Security posture is the measurable state of an environment against a security framework you selected, such as CIS. Insurance posture is the measurable state of the same environment against the questions a cyber insurance carrier asks, expressed as the share of application answers backed by evidence from the live environment rather than answered from memory. The scan data overlaps heavily. The question sets and the consequences do not.

A high CIS score does not make a cyber application defensible, and a clean application does not mean the tenant is secure.

How Do the Two Compare?

Security posture Insurance posture
Who sets the questions You, by choosing a framework The carrier, on its application form
Output Findings ranked by risk Answers, each with or without evidence
Cost of being wrong A remediation ticket A representation the carrier relied on
When it is read Continuously At bind, and again after a loss
Definition of done Score improves Every answer has a dated artifact behind it

Where Do They Diverge?

The question is scoped differently. A benchmark asks whether MFA is enabled to a standard. A carrier asks whether MFA is enforced for email, for remote access, and for all privileged accounts. A tenant can pass the benchmark and fail one of those three, usually because a Conditional Access exclusion group survived a migration.

Correct practice can look like a no. A break-glass account excluded from Conditional Access is deliberate and right, but the form has no field for "excluded by design, with compensating monitoring." The defensible answer is qualified, with the compensating control attached.

The consequence is asymmetric. A missed control is a ticket. A wrong application answer is tested at the worst possible moment, which is why a green dashboard is not the finish line, the same argument auditors make about SOC 2 evidence.

What Does Insurance Posture Measure That a CSPM Dashboard Does Not?

Answer coverage. The share of a carrier's questions that are verifiable from the environment, partly verifiable, or attested. That ratio moves independently of your security score.

The date on the evidence. "MFA is enforced" is an opinion. "MFA enforced for all 14 privileged accounts, read from Entra ID on 12 September" is evidence.

Drift between bind and claim. Exclusions get added and admins get created after the application is signed, and no benchmark trendline tells you a specific answer stopped being true.

How Do You Run Both From One Scan?

Take last year's application, label every question verifiable, partly verifiable, or attested, and point each verifiable one at the check that proves it with the artifact dated. Then rescan on a schedule so drift lands in a ticket queue instead of a claim file. Where each answer lives in the tenant is mapped in proving cyber insurance answers.

SecValley scans Microsoft 365, Entra ID, and Azure read-only and reports dated findings, including checks it could not read, which are reported as unanswered and never as passed. Insurance Posture runs on the same scans and maps them to the carrier question set. The public question library is at insuranceposture.com/questions.

Start with the ratio: of the answers on your last application, how many could you prove today with an artifact that carries a date.

Frequently Asked Questions

What is insurance posture?

Insurance posture is the measurable state of an organization's security controls as cyber insurance carriers evaluate them, expressed as the share of carrier application answers backed by verifiable evidence from the live environment rather than answered from memory.

Is insurance posture just security posture with different branding?

No. Security posture measures against a framework you selected and outputs risk-ranked findings. Insurance posture measures against a carrier's question set and outputs answers with evidence attached. The scan data overlaps; the questions and the consequences do not.

Can a company with a high CIS score have poor insurance posture?

Routinely. Benchmark controls and application questions are scoped differently, so a tenant can satisfy a control while failing the more specific carrier question about where enforcement applies. The reverse also happens.

How often should cyber insurance application answers be rechecked?

Before every renewal at minimum, and quarterly in practice. Conditional Access exclusions, new privileged accounts, and changed backup policies all move between renewals, and an answer that lapses after submission is the discrepancy a post-incident review looks for.