The Technology Risk
Intelligence Layer.
Barbon continuously measures cyber and AI risk - providing insurers with the real-time intelligence needed to underwrite modern technology with confidence.
Built for insurers that need to underwrite technology risk with measurable confidence.
Cyber Risk Intelligence
Continuous risk intelligence.
Across the entire policy lifecycle.
Barbon enables insurers and brokers to confidently issue and manage cyber insurance through continuous technical assessment - replacing the annual questionnaire with ongoing, measurable intelligence.
Cyber Insurance Risk Assessments
Independent technical assessments that provide insurers with objective risk intelligence ahead of policy inception and renewal.
Underwriting Intelligence
Structured risk reports built for underwriting decisions - not compliance reports. Actionable, measurable, and continuously updated.
Continuous Cyber Risk Monitoring
Ongoing surveillance across an organization's entire technology environment throughout the policy lifecycle - not just at renewal.
Cyber Risk Scoring
A proprietary scoring model that quantifies cyber risk into a single, explainable metric that insurers can act on with confidence.
Threat Intelligence
Real-time threat feeds correlated against each insured's specific environment - surfacing exposure before it becomes a claim.
Executive Dashboards
Clear, executive-friendly reporting translating technical risk signals into the language of insurance underwriting and loss prevention.
Security Validation
Verification that existing security controls are correctly implemented, functioning as intended, and reducing actual risk.
Vendor Assurance
Independent validation that cybersecurity vendors are delivering meaningful risk reduction - not just meeting contractual requirements.
Attack Surface Monitoring
Continuous discovery and monitoring of internet-facing assets, identifying exposed infrastructure before threat actors do.
Cloud Security Validation
Assessment of cloud environment configurations across AWS, Azure, and Google Cloud - identifying misconfigurations and policy drift.
Identity Risk Monitoring
Continuous assessment of identity provider health, privileged access, MFA adoption, and credential compromise indicators.
Third-Party Risk Reviews
Evaluation of supply chain and vendor exposure - assessing how third-party risk propagates into the insured's environment.
Security Governance Reviews
Assessment of security programme maturity, policy frameworks, awareness culture, and board-level accountability.
Compliance Validation
Independent verification of regulatory and standards compliance - providing insurers with evidence beyond self-attestation.
Cyber Risk Trend Analysis
Longitudinal tracking of an organization's cyber posture over time - identifying whether risk is improving, stable, or deteriorating.
Our Underwriting Approach
Beyond the questionnaire.
Into the infrastructure.
Rather than asking whether a client has antivirus software, Barbon answers the questions that actually determine underwriting outcomes. How likely is this organization to experience a cyber incident over the next twelve months? Is their posture improving or deteriorating? Should premiums be adjusted?
Risk Intelligence Pipeline
- 01
Signal Collection
Continuous data ingestion from cloud, identity, email, endpoint, and threat intelligence sources
- 02
Environment Analysis
Full mapping of the insured's technology footprint - on-premise, cloud, and SaaS environments
- 03
Threat Correlation
Active threats correlated against the specific organization's exposed attack surface and technology stack
- 04
Posture Scoring
Proprietary risk model converts technical findings into an explainable Cyber Risk Score (0–100)
- 05
Vendor Assurance
Independent validation that existing security vendors are reducing risk - not just deployed on paper
- 06
Underwriting Report
Structured intelligence report delivered in the language of underwriting - with recommended actions
- 07
Continuous Monitoring
Ongoing surveillance flags posture changes, new threats, and material risk shifts throughout the policy term
Risk Intelligence Platform
Built for the underwriters
who decide.
Every signal from every corner of an organization's technology environment - transformed into insurance intelligence. Risk scores, posture trends, and threat indicators in one structured view.
Portfolio Risk Score
74 / 100
Monitored Organizations
147
Posture Improving
70.3%
Active Threat Signals
1,794
Organization Risk Register
147 organizations · Showing 7
| Org ID | Organization | Risk Score | Status | Actions |
|---|---|---|---|---|
| ORG-2024-0291 | Acacia Holdings Ltd | 82 / 100 | Stable | |
| ORG-2024-0287 | Meridian Corp | 54 / 100 | Elevated | |
| ORG-2024-0281 | Rho Transport Group | 71 / 100 | Stable | |
| ORG-2024-0276 | Port Logistics Ltd | 48 / 100 | Critical | |
| ORG-2024-0264 | Greenfield Holdings | 89 / 100 | Stable | |
| ORG-2024-0258 | SkyTravel PLC | 67 / 100 | Stable | |
| ORG-2024-0251 | Helix Pharma | 61 / 100 | Elevated |
Showing 1–7 of 147
Signal Coverage
Every signal.
