Compliance and cyber insurance

Meet your obligations. Give your insurer an accurate answer. Protect your clients.

Compliance should focus on the obligations and assurance your firm actually needs. Tier 1 starts with the controls that reduce risk, then builds formal evidence or certification when there is a clear reason.

Scroll to explore
02Tier 1

Section 02

What we help with

The scope is matched to your firm, contracts, clients, insurer and risk profile.

Privacy

Identify applicable privacy, confidentiality and contractual duties and put practical controls around information handling.

Cyber insurance readiness

Check that application and renewal answers match the controls that are actually in place and evidenced.

Payment-fraud protection

Set verification, access and response controls around changes to bank details and high-value transfers.

Essential Eight

Assess current implementation, agree a useful target and build evidence without overstating maturity.

ISO 27001

Design and deliver a certification program when a client, contract or strategic objective makes the investment worthwhile.

03Tier 1

Section 03

Assess, prioritise, implement and evidence

Tier 1 reviews the current state, produces a short prioritised plan, works alongside the people who need to implement it and makes sure the evidence is ready when a client, insurer or auditor asks.

Translucent sheets aligned on a dark grid with a single amber marker.
04Tier 1

Section 04

Make each assurance answer defensible

A client questionnaire, insurer renewal or audit can expose the gap between a policy statement and daily operation. Tier 1 connects the answer to current scope, ownership, configuration and evidence.

Trace the requirement

Identify the source, scope and exact obligation before turning a broad question into technical work.

Check operation

Confirm that the control applies to the intended users and systems and that exceptions are known rather than hidden.

Retain useful evidence

Keep approvals, settings, reports, tests and review records that support the answer without collecting material for its own sake.

State the limit

Describe gaps, exclusions and planned work accurately so the firm does not overstate maturity or create avoidable commitments.

05Official guidance
06Questions

Straight answers

Common questions

Which framework should we use?

Start with the obligations, client expectations and risks that actually apply. Essential Eight can provide a useful technical baseline, while ISO 27001 can support broader management and assurance needs. The framework should serve the business case, not become the project by default.

Can Tier 1 complete our cyber insurance application?

Tier 1 can review the security questions, test whether the stated controls are operating and organise supporting evidence. Leadership remains responsible for the application, and coverage questions should be confirmed with the insurer or broker.

Does an assessment guarantee compliance or insurance cover?

No. An assessment provides a point-in-time view against an agreed scope. It does not replace legal or insurance advice, guarantee certification or bind an insurer. Its value is a clearer gap view, defensible evidence and a practical plan.

Can you help implement the findings?

Yes. Tier 1 can coordinate owners and providers, review completed work and maintain the evidence. The scope can also stop after the assessment if your internal team or existing provider will deliver the plan.

A quiet first step

Book a confidential call

Talk directly with Michael about what your firm needs to protect and the practical next step.

Book a confidential call