Cyber Insurance Compliance: Better Applications, Stronger Risk Conversations, and the Role of Verification with Matt Naumoff

Cyber Insurance Compliance: Better Applications, Stronger Risk Conversations, and the Role of Verification with Matt Naumoff

A completed cyber application tells you what a business says about its security.

The next question is whether the evidence supports those answers.

That distinction shaped a recent episode of the Power Producers Podcast, where David Carothers welcomed Matt Naumoff of Waypoint to discuss cyber insurance compliance, risk validation, and collaboration with managed services providers.

Their conversation explored a problem that reaches beyond completing forms. Producers need useful information about a client’s operations, while technical specialists need a clear understanding of the safeguards being represented to insurers.

When those conversations happen separately, important gaps can remain unresolved.

For middle market producers, the opportunity is to bring the right people and information together before an application reaches underwriting.

A stronger cyber conversation begins with understanding the risk and verifying the information used to describe it.

Why Cyber Insurance Compliance Starts Before the Quote

Matt came to the discussion with experience in the IT and managed services environment.

He described situations in which a customer’s explanation of its technology did not match what his team discovered during onboarding.

Those differences created problems at the beginning of the relationship. Instead of delivering the planned services, the team had to address unexpected issues.

The insurance application process can face a similar challenge.

A business owner may answer a question based on what they believe their IT provider has implemented. Meanwhile, the provider may understand the scope of its work differently.

Without further investigation, that misunderstanding can become part of the submission.

Matt described Waypoint as a tool intended to compare application answers with supporting evidence and identify discrepancies.

Within this conversation, cyber insurance compliance concerned the security representations and requirements associated with the insurance process. It was not presented as a substitute for evaluating every legal or regulatory obligation a business may have.

The practical starting point is simple: Establish what the question asks, who can answer it, and what supports the response.

Use a Trust-but-Verify Approach to Applications

Matt characterized the approach as “trust but verify.”

The purpose is to investigate whether the client’s answers accurately describe the environment being insured.

That requires more than repeating the same question.

A producer may receive a confident answer without knowing whether the person responding has the technical information needed to support it. Asking for evidence gives the discussion a more useful foundation.

During the episode, Matt described using uploaded documents and technical information to cross-reference responses.

For producers, the broader lesson applies regardless of the assessment tool involved.

When an answer is unclear, involve the person responsible for the control. Clarify what has been implemented and resolve conflicting information before treating the response as complete.

A checked box is a starting point for verification, rather than the entire assessment.

This approach also creates a more productive conversation with the client. The focus becomes understanding what exists and addressing what remains uncertain.

A Case Study Connected Assessment with Remediation

Matt shared an example involving an insurance business in Alabama.

According to his account, the organization wanted to experience the assessment process itself before considering a broader relationship.

His team reviewed the environment and compared its findings with the cyber application, policy, and services provided by the organization’s managed services provider.

The review identified gaps.

Those findings were then taken back to the provider, which addressed them. Matt reported that the organization subsequently saved money on its cyber policy at renewal.

That was one reported outcome. It does not establish that every assessment will produce a premium reduction.

The more useful lesson is the sequence of work.

The assessment identified differences. A technical partner handled remediation. Updated information then supported the renewal conversation.

Finding a problem creates value only when someone understands what to do next.

For an agency, that means identifying who receives the findings, who is responsible for addressing them, and how the team will confirm that the work has been completed.

Understand the Business Behind the Application

David connected cyber risk validation to his broader total cost of risk approach.

Before recommending how a business should finance or transfer risk, the producer needs to understand the exposures within its operations.

Payroll, sales, and classification information serve a purpose. However, they do not explain the full risk.

David emphasized the value of visiting the business, talking with its people, and understanding how the operation functions.

The same curiosity belongs in a cyber conversation.

For example, a producer can ask how the company uses technology to serve customers, keep work moving, and communicate with other parties. The answers help establish why a disruption would matter.

Technical specialists can then investigate the safeguards supporting those activities.

This division of work is important for middle market producers. They can lead the business discussion while bringing in qualified help for the technical assessment.

Understanding the operation gives the application context.

Without that context, the process can become an exercise in collecting answers without understanding what they mean.

Discuss Cyber Limits with Evidence and Context

David also challenged the habit of recommending a limit because it seems easy to sell.

His concern was that producers may lead with an affordable option before fully exploring the client’s exposure.

He encouraged listeners to explain their recommendations and document the choices presented to the client.

During the conversation, David described using third-party cyber modeling reports to support discussions about potential loss severity and insurance limits.

Those reports can give a producer additional information to explain a recommendation. They still require interpretation in light of the business and the coverage being considered.

The episode did not establish one appropriate limit for every company.

Instead, it highlighted the importance of a reasoned discussion.

What information supports the recommendation? Which options has the client considered? Where does the client choose to retain more risk?

A limit recommendation should follow an examination of the exposure.

That approach gives the client a clearer basis for making a decision and gives the producer a more complete record of the conversation.

Keep Risk Modeling and Control Validation Distinct

The episode discussed both cyber modeling and verification of security information.

Those activities contribute to different parts of the advisory process.

A modeling report can help frame potential financial consequences. Control validation examines whether the safeguards described in an application are supported by evidence.

One does not automatically answer the questions addressed by the other.

A business may have documented controls and still need a thoughtful discussion about limits. Conversely, selecting a higher limit does not resolve an inaccurate application response.

For producers, separating these questions makes the conversation easier to manage.

Begin with the operation and its exposures. Bring in appropriate expertise to evaluate security representations. Then use the available information to discuss coverage and risk management options.

The objective is a coordinated assessment.

