The security gaps behind a cyber quote, each with its rule, on a 90-day clock.
Cyber Insurance Subjectivity Tracker turns an applicant's list of security controls into the gaps behind a cyber insurance quote, each with the rule it comes from, and a 90-day schedule with checkpoints at day 30, 60 and 90 showing which gaps the applicant reports closed, and when.
- Tick or paste the controls you have. No passwords, no scans, no access to your systems, and nothing leaves your browser until you save.
- Each gap shows the requirement it comes from and the edition we hold. Closures are what the applicant reports, dated; nothing here verifies them.
- Pick where the business is: Australia, the United States or the United Kingdom. Only that jurisdiction's rules appear.
Subjectivities are the conditions a cyber quote or policy is subject to, such as switching on multi-factor authentication by a date. Here each one is a line on a schedule, with the requirement behind it.
Free: one applicant on screen, any jurisdiction. Solo, USD 99 a month (AUD 149 in Australia): saved clocks, the applicant link, the checkpoint report. Team, USD 329 (AUD 499): unlimited clocks, several users, the change log. Pricing.
| Condition, and the rule behind it | day 30 Mon 31 Aug | day 60 Wed 30 Sep | day 90 Fri 30 Oct |
|---|---|---|---|
Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication at the startnot in place reported closed on 19 Aug by the applicant
| reported closed 19 Aug | ||
Restoring from backup is tested as part of a disaster recovery exercise at the startnot in place reported closed on 12 Sep by the applicant, after the day 30 checkpoint (Mon 31 Aug)
| reported closed 12 Sep | ||
Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed at the startpartly in place open at the day 60 checkpoint (Wed 30 Sep)
| open | ||
Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response) at the startnot sure a question due at day 90 (Fri 30 Oct) No requirement in the core list for Australia covers this; it is on the schedule as a condition proposal forms ask about. | due Fri 30 Oct |
SPECIMEN: 14 gaps, 6 reported closed by day 30, 4 by day 60, 4 still open at day 66 of 90.

Pick the jurisdiction
Australia (the Essential Eight at the target level the underwriter picks, privacy lines when the Privacy Act applies), the United States (CIS Controls and NIST CSF 2.0, with the sector rules ticked) or the United Kingdom (Cyber Essentials).
Mark the controls
In place, partly, not in place or not sure, one by one or pasted from a proposal form or an assessment. Each gap shows the rule behind it and the evidence an assessor asks for.
Run the 90 days
Day 0 is the date the underwriter or broker sets. Each gap gets a checkpoint at day 30, 60 or 90, and the schedule shows what the applicant reports closed by each one, and what is still open.
Start a schedule
AThe control list
BPaste a list
One control per row: control | status | closed on | note | checkpoint. A row may name the clause (ISM-1504, CIS 6.3, PR.AA-03, CE-SC.6, 314.4(c)(5), 164.312(d), 500.12, PCI 8.4.2) or the control in the proposal form's words. Status is in place, partly, not in place or not sure. Rows from a spreadsheet paste as they are; fill in the template CSV and paste it back.
Nothing is sent anywhere until you choose to save.
Free: the gap list and the 90-day schedule for one applicant, any jurisdiction, and print. Solo: saved clocks for up to 25 applicants, the private applicant link, the checkpoint report as CSV and print, your own conditions, checkpoints you set. Team: unlimited clocks, several users, the change log on every clock. Pricing.
A schedule the underwriter, the broker and the business all read
A cyber quote often comes with conditions: switch on multi-factor authentication, keep an offline backup, patch internet-facing systems within the times the rule sets. Cyber Insurance Subjectivity Tracker writes each condition as a line on one schedule, with the requirement it rests on in the applicant's jurisdiction, and gives it a checkpoint at day 30, 60 or 90 from the date the underwriter or broker sets. The applicant reports each fix closed through a private link, with a date and a note; the schedule shows what was reported closed by each checkpoint, what was reported after it, and what is still open. It never says a business is covered, never rates it, and never checks a closure: a closure is what the applicant reports.
Scope. The default checkpoints are a schedule the underwriter or broker sets, not a deadline in any standard; where a requirement carries its own timeframe (patching within two weeks or 48 hours of release, Cyber Essentials' 14 days, the FTC Safeguards Rule's 30 days after discovery, 23 NYCRR 500.17's 72 hours, the Notifiable Data Breaches scheme's 30-day assessment) the line shows those words beside the checkpoint. Rules that bind public companies (the SEC cyber disclosure rule, SOX 404) are not in this product. Read how the schedule works, what subjectivities are, the 38 controls, the 11 rule sets and the guides for Australia, the United States and the United Kingdom.