Cyber Insurance Subjectivity Tracker
For underwriters and brokers, and the business that has to close the gaps

The security gaps behind a cyber quote, each with its rule, on a 90-day clock.

Cyber Insurance Subjectivity Tracker turns an applicant's list of security controls into the gaps behind a cyber insurance quote, each with the rule it comes from, and a 90-day schedule with checkpoints at day 30, 60 and 90 showing which gaps the applicant reports closed, and when.

  1. Tick or paste the controls you have. No passwords, no scans, no access to your systems, and nothing leaves your browser until you save.
  2. Each gap shows the requirement it comes from and the edition we hold. Closures are what the applicant reports, dated; nothing here verifies them.
  3. Pick where the business is: Australia, the United States or the United Kingdom. Only that jurisdiction's rules appear.

Subjectivities are the conditions a cyber quote or policy is subject to, such as switching on multi-factor authentication by a date. Here each one is a line on a schedule, with the requirement behind it.

Start a scheduleOne applicant's gap list and schedule are free. No account.

Free: one applicant on screen, any jurisdiction. Solo, USD 99 a month (AUD 149 in Australia): saved clocks, the applicant link, the checkpoint report. Team, USD 329 (AUD 499): unlimited clocks, several users, the change log. Pricing.

SPECIMEN: four of 14 linesan invented applicant, Australia, Maturity Level One
Condition, and the rule behind itday 30 Mon 31 Augday 60 Wed 30 Sepday 90 Fri 30 Oct

Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication

at the startnot in place reported closed on 19 Aug by the applicant

  • ISM-1504 Essential Eight Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data

    Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1504 in ASD's Essential Eight to ISM mapping (December 2023).

    maturity level required from Maturity Level One

    edition Essential Eight Maturity Model, November 2023 (ISM mapping, December 2023); held text read 2026-09-30

    evidence an assessor asks for Identity provider policy enforcing multi-factor authentication for the organisation's online services holding sensitive data; List of those online services mapped to the policy

    Every Essential Eight clause we hold

  • ISM-1679 Essential Eight Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data

    Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1679 in ASD's Essential Eight to ISM mapping (December 2023).

    maturity level required from Maturity Level One

    edition Essential Eight Maturity Model, November 2023 (ISM mapping, December 2023); held text read 2026-09-30

    evidence an assessor asks for Inventory of third-party online services processing sensitive data with multi-factor authentication status; Screenshots or configuration exports of multi-factor enforcement at each service

    Every Essential Eight clause we hold

  • and 2 more requirements
reported closed 19 Aug

Restoring from backup is tested as part of a disaster recovery exercise

at the startnot in place reported closed on 12 Sep by the applicant, after the day 30 checkpoint (Mon 31 Aug)

  • ISM-1515 Essential Eight Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises

    Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1515 in ASD's Essential Eight to ISM mapping (December 2023).

    maturity level required from Maturity Level One

    edition Essential Eight Maturity Model, November 2023 (ISM mapping, December 2023); held text read 2026-09-30

    evidence an assessor asks for Disaster recovery exercise records with restoration to a common point in time; Test results and issues found

    Every Essential Eight clause we hold

reported closed 12 Sep

Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed

at the startpartly in place open at the day 60 checkpoint (Wed 30 Sep)

  • ISM-1501 Essential Eight Operating systems that are no longer supported by vendors are replaced

    Operating systems that are no longer supported by vendors are replaced. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1501 in ASD's Essential Eight to ISM mapping (December 2023).

    maturity level required from Maturity Level One

    edition Essential Eight Maturity Model, November 2023 (ISM mapping, December 2023); held text read 2026-09-30

    evidence an assessor asks for Operating system version inventory (for example winver output or scanner OS fingerprinting) compared with vendor support lists; Replacement or upgrade records for operating systems that reached end of support

    Every Essential Eight clause we hold

  • ISM-1704 Essential Eight Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed

    Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1704 in ASD's Essential Eight to ISM mapping (December 2023).

    maturity level required from Maturity Level One

    edition Essential Eight Maturity Model, November 2023 (ISM mapping, December 2023); held text read 2026-09-30

    evidence an assessor asks for Software inventory of office suites, browsers and extensions, email clients, PDF software and security products checked against vendor support lifecycles; Evidence that the retired browser plug-in named in the requirement is removed (the removal hotfix or an equivalent record)

    Every Essential Eight clause we hold

  • and 1 more requirement
open

Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)

at the startnot sure a question due at day 90 (Fri 30 Oct)

No requirement in the core list for Australia covers this; it is on the schedule as a condition proposal forms ask about.

due Fri 30 Oct

SPECIMEN: 14 gaps, 6 reported closed by day 30, 4 by day 60, 4 still open at day 66 of 90.

A broker going through a printed page with an older client on a sofa
Every condition on the quote comes with the requirement it rests on and a date it is due, so the broker, the underwriter and the business read the same schedule. The applicant reports each fix through a private link, and every report is kept with the time it was made.
01

Pick the jurisdiction

Australia (the Essential Eight at the target level the underwriter picks, privacy lines when the Privacy Act applies), the United States (CIS Controls and NIST CSF 2.0, with the sector rules ticked) or the United Kingdom (Cyber Essentials).

02

Mark the controls

In place, partly, not in place or not sure, one by one or pasted from a proposal form or an assessment. Each gap shows the rule behind it and the evidence an assessor asks for.

03

Run the 90 days

Day 0 is the date the underwriter or broker sets. Each gap gets a checkpoint at day 30, 60 or 90, and the schedule shows what the applicant reports closed by each one, and what is still open.

Start a schedule

Where is the business?

AThe control list

Notes typed here stay on this page.

BPaste a list

One control per row: control | status | closed on | note | checkpoint. A row may name the clause (ISM-1504, CIS 6.3, PR.AA-03, CE-SC.6, 314.4(c)(5), 164.312(d), 500.12, PCI 8.4.2) or the control in the proposal form's words. Status is in place, partly, not in place or not sure. Rows from a spreadsheet paste as they are; fill in the template CSV and paste it back.

No clause we hold covers these; they carry no citation.

Nothing is sent anywhere until you choose to save.

Free: the gap list and the 90-day schedule for one applicant, any jurisdiction, and print. Solo: saved clocks for up to 25 applicants, the private applicant link, the checkpoint report as CSV and print, your own conditions, checkpoints you set. Team: unlimited clocks, several users, the change log on every clock. Pricing.

A schedule the underwriter, the broker and the business all read

A cyber quote often comes with conditions: switch on multi-factor authentication, keep an offline backup, patch internet-facing systems within the times the rule sets. Cyber Insurance Subjectivity Tracker writes each condition as a line on one schedule, with the requirement it rests on in the applicant's jurisdiction, and gives it a checkpoint at day 30, 60 or 90 from the date the underwriter or broker sets. The applicant reports each fix closed through a private link, with a date and a note; the schedule shows what was reported closed by each checkpoint, what was reported after it, and what is still open. It never says a business is covered, never rates it, and never checks a closure: a closure is what the applicant reports.

Scope. The default checkpoints are a schedule the underwriter or broker sets, not a deadline in any standard; where a requirement carries its own timeframe (patching within two weeks or 48 hours of release, Cyber Essentials' 14 days, the FTC Safeguards Rule's 30 days after discovery, 23 NYCRR 500.17's 72 hours, the Notifiable Data Breaches scheme's 30-day assessment) the line shows those words beside the checkpoint. Rules that bind public companies (the SEC cyber disclosure rule, SOX 404) are not in this product. Read how the schedule works, what subjectivities are, the 38 controls, the 11 rule sets and the guides for Australia, the United States and the United Kingdom.