Each resource should have a defined purpose, and the client should understand how the findings contribute to the overall recommendation.

Give the MSP a Clear Role in Closing Gaps

Insurance advisor and IT specialist review cyber security findings and plan next steps together.

Managed services providers, or MSPs, were central to Matt’s explanation.

He described the assessment as a way to identify issues that a client’s technical provider could address.

That distinction matters. Finding a gap and fixing it are separate responsibilities.

A useful report should lead to a conversation about the corrective work, the person responsible, and the evidence needed to confirm completion.

David also raised a concern about assuming that every IT service arrangement includes proactive security and compliance work.

The practical response is to examine the actual scope of services.

What has the provider agreed to handle? Which responsibilities remain with the customer? Does the current arrangement address the items raised during the insurance assessment?

Those questions keep the discussion specific.

The presence of an IT provider does not answer every question about the client’s security program.

Producers can help coordinate the conversation while allowing the technical provider to explain and perform its work.

Build Collaboration Around the Client’s Needs

David asked whether introducing an outside assessment could create tension with an existing MSP.

Matt said he had not encountered that problem in the prospecting conversations he described.

He emphasized working with providers that take a proactive approach and tailor their services to the customer.

For producers, the way an assessment is introduced can influence the response.

Explain the purpose clearly: The team wants to understand the security information being supplied for insurance and identify anything that requires clarification.

That gives the MSP a defined role.

The provider can explain the environment, supply evidence, and respond to findings. Meanwhile, the agency can focus on communicating the risk and managing the insurance process.

A practical opening could be:

“Before we submit the application, we want to confirm that the answers reflect your current environment. We can involve your IT provider and a technical specialist to review the supporting information.”

That wording is an example of how to apply the discussion. It keeps the conversation focused on accuracy and shared responsibilities.

Use Technical Specialists Without Giving Up the Advisory Role

Matt made clear that he was not acting as a licensed insurance agent.

His role was to help investigate the technical environment and provide information that could support the agency’s work.

The producer remained responsible for the insurance conversation.

That division offers a useful model for agents who find cyber intimidating.

You do not need to personally resolve every technical issue to coordinate a stronger process. However, you need enough understanding to recognize when specialist input is required.

Ask the specialist to explain findings in language the client can use.

Then connect those findings to the questions that need resolution before the submission proceeds.

David’s concern was that some producers avoid deeper cyber discussions because they fear uncovering problems they cannot fix themselves.

A dependable technical relationship gives them somewhere to turn.

The producer’s value includes knowing which resources to bring into the conversation and making sure the client understands the next step.

Treat Verification as Support, Not a Coverage Guarantee

The discussion emphasized the importance of accurate representations and appropriate safeguards.

That should not become a promise that an assessment guarantees a claim payment.

A technical review can help identify discrepancies and document findings. It does not replace the policy or determine the outcome of a future claim.

Similarly, a security gap should not automatically be described as proof that all coverage will disappear.

Producers should distinguish what the assessment establishes from questions that require review of the insurance contract and the circumstances involved.

That precision strengthens the client conversation.

If a finding raises a question about an application answer or policy requirement, clarify it with the appropriate parties before proceeding.

The value of verification is better information and a clearer path to corrective action.

Keep the explanation tied to that value, with specific findings and documented follow-through.

Recognize That the Work Continues After Assessment

Assessment document, follow-up notes, and calendar illustrating ongoing cyber risk review.

Matt described an ongoing service model in which technical providers would address findings over time.

That reinforces an important operational point: An assessment captures information that needs to remain relevant as the business changes.

For producers, the practical application is to build a follow-up process around unresolved items and renewal preparation.

Confirm what has changed since the previous review. Determine whether corrective work has been completed. Involve the appropriate technical contact when the answers need updating.

This does not require turning the producer into the client’s IT department.

It requires keeping responsibilities visible and making sure the information used in the insurance process reflects the business being presented.

A report that is filed away without follow-through has limited usefulness.

A report connected to assigned actions can support a more informed conversation the next time the account comes to market.

Understand How Carrier Services Affect Existing Relationships

Near the end of the episode, David discussed situations in which cyber carriers offer services that may overlap with an existing MSP relationship.

His point was to understand that overlap and communicate about it.

A producer may receive referrals from an MSP that already supports the client. Introducing another service without understanding its scope can create confusion over responsibilities and expectations.

David described communicating with carriers when an established MSP relationship was involved.

He also emphasized that the client’s interests remain the priority.

For agencies, the practical lesson is to review what is included in the insurance offering and explain it clearly.

Determine which services supplement the current arrangement and which could replace part of it. Discuss relevant options with the client and clarify how the parties will work together.

Strong referral relationships benefit from transparency, especially when the services surrounding a policy continue to evolve.

Make Cyber Insurance Compliance Part of a Better Advisory Process

David and Matt’s conversation returned to the importance of understanding what is actually happening inside the client’s business.

An application provides information. Supporting evidence helps establish whether that information is accurate. Technical expertise helps turn identified gaps into a plan.

The producer connects those pieces to the insurance discussion.

Start with one account where the security answers deserve closer examination.

Identify the person responsible for the technical information. Review what supports the responses, clarify any discrepancies, and document the actions agreed upon.

Then use the improved understanding to strengthen the submission and the client’s decision-making.

A better cyber process gives the client more clarity about its risk, its safeguards, and the work still to be done.

Listen to “Cyber Compliance, Risk Validation, and the Future of Cyber Insurance with Matt Naumoff” on the Power Producers Podcast for the full conversation. Explore Killing Commercial for more practical discussions about risk assessment, producer development, and building stronger client relationships.

Responses

Test Message

Killing Commercial Login