Roux Cyber experts reviewing a cyber-risk dashboard

ROUX CYBER · AFRICA & MIDDLE EAST

CYBER RISK ASSESSMENT

ENGINEERING RISK SURVEY · CLAIMS ADJUSTER

ASSESS BEFORE INCEPTION · DEFEND AFTER LOSS

Two services. One objective: make cyber risk intelligible, insurable and defensible.

Before inception or renewal, Roux Cyber provides a documented risk view at a stated reference date and a dashboard insurers and reinsurers can use to structure cyber insurance and reinsurance contracts.

After a loss, Roux Cyber acts as Cyber Claims Adjuster acting on behalf of the insured to document, quantify and defend the cyber claim through settlement.

POSITIONING

Engineering Risk Survey applied to cyber risk.

Roux Cyber applies Engineering Risk Survey discipline to cyber: defined scope, reference date, evidence gathering, exposure analysis, loss scenarios, control assessment and prioritised recommendations.

The result is not a security declaration. It is an independent insurance-oriented view of the observed position, potential financial consequences and residual risk presented to the market.

Audience
Insured organisationsBoardsCIOs & CISOsRisk ManagersInsurance ManagersBrokersInsurersReinsurers

TWO EXCLUSIVE SERVICES

Before inception. After loss.

01 · INCEPTION · RENEWAL

Cyber Risk Assessment / Cyber Engineering Risk Survey

Establish the cyber-risk profile and quality of protection at a stated date to inform insurability, capacity, limits, deductibles, sublimits, waiting periods and coverage conditions.

SCOPE

  • map critical assets, data, processes and IT/OT dependencies
  • review governance, identity, segmentation, backups, detection, response and third parties
  • develop ransomware, outage, data breach, fraud and supplier scenarios
  • quantify durations and financial impacts from available data
  • assess control effectiveness and residual risk
  • prioritise improvements relevant to risk and insurance

DELIVERABLES

  • Cyber Engineering Risk Survey Report
  • Executive Underwriting Dashboard
  • Cyber Loss Scenario Register
  • Risk Improvement Plan
  • Insurance & Reinsurance Data Pack
02 · AFTER LOSS

Cyber Claims Adjuster acting on behalf of the insured

Support the insured from notification and evidence preservation through quantification, presentation and advocacy of the cyber claim.

SCOPE

  • establish claim governance and chronology
  • coordinate appointed technical and financial specialists
  • coordinate specialist digital investigation: preservation of digital evidence, trace analysis and incident reconstruction
  • document facts, causes, emergency measures and response costs
  • quantify Incident Response, recovery, extortion, Business Interruption, increased costs and liabilities under the policy
  • prepare interim payments and defend the Statement of Claim through settlement

DELIVERABLES

  • Cyber Claim Strategy Memo
  • Evidence & Causation Matrix
  • Cyber Loss Quantification
  • Interim Payment Requests
  • Statement of Claim
  • Settlement & Closure Report

Roux Cyber operates no other standalone business line.

UNDERWRITING VIEW

A point-in-time dashboard for insurance and reinsurance.

The dashboard consolidates evidenced facts, gaps, scenarios and uncertainties that influence the structure of the transferred risk.

01

Scope & criticality

Entities, revenue, data, assets, critical processes, IT/OT, cloud and suppliers.

02

Evidenced controls

Documented coverage and effectiveness of essential safeguards, beyond declarations.

03

Loss scenarios

Propagation, interruption, detection, containment, recovery and third-party consequences.

04

Quantification

Orders of magnitude for response costs, increased costs, BI and potential liabilities.

05

Residual risk

Material weaknesses, concentrations, single points of failure and uncertainty.

06

Policy view

Technical evidence relevant to limits, deductibles, sublimits, waiting periods, conditions and reinsurance.

METHOD

One evidence chain across both services.

  1. 01

    Scope

    Fix the mandate, entities, systems, covers, reference date and expected decisions.

  2. 02

    Collect

    Structure the Data Room, interviews and technical, financial and contractual evidence.

  3. 03

    Verify

    Distinguish evidenced, partially evidenced, declared and unestablished controls.

  4. 04

    Scenario

    Connect event, propagation, interruption, recovery and financial consequences.

  5. 05

    Quantify

    Document assumptions, duration, costs, losses, liabilities and confidence levels.

  6. 06

    Report

    Deliver the underwriting dashboard or claim file required by the mandate.

STRICT SCOPE

What Roux Cyber does not sell as a standalone service.

Roux Cyber may review these works or coordinate authorised specialists where required. Within Cyber Claims Adjusting, specialist digital investigation supports fact and causation analysis; it is not a third standalone business line.

  • Penetration testing and vulnerability exploitation
  • SOC, MDR or operational monitoring
  • IT solution integration and deployment
  • ISO certification or accreditation audit
  • Legal advice and litigation representation
  • Digital forensics outside an authorised Cyber Claims Adjuster mandate

Underwriting, pricing, capacity, coverage and settlement decisions remain with insurers, reinsurers and authorised parties.

FREQUENTLY ASKED QUESTIONS

Understand the mandate before acting.

Is the Cyber Risk Assessment a pentest?

No. It is an insurance-focused Engineering Risk Survey. Technical test results may be reviewed as evidence, but pentesting is not a Roux Cyber standalone service.

What is the insurer and reinsurer dashboard for?

It provides a dated view of exposures, controls, scenarios, financial impacts and residual risk to support cyber insurance and reinsurance placement or renewal.

Does Roux Cyber decide coverage terms?

No. Roux Cyber provides technical and financial analysis. Insurers and reinsurers decide capacity, price, coverage and conditions.

Whom does Roux Cyber represent after a loss?

Under this positioning, Roux Cyber acts as Cyber Claims Adjuster acting on behalf of the insured, within the agreed mandate.

Can the engagement continue through settlement?

Yes. It may cover notification, evidence, quantification, interim payments, technical negotiation and settlement tracking. Payment authority remains with the authorised party.

Does Roux Cyber replace forensic experts or lawyers?

No. It coordinates and uses their findings within the Risk Assessment or claim. Forensics and legal opinions remain with authorised specialists.

ROUX CYBER

Measure the risk before transfer. Defend the loss after the event.

Share your inception, renewal or cyber-loss objective. We will define the mandate, reference date, evidence and appropriate deliverable.

Speak with Roux Cyber