Skip to content

Every yes on your insurance form, true and evidenced

Your insurer’s renewal form asks for MFA, endpoint protection, tested backups and DMARC. We check each one, fix what’s missing, and give your broker the evidence.

Free 30-minute call. The assessment from €3,600, fixed and confirmed before any work begins.

Unmesha security assessmentsUM-SA-001 · Revision 4.0

The evidence behind Fernleaf’s insurance answers

The renewal form asks about MFA, laptops, backups and email. Here’s what’s true today and what changes before the renewal, with the evidence for each.

Who it’s for

Your insurance broker

What we checked

MFA on staff accounts, endpoint protection on laptops, backups and restores, and email authentication for fernleaf.example.

The form’s questions

MFA
Partly. On for the people who deploy, and on every account after the Identity fix.
Laptops
Yes. Managed and encrypted, with endpoint protection.
Backups
Partly. Nightly and kept 14 days. A documented restore test comes with the Backups and recovery fix.
Email
Yes. DMARC at reject, so no one can send as fernleaf.example.

What we found

  • MFA covers the people who deploy, not every staff account.
  • Backups run nightly but have never been restored in a test.
  • Laptops and email already meet what the form asks.

In place now

  • Staff laptops managed, encrypted and running endpoint protection.
  • SPF, DKIM and DMARC at reject for fernleaf.example.
  • Nightly database backups, kept for 14 days.

Planned

  • Identity: MFA on every staff account3 to 4 weeks
  • Backups and recovery: immutable copies and a documented restore test1 week

Evidence

Every answer on this page points at an item in the evidence index on page 24: exports, policy files, restore logs.

Questions

Want the detail behind a line? Ask Fernleaf for the finding pages, and we’ll walk you through them.

Fictional sample. The company, systems and data are invented; no real client was assessed.

Prepared by Unmesha Technologies for Fernleaf Billing Ltd
An example of the one-page summary you forward, from our fictional sample report.Read the whole sample report

When you need it

Usually one of these, often with a date attached.

  • Your renewal asks for MFA, endpoint protection, tested backups or DMARC.
  • Your quote was declined, made conditional, or the premium went up.
  • An agency handover left you unsure who holds the keys.

What you get, and what it costs

Step 1 is the assessment, at one fixed fee. Step 2 is only the fixes the person asking needs. Every fix, with prices.

Step 1: what the assessment includes

  • A gap check against the insurer’s application.
  • The application answered, with an evidence folder your broker can forward.
  • A remediation plan timed to the renewal date.
  • A one-page summary for the broker.

Variants

  • Email spoofing protection (from €900)SPF, DKIM and DMARC taken to enforcement, on its own.
  • Access check after a handover (from €2,700)Access, keys and ownership verified after an agency or contractor handover.

How it works

Three steps. You know the price before each one starts.

  1. A free call

    Tell us what you need and who’s asking. We’ll say what we’d check and give you a fixed price.

    30 minutesFree

  2. We check your product

    Your app, your cloud and how code gets to production. You get a report, a plan and a one-page summary to send to whoever’s asking.

    About two weeksfrom €3,600

  3. We fix what’s missing

    We set up what your product lacks, like MFA, alerts and tested backups. Your developers make any code changes, with our help. Then we retest, at no extra cost.

    Fixed price per fixfrom €700

Before you enquire

What people ask us most. Anything else, ask on the call.

Will this lower our premium?

We can’t promise that. Insurers set premiums. What we do is make every answer on the form true, with evidence, which is what they price on.

We’re not sure what our old agency left behind. Where do we start?

With an access check. We list every account, key and domain that can reach your systems, who holds each one, and what to revoke.

What do you need from us?

The form, questionnaire or report, and a call with whoever runs your cloud and your workspace. For a fix, a named admin account for the systems it changes, set up the way we describe on the call.

How do you handle our admin access?

You create a named account for us with only the rights the fix needs, and you can see everything it does. We never use shared logins. Each fix lists its changes, when they happen and how to roll them back, and you remove the account when the fix is done.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Send us the form

Which insurer, when the renewal is due, and which questions you’re unsure about.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team

Request a free call

Send a short outline of what you want checked and any deadline.

Email Unmesha

Please leave out passwords and customer data. How we handle enquiry information.