flexible and works around reasonable renewal and placement timeframes, ensuring the required software-risk evidence is available when underwriting decisions need to be made. Our assessment approach is designed to support the underwriting process, not delay it.
“How is this different from outside scanning services already in use?”
Services like BitSight, SecurityScorecard and Black Kite look at a company from the outside, the way an attacker first would. That is useful, but it stops at the front door. Codebridge looks inside, the code, the borrowed libraries, and the way the system is built. That is where the two-part problems live, and outside scanners cannot see any of it.
“Will the regulator accept this approach?”
A signed, evidence-based report helps insurers show how cyber risk was assessed and underwriting decisions were made. Codebridge documents what was reviewed, how the assessment was completed and the findings that informed the decision, creating a clear, traceable basis for pricing, policy terms and risk-management actions, while supporting internal governance, reinsurance discussions and regulatory review.
“What if the customer fixes the problem before the policy is written?”
That is the best possible result. The insurer gets the evidence, and the risk goes down at the same time. Codebridge records the problem and the fix side by side in the report. The customer’s price reflects the better position, and the insurer covers a genuinely safer company. The only loser is the risk itself.
A real example: pricing a renewal on proof
An Australian payments company came up for renewal. About $40 million in revenue, around 200 staff, moving money across borders. They wanted $50 million of cover. The year before, the price had been set from the form and an outside scan, and the insurer now believed it was too low for how much the company had grown. The broker asked for the whole thing to be done again, properly.
Codebridge installed its tools in the customer’s own cloud on day one. By the end of week two, the team had found:
Here is what the insurer did with that. They held the base price. They capped what they would pay for the two-part problem at 25 percent of the total cover. They pushed the business interruption waiting period out by 24 hours. They tightened the cap on data breach notification costs. The final price came out 12 percent above what the form alone would have produced. But now it was a policy the reinsurer could see had been priced properly, and the customer started using the Codebridge report internally as its own security record.
Final outcome for the client
The customer secured cyber cover that better reflected their software-related risk. While the premium was slightly higher than initially expected, the detailed assessment gave them greater confidence in the cover and the decisions behind it. For the insurer and reinsurer, the documented evidence supported a clear, defensible view of the risk, pricing and policy terms.
Common questions
Book a consultation with Codebridge.
Thirty minutes with a Codebridge principal. Bring an account the pricing team is stuck on, and we will walk through what the evidence would show and how it would feed the premium.
