Business
Business Security · Overview Executive Protection
Individual
Personal Protection · Overview Personal Credential Briefing
Programs
Perimeter · Households Wealth Firms Sports & Entertainment Agencies Reputation Threat Intelligence Wealth Manager Program Business Broker Program Partners
Intelligence
Research Library Threat Intelligence Global Breach Map Recent Breach Disclosures
Company
How It Works About Contact
Sign In
Networks / Insurers and mutuals

Every member mutual, watched from the outside.

For insurance associations, mutual groups and broker networks. One ranked board of every member's email, staff logins and lookalike domains, read every day, with the fix handed to whoever runs each member's systems.

You keep the relationship. We bring the evidence, and record the day each opening closed.

Private to you|Nothing tested or logged into|Human-reviewed
Network readingPrivate to you
YOUR NETWORK EACH MEMBER MUTUAL ITS DOMAIN AND EMAIL WHAT IS OPEN TODAY
Email that can be forged in its nameDaily
Staff addresses in monitored breach databasesDaily
Lookalike domains registeredDaily
What AI assistants tell clients about itMonthly
Human-reviewed before releaseEvery line checkable
01 · Why it lands on you

A forged email from one mutual is trusted because of the others.

Policyholders, brokers and adjusters act on email that carries a mutual's name: premium notices, claim payments, changes to banking details. When one mutual's email can be forged or one staff password is already in a breach database, the false instruction travels on the trust the whole group has built. The policyholder who is misled calls the mutual, and the questions reach the association. The same openings are the ones underwriters now ask about before they write cyber cover, so a member that has them is also a member that will be asked about them.

Your member mutualsEvery one listed publicly
What we readPublic records, ordinary page visits
Who sees itYou alone
02 · How it works

One system, five steps, every member mutual.

A network summary is the first reading. The watch keeps reading every day, tells you and the member mutual the day something new opens, and hands over the fix. A person reviews every assessment before it is released.

01
Watch

Email that can be forged, staff logins in breach databases and lookalike domains, for every member, every day. What AI assistants tell clients about each member, every month.

02
Rank

One board, most exposed first, with the evidence and the one-line check beside each member.

03
Alert

A new opening reaches you and the member the same day, with the incident reported that week that used the same way in.

04
Fix

The member gets a step-by-step fix for its own set-up, addressed to whoever runs its systems.

05
Prove

Each closed opening is re-checked and recorded, so the member can show it was fixed and when.

03 · What you get

One board for you, a fix for each member mutual.

For the network
  • One board across every member, ranked, with the evidence
  • Same-day alerts when a member's exposure changes
  • A monthly summary of what changed across your members
  • Private links like this one, and logins for your team
For each member mutual
  • A full assessment: three documents and a signed summary
  • Its own dashboard, re-checked every day
  • A step-by-step fix for its own set-up
  • Alerts matched to the incidents reported that week
For your policyholdersin your portal
  • A consent page each policyholder agrees to once, and can withdraw on
  • A check at application or renewal, run by your staff
  • Your book re-checked every month, most openings first
  • A CSV export for your underwriting system; a direct feed set up with you

Nothing reaches any of your member mutuals without your say-so. You decide who hears what, and when.

04 · Independence

Works with the IT you already have.

We never replace a member's IT provider and we never sell or perform the fix. The exact fix goes to whoever runs each member's systems, written for their set-up. When they say it is done, we re-check it from outside and record the date it closed.

Independent01

Like an auditor, we check and record. We earn nothing from the repair, so nothing in a reading is there to create work.

Addressed to the right person02

Each fix is written for whoever runs that member's email and domain, whether in-house or a provider.

Closed on the record03

A fix counts when the outside view shows it, with the date, so a member can show its board and its insurer.

05 · Where your member mutuals are in Ontario

What the guidance already expects, in its own words.

Financial Services Regulatory Authority of Onta…

FSRA IT Risk Management Guidance (GR0016INT)

The guidance that applies to Ontario-incorporated insurers, effective 1 April 2024. It places accountability for IT risk with each insurer's board, expects risks and vulnerabilities to be identified and monitored on a regular basis, and asks for a material IT risk incident to be reported to FSRA no later than 72 hours after it is determined.

"Accountability for the effective management of IT risk rests with the Insurer's Board of Directors."
Source: Financial Services Regulatory Authority of Ontario
Financial Services Regulatory Authority of Onta…

The same guidance on distribution channels

It extends an insurer's IT risk expectations to its brokers and outsourced functions.

"This includes ensuring that IT risks are being effectively managed through all of its distribution channels and outsourced functions"
Source: Financial Services Regulatory Authority of Ontario

A reading is outside evidence a board can use for this. It does not say any member mutual is out of step with it.

06 · Questions networks ask

What we are usually asked first.

Our members already have IT providers.

We do not replace them. The exact fix goes to whoever runs each member's systems, and we re-check and record the date it closed.

We already give members cyber templates and self-assessment material.

Templates set out what should be true. This shows what is true today, from outside, for each member, and keeps reading every day.

Did you test our members' systems?

No. Nothing was logged into or tested. Public DNS, certificate and registration records, monitored breach databases and an ordinary visit to each public website.

07 · Request a network summary

See your members from the outside, privately.

Tell us who you are and where your members are listed. We read the public side of every member you list and send you a private summary, ranked, with the check anyone can run beside each line.

What we readPublic records only
Your membersNever contacted
Who sees itYou alone
No-charge pilotThree members, authorised

Choose three members. We run the full assessment for them at no charge, with each firm's written authorisation, and show you the result. Or write to [email protected].

Network summary requestPrivate

We reply from [email protected]. Nothing is sent to your members.