This translation has not been editorially reviewed yet. The German version is authoritative. German version →
ContentsCyber insurance
Cyber insurance: the prerequisites
The cyber-insurance seal builds on two sources. The operator declares their protective measures, the measurement documents the technical state of the website. A person checks the details before the seal is created.
What is measured
These audit areas carry the topic. Each leads to its checks with explanation, measurement path and remedy.
- CurrencyDetected CMS, extensions and libraries past their maintenance end, determined passively, without credentials.5 articles
- Indexing & technical setupWhether search engines may fetch the page, can find it and assign it unambiguously.25 articles
- Data protection & cookiesWhat loads before any consent, whether pressing “reject” actually stops it, cookies set before a choice was made, remotely loaded web fonts, and the presence of a privacy notice.15 articles
- Loading performanceLoading behaviour, responsiveness, layout stability, measured rather than estimated.8 articles
What you declare
The operator declares organisational protective measures; software currency, technology, data protection and performance of the website are measured. These details later appear in the public proof:
- Regular backups (required): At least weekly, automated.
- Backups separated from the production system
- Restore tested in the last 12 months
- Two-factor login for administrators (required)
- Updates of CMS and libraries (required): Automatic, Checked monthly, Irregular
- Staff trained on phishing
How the seal comes about
- Cyber insurance is an add-on to the human audit. It is ordered with the audit, the details are requested afterwards and checked separately.
- The proof names the declared measures and the measured state with date. Internal details such as the emergency contact stay internal.
- The price depends on the scope of the website; the quote is in the order.
What the seal tells an insurer
It documents, as of a date, that the website is maintained and that the operator has declared the organisational basics: backups, access protection, updates, training. The procedure reads the website like a visitor; security scans, vulnerability and load tests belong to other procedures. The order log records every run and every judgement so that the activity proof holds over time.
Ongoing monitoring as a prerequisite
- The cyber certificate requires active monitoring with the Cyber category for the domain. Without it, it is not issued.
- Monitoring measures the Cyber category daily, the other categories monthly; each run produces a state with scores per audit area and the change from the previous month.
- The monthly price is reserved once per month on the first run; further runs that month cost nothing. If credit is missing, the next day tries again.
- Measured are software currency (libraries past end of maintenance, visible versions, server signature), security headers, data protection and loading behaviour, each run with evidence in the case folder.
Read-only access: probed, never used
- Access to FTP, SFTP, SSH, PostgreSQL and MySQL is stored by the organisation in its vault; host and port are part of the entry's purpose.
- Every cyber run probes all stored accesses: open the connection, read the greeting, disconnect. The service never logs in. Unreachable accesses appear as a finding in the state.
- The login itself is done by the authorised auditing person, with purpose and deadline in the log.
The organisation's vault
- Every secret has a kind: audit (read only by the measurement core, for protected areas behind login or basic auth), external system (read only by the service) or safekeeping (plain text for owners and auditors released per entry).
- Every access is recorded with its purpose in the vault log and in the organisation's activity log, without the value. Audit and external-system secrets are never shown in plain text, not even to the owner.
- Before each run the measurement core reads the access to the protected area from the vault of the order or the organisation; if the login fails, it measures without it and says so in the run.
Photo: Alan Levine, CC0
Beratung und Angebot
Deckung, Versicherbarkeit, Marktvergleich und Angebot über unseren Versicherungspartner Cyberverantwortung. Angemeldete Kunden bekommen das Formular unter „Cyberversicherung“ im Zahnrad ihrer Organisation mit ihren Stammdaten vorbelegt.
Das Formular stammt von Cyberverantwortung. Was Sie dort eingeben, geht direkt an Cyberverantwortung; euid.com sieht es nicht. Vorbelegt sind nur Angaben, die Sie dem Dienst schon genannt haben — Sie können jede Angabe im Formular ändern.





