CYB-32 · Cyber security
Cyber-insurance applications may ask the applicant to declare whether controls such as MFA, backups and incident response are implemented. Those declarations should be checked against current evidence before submission. A Provantis readiness assessment can organise that evidence but does not determine coverage or guarantee claim acceptance.
Trigger
No cyber insurance in place; cyber insurance application declarations not verified against actual controls; significant gap between declared and actual MFA, backup, or IRP status
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Obtain cyber insurance if not in place. Before renewal, conduct an Provantis cyber audit to verify all declared controls match actual implementation. Address any gaps before submission. Retain the Provantis audit report as evidence of controls at the time of declaration.
Evidence required