RecommendationHigh riskComparison recommended

AI Cyber Liability Underwriting Assessment Playbook

A specialty lines underwriter has received a cyber liability application from a $200M revenue healthcare company. The company processes PHI for 480,000 patients. Their security questionnaire indicates no MFA on remote access, no endpoint detection, and their last penetration test was 3 years ago.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: A specialty lines underwriter has received a cyber liability application from a $200M revenue healthcare company.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Cyber Liability Underwriting Assessment".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • Cyber liability application and security questionnaire
  • Loss run (3 years, prior carrier)
  • Company revenue, employee count, and data volume
  • Industry cyber loss benchmarks for healthcare companies with similar revenue
  • Current reinsurance treaty terms and cyber aggregation limit

Attachments: Spreadsheets (Spreadsheets)

The Prompt

You are a cyber liability underwriter evaluating a healthcare company submission with significant security gaps. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Assess the security posture against the 5 controls that most consistently reduce cyber loss frequency: MFA, EDR, backups, patch management, incident response plan.
2. Estimate the probability of a material cyber event in the next policy year given the security gaps identified.
3. Calculate the indicated premium at the current security posture vs. the premium if MFA and EDR were implemented.
4. Identify the underwriting conditions that must be met before binding: which security gaps are non-negotiable vs. acceptable with a warranty or endorsement.
5. Tell me whether to write this risk, decline, or write with conditions—and what the specific conditions are with compliance deadline.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Security posture assessment against 5 key controls
  • Material event probability estimate
  • Premium at current posture vs. improved posture
  • Non-negotiable vs. conditionally acceptable gap list
  • Write/decline/condition recommendation with specific conditions

Review before you act

  • Validate this output against source files before relying on it: Assess the security posture against the 5 controls that most consistently reduce cyber loss frequency: MFA, EDR, backups, patch management, incident response plan.
  • Validate this output against source files before relying on it: Estimate the probability of a material cyber event in the next policy year given the security gaps identified.
  • Validate this output against source files before relying on it: Calculate the indicated premium at the current security posture vs. the premium if MFA and EDR were implemented.
  • Validate this output against source files before relying on it: Identify the underwriting conditions that must be met before binding: which security gaps are non-negotiable vs. acceptable with a warranty or endorsement.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Cyber Liability Underwriting Assessment, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface security posture assessment against 5 key controls; material event probability estimate; premium at current posture vs. improved posture; non-negotiable vs. conditionally acceptable gap list. Those are comparison artifacts — they only exist if more than one model runs. Models split on tail scenarios, aggregation, and whether a hazard is excluded. Divergence is a referral to a specialist underwriter, not a silent average of three prices.

Insurance UnderwritingSpecialty LiabilityRecommendationHighSpreadsheets

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.