CISI Assessment | Cybantage — Score Your Cyber Insurance Claim Payability
Cyber Insurance Survivability Index

Would your cyber insurance claim
actually be paid?

The CISI puts a structured, evidence-based score on the one question boards and CFOs haven't been able to answer — until now. 34 questions. 10 domains. Two dimensions of denial risk. Free assessment. Immediate results.

Free assessment
Immediate results
Instant PDF report
▶ Start the Assessment — Free

34 questions · 10 domains · Claimant-side + insurer-side · Immediate results

Sample CISI Report Output
Your score will reflect your actual control environment
142 /215
At Risk — Partial Payment Likely
Paid
42%
Partial
38%
Denied
20%
Domain 10 — Insurer-Side Flags
D10-NS Nation-state exclusion unreviewed
D10-TP Third-party coverage unconfirmed
D10-SY Systemic event — reviewed ✓
3:1
Claims closed without payment vs. paid
NAIC 2024 · 28,555 unpaid vs. 9,941 paid
31.3%
Of breached healthcare orgs ceased to exist
Cybantage Research · 1,478 orgs · 2023–2026
20–30%
Of denials from insurer-side exclusions — not security gaps
CISI Discussion Paper · Cybantage 2026
3–5×
Uninsured cost exceeds insured payout even when claims pay
NetDiligence 2025 · IBM Cost of Breach 2024

10 domains. 34 questions.
Both dimensions of claim denial.

Domain point values reflect forensic significance — the frequency with which each domain appears as a driver of claim denial in post-breach investigations. Domains 1–9 measure claimant-side control failures. Domain 10 measures insurer-side policy exclusion risk independently.

D1
30
Identity & Access Control
CRITICAL
D2
25
Endpoint Protection & Detection
MEDIUM
D3
25
Backup & Recovery Integrity
HIGH
D4
20
Logging, Monitoring & Evidence
HIGH
D5
30
Control Reality vs. Documentation
CRITICAL
D6
25
Incident Response Capability
MEDIUM
D7
15
Third-Party & Supply Chain Risk
MEDIUM
D8
20
Policy Alignment & Attestation
HIGH
D9
10
Data Classification & Exposure Scope
HIGH
D10
15
Policy Exclusion & Coverage Gap Risk
CRITICAL

Total: 34 questions · Domain 10 evaluates independently of total score

Domain 10 — The Independent Dimension

The insurer-side risks no security control can fix.

Domain 10 is unique in the CISI framework. These three flags are evaluated independently of your total score. A 210/215 score with a D10-NS flag is a high-risk situation that a strong Domains 1–9 posture cannot address. These risks are resolved only through policy review, legal counsel, endorsements, or supplemental coverage.

D10-NS

Nation-State Exclusion

Lloyd's-mandated state-backed attack exclusions have been required since March 2023. Healthcare, financial services, critical infrastructure, and defense contractors are primary nation-state targets. If your policy contains this exclusion and it has not been reviewed by qualified counsel, coverage for the most likely threat actor class in your sector may be void.

Fires when question 10.1 scores zero. Triggers Stage 2B Privileged Review recommendation regardless of total CISI score.
D10-TP

Third-Party Coverage Gap

Standard policies frequently exclude downstream losses from third-party breaches. EHR clearinghouses, billing processors, cloud platforms, fintech APIs, and payment systems create coverage gaps that are unconfirmed until the claim is filed. The Change Healthcare incident produced $2.3B in losses — much of it from organizations that believed their policy covered supply chain events.

Fires when question 10.2 scores zero. Critical for healthcare and financial services organizations with significant vendor dependencies.
D10-SY

Systemic Event Coverage

The July 2024 CrowdStrike incident generated $400M–$1.5B in insured losses and accelerated insurer exclusion of non-malicious correlated events. Cloud provider failures, software update failures, and widespread infrastructure outages may not be covered under your current policy. Business interruption coverage for events originating outside your organization requires explicit confirmation.

Fires when question 10.3 scores zero. Particularly relevant for manufacturing and financial services organizations dependent on shared infrastructure.

The critical insight: A security team cannot fix a Domain 10 flag. No amount of MFA enforcement, backup isolation, or IR plan testing resolves a nation-state exclusion clause. These gaps are closed through policy review with insurance counsel, endorsements, or supplemental coverage — not through the security program. The CISI surfaces them so organizations can act before a breach occurs, not after a claim is denied.

Four steps from start
to complete picture.

01

Complete the assessment

34 questions across 10 domains. For each question, select the score that best reflects your current operating environment and the evidence type supporting your answer. Approximately 15 minutes.

02

See your live score

Your CISI score updates in real time as you answer each question. Domain breakdown, claim probability projection, and Domain 10 flag status are visible throughout the assessment.

03

Unlock your full report

Enter your organization details to unlock the full report: executive summary, primary denial drivers, domain critique, financial exposure estimate, and priority remediation recommendations.

04

Download your PDF

Download your complete CISI Assessment Report — formatted for executive and board presentation. The paid analysis debrief with a Cybantage advisor is the recommended next step.

What your score means
in claim payment terms.

Score Range What It Means Claim Outcome Status
198–215 Controls validated, evidence defensible, exclusion exposure reviewed. Strong position for renewal negotiation. High probability paid Exemplary
169–197 Strong operational security with validated evidence. More likely to withstand forensic scrutiny. Review exclusion exposure. Likely paid Claim Likely Paid
134–168 Coverage probable but not certain. One or more material gaps. Claim may be reduced or subject to dispute. Partial / dispute At Risk
105–133 Multiple control gaps. Forensic investigation will expose material misalignment. Coverage challenge expected. High dispute risk High Denial Risk
< 105 Critical failures across multiple domains. Policy attestation likely inaccurate. Coverage will be contested. Survivability signal. Likely denied Likely Denied

Note: Domain 10 flags are evaluated independently. A score in any band with active D10 flags requires separate policy review regardless of the claimant-side score.

Know where you stand
before you need to know.

The organizations that survive breaches built their posture before the event — not in response to it. The CISI gives you the scored picture of where you actually stand, 15 minutes from now.

No form required to start
No sales call
Instant results
PDF report included
▶ Start the CISI Assessment — Free