Kenzer scores a whole book of policyholders on one consistent, externally-measured methodology — from continuous passive reconnaissance, not self-reported applications.
For underwriting, renewal pricing, and continuous portfolio monitoring between policy periods.
A cyber insurance application captures a snapshot at the moment of signing — self-reported, unverified, and immediately out of date.
Kenzer replaces or augments that snapshot with a live, continuously-updated external risk grade, applied identically across every applicant and every renewal.
Sample grades from Kenzer's own live instance — the same 13-tier scale applied to every organization in the portfolio, so risk is comparable across applicants.
| Policyholder | Grade | Risk score | Open findings |
|---|---|---|---|
| Applicant A | D+ | 68.0 | 551 |
| Applicant B | C- | 53.1 | 57 |
| Applicant C | A+ | 2.0 | 1 |
13-tier O to F score, computed the same way for every applicant — consistent, explainable, reproducible.
Continuous rescanning between policy periods surfaces posture changes before renewal — not relying on a fresh application.
See aggregate exposure, worsening-trend counts, and non-compliant policyholder counts across the entire book, at a glance.
Findings weighted by real exploit likelihood (EPSS, VEDAS, CISA KEV), not raw CVSS.
Closer to actual claim likelihood.
Fourth-party breach cascade flags every policyholder exposed to a common shared provider.
Useful for spotting concentration risk.
Share a scorecard link with an applicant during underwriting, or grant remediation access post-bind.
See how remediation access works.
One-click report per applicant, or the whole book at once, for a file that stands on its own.
Plus CSV export for whatever your own actuarial tooling expects.
Most carriers use it alongside the application — as objective, verifiable ground truth for the external-facing risk portion, complementing internal-control questions a scan can't see.
Yes — the underlying findings driving the grade are visible via a scorecard, so a decision isn't a black box.
Yes — peer and industry-tier benchmarking is built in.
The fourth-party breach cascade flags any policyholder with a dependency on a provider you log an incident against.
Useful for assessing systemic exposure across the book.
One consistent, externally-measured grade — applied across the whole book.