Boardroom Answers · Security & Compliance · Security & Cyber Risk
Do you carry cyber insurance, and what's your incident track record? "We've never been breached" from a company with no customers isn't the reassurance you think it is.?
The question a Chief Risk Officer (CRO) asks.
The short answer
No policy yet and no track record to sell you — pre-launch honesty. Coverage binds at commercial launch, sized with real contracts; until then, what you can verify is inspectable engineering, and what protects you contractually is the DPA's notification and cooperation duties.
The full executive answer
You've pre-empted the weak answer, so let me not give it. Correct: we have no incident history because we have no operating history — we are pre-launch, and "never breached" is a statement about elapsed time, not resilience. I won't offer it as evidence. On insurance: as of today we do not carry a cyber liability policy; binding appropriate cyber and technology E&O coverage is a commercial-launch gate on our roadmap — it's sequenced with first customer contracts because policy scope should match actual exposure, and underwriters price on the controls we've spent this conversation describing. If your procurement requires named coverage amounts as a condition, that's a contract-stage conversation we're prepared for, and frankly your requirement helps us scope the policy correctly.
What substitutes for a track record at our stage is inspectable engineering rather than survivable history: the CI-enforced control gates, the tamper-evident audit trail, the supply-chain register with honest statuses, and the third-party attack surface running continuously (CodeQL, ZAP, gitleaks) — all of which you can verify directly rather than take on faith. Additionally, much of the operational risk sits with providers who do have deep incident track records and insurance: AWS, Vercel, Clerk, Stripe have collectively weathered thousands of incidents, and we inherit both their hardening and their contractual liability frameworks.
And the risk-transfer picture you actually care about: our terms cap our liability (fees paid, trailing twelve months — standard SaaS), which means your residual risk management shouldn't assume our balance sheet absorbs a catastrophe; it should assume our controls reduce likelihood, our DPA obligations guarantee notification and cooperation, and your own cyber programme covers the tail. That's the honest allocation, and I'd rather state it plainly than let an insurance line-item imply coverage that contract language would cap anyway.
Grounded in: SOC 2 TSC CC3.2 (risk mitigation incl. insurance); NIST CSF 2.0 GV.RM (risk strategy); ISO 27001 A.5.7 (threat intelligence context).
The natural next questions
Related governed answers
- Every credible company can name its own top risks. What are yours — the ones that would actually hurt us as your customer?
- You deploy one codebase to all tenants. A single poisoned dependency is a breach of every customer simultaneously. How do you defend the software supply chain?
- Forget external hackers — your biggest threat is your own people. What stops one of your engineers, or frankly you yourself, from reading my board's data?
Want this answered live, on your data?