Every environment. Continuously.
Our platform continuously collects and analyzes signals from across an organization's entire technology environment - transforming raw technical data into structured underwriting intelligence.
Microsoft 365 & Azure
Continuous monitoring of Microsoft cloud environments - identity posture, conditional access, email security, and misconfiguration detection.
AWS Cloud Environments
Assessment of AWS configurations, IAM policies, public S3 buckets, security groups, and workload exposure across all regions.
Identity Providers
Continuous review of Okta, Azure AD, and Google Workspace - MFA adoption rates, privileged access, dormant accounts, and sign-in anomalies.
Endpoint Protection
Real-time visibility into EDR deployment coverage, threat detections, unmanaged devices, and patch compliance across the endpoint fleet.
Email Security
Assessment of DMARC, DKIM, SPF configuration and enforcement, plus monitoring for phishing simulation results and BEC indicators.
Threat Intelligence Feeds
Correlation of global threat intelligence against the insured's specific infrastructure, domains, IP ranges, and technology stack.
Dark Web Monitoring
Continuous scanning of dark web forums, paste sites, and criminal marketplaces for leaked credentials, data, and organizational references.
Credential Exposure
Real-time detection of compromised credentials - including employee accounts, service accounts, and third-party integration keys.
Patch Management
Assessment of patching cadence and coverage across operating systems, applications, and critical infrastructure components.
Configuration Drift
Continuous monitoring for deviations from security baselines across cloud, network, and application configurations.
Backup Health
Verification of backup integrity, encryption, offline copies, and recovery testing - critical indicators for ransomware resilience.
Business Continuity Readiness
Assessment of incident response plans, disaster recovery procedures, tabletop exercise history, and recovery capability.
BEC & Fraud Indicators
Monitoring for business email compromise patterns, executive impersonation attempts, and financial fraud precursors.
Domain & Brand Spoofing
Detection of typosquatted domains, lookalike sites, and domain infrastructure used in phishing campaigns targeting the organization.
Security Awareness Metrics
Integration with phishing simulation platforms to assess employee susceptibility and training effectiveness across the organization.
Vulnerability Intelligence
Continuous scanning and enrichment of known vulnerabilities against the organization's technology inventory and exposure profile.
Signal Sources
Signals collected from
every layer of the environment.
Our platform aggregates intelligence from every layer of an organization's digital infrastructure - cloud platforms, identity providers, endpoint protection, threat intelligence feeds, and beyond.
Cloud Platforms
- Microsoft Azure
- Amazon Web Services
- Google Cloud
- Multi-cloud Environments
Identity & Access
- Azure Active Directory
- Okta
- Google Workspace
- CyberArk PAM
Email & Collaboration
- Microsoft Exchange
- Google Workspace
- Proofpoint
- Mimecast
Endpoint Protection
- CrowdStrike Falcon
- Microsoft Defender
- SentinelOne
- Carbon Black
Network & Firewall
- Palo Alto Networks
- Fortinet
- Cisco Meraki
- Check Point
Threat Intelligence
- VirusTotal
- Recorded Future
- CrowdStrike Intel
- Mandiant
Dark Web Sources
- Credential Markets
- Paste Sites
- Criminal Forums
- Data Breach Feeds
SIEM & Logging
- Microsoft Sentinel
- Splunk
- IBM QRadar
- Elastic Security
Backup & Recovery
- Veeam
- Cohesity
- Commvault
- Backup Health APIs
Attack Surface
- Domain Intelligence
- Certificate Transparency
- Shodan
- Open Port Scanning
Vulnerability Management
- Tenable Nessus
- Qualys
- Rapid7
- CVE Intelligence Feeds
Security Awareness
- KnowBe4
- Proofpoint TAP
- Cofense
- Phishing Simulation APIs
Financial Systems
- Authorized Read-Only Access
- Transaction Monitoring
- BEC Detection
- Anomaly Alerts
Deception Environments
- Honeypots
- Canary Tokens
- Decoy Credentials
- Attacker Profiling
Business Applications
- CRM Systems
- ERP Platforms
- HRIS Systems
- Critical SaaS Tools
Third-Party Vendors
- Vendor Risk APIs
- Supply Chain Intelligence
- Fourth-Party Exposure
- Security Ratings
AI Risk Assurance
Enabling insurers to confidently
underwrite AI systems.
