Skip to main content
Granite PeakTechnology Services

Compliance & Insurance

Answer the hard security questions with evidence, not guesses.

Cyber-insurance renewals and client requirements increasingly demand proof of basic controls. We build the baseline and the documentation so you can answer honestly.

You may need this if

Any of these sound familiar

A renewal questionnaire you are not sure how to answerA new client or grant requiring proof of controlsA recent premium increase or coverage denialRequirements you have never had documented

What you get

Readiness you can actually show

Honest questionnaire answers

Say yes to MFA, backups and endpoint protection because they are actually in place — not because you hope they are.

A defensible baseline

Controls mapped to the questions insurers and auditors keep asking, with evidence you can point to.

Written documentation

Owners, dates and decisions recorded — the paper trail that turns "we think so" into "here it is".

Coordination, not confusion

We work alongside your compliance advisor or broker instead of pretending to replace them.

The baseline

The controls insurers keep asking about

Most questionnaires map to the same handful of layers. Here is what a defensible baseline covers.

VerifiedIn placeNeeds work
  • Multi-factor authentication on every account, tightened Microsoft 365 sign-in policies, and phishing-resistant keys for the roles that would hurt most if compromised.

Example statuses shown for illustration — your baseline starts with an honest assessment of where you are today.

Sample deliverable

Cyber-insurance readiness summary

A one-page snapshot mapping your current controls to common questionnaire items, with owners and target dates for anything still open.

  • Controls mapped to questionnaire
  • Gaps with owner & due date
  • Evidence references
  • Next review date

FAQ

Common questions

  • Can you guarantee we pass an audit or get coverage?

    No one honestly can. We build and document a baseline that supports common questionnaires and requirements, which puts you in a far stronger position — but the insurer or auditor makes the final call.

  • Do you replace our compliance advisor?

    No. For formal frameworks like HIPAA or CMMC we coordinate with your compliance professional and handle the technical controls and documentation on our side.

  • What do we actually walk away with?

    A documented baseline, a prioritized list of any gaps with owners and target dates, and clear answers you can give to insurers and clients.

Not sure how you would answer that questionnaire?

Bring it to a fit call. We will walk through it honestly and tell you what a defensible baseline would take.

What happens next

  • A short, no-pressure fit call to understand your environment
  • A plain-English summary of what we would look at first
  • A clear recommendation — even if that is not Granite Peak