CISI Assessment | Cybantage — Score Your Cyber Insurance Claim Payability
Cyber Insurance Survivability Index

Would your cyber insurance claim
actually be paid?

The CISI puts a structured, evidence-based score on the one question boards and CFOs haven't been able to answer — until now. 34 questions. 10 domains. Two dimensions of denial risk. Free assessment. Immediate results.

Free assessment
Immediate results
Instant PDF report
No sales call required
▶ Start the Assessment — Free

34 questions · 10 domains · Claimant-side + insurer-side · Immediate results

Sample CISI Report Output
Your score will reflect your actual control environment
142 /215
At Risk — Partial Payment Likely
Paid
42%
Partial
38%
Denied
20%
Domain 10 — Insurer-Side Flags
D10-NS Nation-state exclusion unreviewed
D10-TP Third-party coverage unconfirmed
D10-SY Systemic event — reviewed ✓
3:1
Claims closed without payment vs. paid
NAIC 2024 · 28,555 unpaid vs. 9,941 paid
31.3%
Of breached healthcare orgs ceased to exist
Cybantage Research · 1,478 orgs · 2023–2026
20–30%
Of denials from insurer-side exclusions — not security gaps
CISI Discussion Paper · Cybantage 2026
3–5×
Uninsured cost exceeds insured payout even when claims pay
NetDiligence 2025 · IBM Cost of Breach 2025

10 domains. 34 questions.
Both dimensions of claim denial.

Domain values reflect forensic significance — the frequency with which each domain appears as a driver of claim denial in post-breach investigations. Domains 1–9 measure claimant-side control failures. Domain 10 measures insurer-side policy exclusion risk independently.

D1
30
Identity & Access Control
CRITICAL
D2
25
Endpoint Protection & Detection
MEDIUM
D3
25
Backup & Recovery Integrity
HIGH
D4
20
Logging, Monitoring & Evidence
HIGH
D5
30
Control Reality vs. Documentation
CRITICAL
D6
25
Incident Response Capability
MEDIUM
D7
15
Third-Party & Supply Chain Risk
MEDIUM
D8
20
Policy Alignment & Attestation
HIGH
D9
10
Data Classification & Exposure Scope
HIGH
D10
15
Policy Exclusion & Coverage Gap Risk
CRITICAL

The insurer-side risk no security program can fix.
Only a policy review does.

Domain 10 evaluates three specific policy exclusion risks that exist independent of security posture. A Domain 10 flag fires regardless of total score and triggers an immediate Stage 2B recommendation.

D10-NS

Nation-State Exclusion

Lloyd's-mandated state-backed attack exclusions have been required since March 2023. Healthcare, financial services, critical infrastructure, and defense contractors are primary nation-state targets. If your policy contains this exclusion and it has not been reviewed by qualified counsel, coverage for the most likely threat actor class in your sector may be void.

Fires when question 10.1 scores zero. Triggers Stage 2B Privileged Review recommendation regardless of total CISI score.
D10-TP

Third-Party Coverage Gap

Standard policies frequently exclude downstream losses from third-party breaches. EHR clearinghouses, billing processors, cloud platforms, fintech APIs, and payment systems create coverage gaps that are unconfirmed until the claim is filed. The Change Healthcare incident produced $3.09B in losses — much of it from organizations that believed their policy covered supply chain events.

Fires when question 10.2 scores zero. Critical for healthcare and financial services organizations with significant vendor dependencies.
D10-SY

Systemic Event Coverage

The July 2024 CrowdStrike incident generated $400M–$1.5B in insured losses and accelerated insurer exclusion of non-malicious correlated events. Cloud provider failures, software update failures, and widespread infrastructure outages may not be covered under your current policy.

Fires when question 10.3 scores zero. Particularly relevant for manufacturing and financial services organizations dependent on shared infrastructure.

The critical insight: A security team cannot fix a Domain 10 flag. No amount of MFA enforcement, backup isolation, or IR plan testing resolves a nation-state exclusion clause. These gaps are closed through policy review with insurance counsel — not through the security program. The CISI surfaces them so organizations can act before a breach occurs, not after a claim is denied.

Four steps from start
to complete picture.

01

Complete the assessment

34 questions across 10 domains. For each question, select the score that best reflects your current operating environment. Approximately 15 minutes.

02

See your live score

Your CISI score updates in real time as you answer each question. Domain breakdown, claim probability projection, and Domain 10 flag status are visible throughout.

03

Unlock your full report

Enter your organization details to unlock the full report: executive summary, primary denial drivers, domain critique, financial exposure estimate, and priority recommendations.

04

Download your PDF

Download your complete CISI Assessment Report — formatted for executive and board presentation. The optional analysis debrief with a Cybantage advisor is the recommended next step.

What your score means
in claim payment terms.

Score RangeWhat It MeansClaim OutcomeStatus
198–215Controls validated, evidence defensible, exclusion exposure reviewed. Strong position for renewal negotiation.High probability paidExemplary
169–197Strong operational security with validated evidence. More likely to withstand forensic scrutiny. Review exclusion exposure.Likely paidClaim Likely Paid
134–168Coverage probable but not certain. One or more material gaps. Claim may be reduced or subject to dispute.Partial / disputeAt Risk
105–133Multiple control gaps. Forensic investigation will expose material misalignment. Coverage challenge expected.High dispute riskHigh Denial Risk
< 105Critical failures across multiple domains. Policy attestation likely inaccurate. Coverage will be contested.Likely deniedLikely Denied

Domain 10 flags are evaluated independently. A score in any band with active D10 flags requires separate policy review regardless of the claimant-side score.

Know where you stand
before you need to know.

The organizations that survive breaches built their posture before the event — not in response to it. The CISI gives you the scored picture of where you actually stand, 15 minutes from now.

No form required to start
No sales call
Instant results
PDF report included
▶ Start the CISI Assessment — Free