Businesses are rapidly deploying AI agents capable of making autonomous decisions - approving purchases, managing infrastructure, executing workflows. Yet one question remains unanswered: who bears financial responsibility when an AI system independently causes loss? Barbon exists to answer that question.
Security Assessment
Evaluation of the AI system's underlying infrastructure, API exposure, authentication mechanisms, and attack surface.
Governance Review
Assessment of AI governance frameworks, accountability structures, change management processes, and board oversight.
Reliability Testing
Systematic testing of AI system performance under stress, edge cases, and degraded conditions - including fail-safe behaviour.
Prompt Injection Resistance
Structured adversarial testing to determine whether the AI system can be manipulated through crafted inputs.
Jailbreak & Evasion Testing
Assessment of the system's resilience to attempts to bypass its operating constraints or extract sensitive information.
Tool Permission Audit
Review of what actions the AI agent is permitted to take autonomously - and whether those boundaries are enforced.
Data Leakage Analysis
Assessment of whether the AI system exposes sensitive organizational, customer, or third-party data through its outputs.
Hallucination Risk
Evaluation of the probability and potential financial impact of the AI system generating confidently incorrect outputs.
Decision Consistency
Testing whether the AI system produces consistent, auditable, and explainable decisions across identical or similar inputs.
Human Oversight Mechanisms
Verification that adequate human approval workflows, review processes, and emergency stop capabilities are in place.
Compliance Readiness
Assessment against emerging AI regulatory frameworks - including EU AI Act, NIST AI RMF, and sector-specific requirements.
Financial Exposure Modelling
Quantification of maximum financial loss scenarios arising from AI system failures, errors, and autonomous decision-making.
AI Assurance Index - Barbon Scoring Framework
Who We Serve
Trusted across the
technology insurance ecosystem.
One intelligence platform - configured for every stakeholder involved in underwriting, managing, and insuring modern technology risk.
Underwrite cyber risk with measurable confidence.
Barbon provides insurers with continuous technical intelligence across their cyber book - enabling better risk selection, more accurate pricing, and earlier identification of deteriorating accounts before claims occur.
Why Barbon
Built for the next decade
of technology risk.
Technology risk has outgrown traditional underwriting models. Cyber threats change every hour. AI systems evolve continuously. Barbon exists to close the gap between what technology actually does and what insurers can see.
Annual questionnaire completed at renewal. Posture changes throughout the year go undetected until the next cycle.
Continuous monitoring across the entire policy lifecycle. Material risk changes flagged in real time - not twelve months later.
Self-reported answers from insured organizations. No independent verification of the accuracy or completeness of responses.
Independent technical assessment of the actual environment. Validated against live infrastructure - not self-attestation.
Qualitative risk categories based on questionnaire scoring. Limited ability to quantify or compare risk across the portfolio.
Proprietary Cyber Risk Score (0–100) built from hundreds of technical signals. Quantified, explainable, and comparable.
No established framework for assessing autonomous AI systems. AI risk excluded or approximated using cyber questions.
Purpose-built AI Risk Assurance framework. Independent evaluation of AI agents before deployment and continuous monitoring once live.
Security vendors listed on questionnaires taken at face value. No verification of effective implementation or actual risk reduction.
Independent validation of every major security vendor - confirming effective deployment, correct configuration, and genuine risk reduction.
Underwriting decisions made on incomplete, unverified, and potentially outdated information about the insured's true posture.
Underwriting decisions supported by continuous, independently verified technical intelligence - reducing adverse selection and surprise losses.
Get Started
Ready to underwrite technology
risk with confidence?
Talk to our team. We'll walk you through our risk intelligence platform, discuss how continuous assessment differs from traditional approaches, and help you determine the right programme for your underwriting operation.
We respond to all briefing requests within one business day.