HiveSec Contact us
Products Partners Research Trust Company Contact us

Score the risk. Then improve it.

Rates are softening and loss ratios are climbing. Margin now lives in how you select the risk and how you improve it after bind. HiveSec Engine for Insurance is agentic underwriting intelligence for the cyber insurance market.

Download the Insurance datasheet PDF · 226 KB

$16.3bnglobal cyber premium, 2025 · Munich Re
53%US cyber loss ratio, 2025 · AM Best
~20%rate declines through 2025, slowing into 2026 · Aon
The product

Select the risk. Improve the risk.

01 · Select

BindSight™

An evidence-linked Cyber Tier Score, kept current by continuous scanning. Every penalty decomposes to an observed signal: a score your underwriters can defend and your actuaries can take apart.

02 · Improve

Loss Control Desk™

Analyst-reviewed findings released to insureds, chased to closure, and evidenced for renewal.

Evidence

What is driving the score.

Server-computed penalties ● Observed
−45Known-exploited vulnerability (CISA KEV)
−25Ransomware-linked CVE (CISA KEV)
−18High exploit probability (EPSS ≥ 0.5)
−10Internet-exposed RDP
−8Confirmed-present findings
Each figure is the point penalty the signal costs the Security Score: weight × count, capped. Drill down from score to signal to finding to host.
BindSight

Select the risk at quote.

Cyber Tier Score, transparent by construction

A 0 to 100 Security Score and Exposure Score for every insured, resolved to a matrix cell and an A to F grade. The full scoring model is documented: every weight, every cap, every input.

Confirmed-present findings

BindSight confirms each vulnerability is present and valid before it surfaces as a finding: HiveSec's AI agents test the exposure and peer-review the conclusion, the same agentic investigation that runs the assurance catalogue. Every observation traces to the host it was seen on, and what reaches the queue can go in front of a broker.

Signals weighted by what drives claims

A known-exploited or ransomware-linked CVE costs an insured more points than a routine finding. Weightings draw on CISA KEV and EPSS, alongside exposure signals: internet-facing RDP, exposed databases, SMB and NetBIOS, and cleartext legacy protocols.

Underwriting queue and renewal triage

A queue ordered by bind-by date. Renewals due in the next 30 days, accounts awaiting a score, and grade drift across the book: the desk's priorities, already in order.

What-if remediation projection

Tick the exposures an insured could fix and project the new score: a ready-made subjectivity list at quote and a loss-control agenda mid-term.

Your whole book, continuously monitored

Score-over-time for every insured, cohort percentiles, grade distribution, and priority actions ranked across the whole book. The platform observes from outside, with nothing to deploy and nothing to ask of the insured. When an aggregation event breaks, answer “which of our insureds are exposed?” from live observations.

The appetite map

Two axes, one decision.

Inherent exposure of the attack surface, plotted against demonstrated security posture. Each insured lands in a matrix cell and grade that map to appetite, tiering and rate. The book distribution shows where your portfolio concentrates.

Loss Control Desk

Improve the risk in-term.

Selection protects the margin once; loss control protects it all year. The Loss Control Desk runs mid-term policyholder engagement across the book, so subjectivities written at quote get chased, evidenced and closed before renewal. Improved posture earns its rate credit on the evidence.

Detectedobserved on scan Analyst reviewcurated for release Released to insuredbriefing and fix steps Awaiting insuredremediation tracked Closedrenewal evidence

Analyst-reviewed release

Every finding is reviewed before it reaches the insured: released or risk-accepted, finding by finding. The platform confirms the finding is real; the analyst decides what the insured sees.

Briefings and case threads

The insured receives a remediation briefing with evidence, impact and fix steps attached; internal notes stay internal. Reports are downloadable per case.

Awaiting insured

One queue for what the desk owes and what the insured owes, so nothing stalls silently until renewal.

Renewal evidence

The engagement trail, released, remediated and re-verified on scan, lands next to the score at re-rating.

Run the desk with your own risk engineers, or have HiveSec's offensive security analysts operate it as a managed service. Brokers and underwriters operating the platform across their own book are covered on Operate HiveSec Engine.

Audiences

Built for the desk.

UnderwritersFaster submission triage, and a decision they can defend at referral with the evidence attached.
Portfolio and exposure managersA live view of where the book concentrates, and what moved since last quarter.
ActuariesA fully documented scoring model, penalty = weight × count, capped, with auditable inputs for rating factors.
MGAs and MGUsShow capacity providers why each risk was selected; API-first for fast-flow SME decisioning.
Risk engineers and loss controlThe desk as the working queue: release decisions, briefings, and remediation tracked to closure.
How it works

From account to renewal.

01

Profile

Point the platform at an account; it maps the insured's internet-facing estate.

02

Observe and validate

The platform measures the signals, confirms each finding present, and applies threat-intelligence enrichment.

03

Score and steer

Cyber Tier Score, grade, matrix cell and book percentile land in your queue and over the API.

04

Engage and improve

Brief the insured, track the fix, and carry the evidence into renewal.

Scoring model v1. Scores are evidence summaries of observed external signals; they are not a guarantee of insurability or loss outcome.

Engage

See your book through the evidence.

Web platform and API, with a workspace for each book or programme. We will walk your in-force book through the platform.

Request a briefing