The Technology Risk
Intelligence Layer.

Barbon continuously measures cyber and AI risk - providing insurers with the real-time intelligence needed to underwrite modern technology with confidence.

Vendor-Neutral
Independent Assessments
Continuous Monitoring
ISO 27001
Insurer-Trusted
🔒app.barbon.tech/risk-intelligence

Built for insurers that need to underwrite technology risk with measurable confidence.

Independent & Vendor-Neutral
Continuously Validated
Insurer-Grade Intelligence
Real-Time Risk Signals

Cyber Risk Intelligence

Continuous risk intelligence.
Across the entire policy lifecycle.

Barbon enables insurers and brokers to confidently issue and manage cyber insurance through continuous technical assessment - replacing the annual questionnaire with ongoing, measurable intelligence.

Cyber Insurance Risk Assessments

Independent technical assessments that provide insurers with objective risk intelligence ahead of policy inception and renewal.

Underwriting Intelligence

Structured risk reports built for underwriting decisions - not compliance reports. Actionable, measurable, and continuously updated.

Continuous Cyber Risk Monitoring

Ongoing surveillance across an organization's entire technology environment throughout the policy lifecycle - not just at renewal.

Cyber Risk Scoring

A proprietary scoring model that quantifies cyber risk into a single, explainable metric that insurers can act on with confidence.

Threat Intelligence

Real-time threat feeds correlated against each insured's specific environment - surfacing exposure before it becomes a claim.

Executive Dashboards

Clear, executive-friendly reporting translating technical risk signals into the language of insurance underwriting and loss prevention.

Security Validation

Verification that existing security controls are correctly implemented, functioning as intended, and reducing actual risk.

Vendor Assurance

Independent validation that cybersecurity vendors are delivering meaningful risk reduction - not just meeting contractual requirements.

Attack Surface Monitoring

Continuous discovery and monitoring of internet-facing assets, identifying exposed infrastructure before threat actors do.

Cloud Security Validation

Assessment of cloud environment configurations across AWS, Azure, and Google Cloud - identifying misconfigurations and policy drift.

Identity Risk Monitoring

Continuous assessment of identity provider health, privileged access, MFA adoption, and credential compromise indicators.

Third-Party Risk Reviews

Evaluation of supply chain and vendor exposure - assessing how third-party risk propagates into the insured's environment.

Security Governance Reviews

Assessment of security programme maturity, policy frameworks, awareness culture, and board-level accountability.

Compliance Validation

Independent verification of regulatory and standards compliance - providing insurers with evidence beyond self-attestation.

Cyber Risk Trend Analysis

Longitudinal tracking of an organization's cyber posture over time - identifying whether risk is improving, stable, or deteriorating.

Explore Cyber Risk Intelligence

Our Underwriting Approach

Beyond the questionnaire.
Into the infrastructure.

Rather than asking whether a client has antivirus software, Barbon answers the questions that actually determine underwriting outcomes. How likely is this organization to experience a cyber incident over the next twelve months? Is their posture improving or deteriorating? Should premiums be adjusted?

Risk Intelligence Pipeline

  1. 01

    Signal Collection

    Continuous data ingestion from cloud, identity, email, endpoint, and threat intelligence sources

  2. 02

    Environment Analysis

    Full mapping of the insured's technology footprint - on-premise, cloud, and SaaS environments

  3. 03

    Threat Correlation

    Active threats correlated against the specific organization's exposed attack surface and technology stack

  4. 04

    Posture Scoring

    Proprietary risk model converts technical findings into an explainable Cyber Risk Score (0–100)

  5. 05

    Vendor Assurance

    Independent validation that existing security vendors are reducing risk - not just deployed on paper

  6. 06

    Underwriting Report

    Structured intelligence report delivered in the language of underwriting - with recommended actions

  7. 07

    Continuous Monitoring

    Ongoing surveillance flags posture changes, new threats, and material risk shifts throughout the policy term

Explore our approach
Live Demo · Risk Assessment Engine
Attack SurfaceCloud PostureIdentity RiskDark WebBEC IndicatorsVendor Risk

Risk Intelligence Platform

Built for the underwriters
who decide.

Every signal from every corner of an organization's technology environment - transformed into insurance intelligence. Risk scores, posture trends, and threat indicators in one structured view.

Signal Coverage

Every signal.
Every environment. Continuously.

Our platform continuously collects and analyzes signals from across an organization's entire technology environment - transforming raw technical data into structured underwriting intelligence.

Microsoft 365 & Azure

Continuous monitoring of Microsoft cloud environments - identity posture, conditional access, email security, and misconfiguration detection.

AWS Cloud Environments

Assessment of AWS configurations, IAM policies, public S3 buckets, security groups, and workload exposure across all regions.

Identity Providers

Continuous review of Okta, Azure AD, and Google Workspace - MFA adoption rates, privileged access, dormant accounts, and sign-in anomalies.

Endpoint Protection

Real-time visibility into EDR deployment coverage, threat detections, unmanaged devices, and patch compliance across the endpoint fleet.

Email Security

Assessment of DMARC, DKIM, SPF configuration and enforcement, plus monitoring for phishing simulation results and BEC indicators.

Threat Intelligence Feeds

Correlation of global threat intelligence against the insured's specific infrastructure, domains, IP ranges, and technology stack.

Dark Web Monitoring

Continuous scanning of dark web forums, paste sites, and criminal marketplaces for leaked credentials, data, and organizational references.

Credential Exposure

Real-time detection of compromised credentials - including employee accounts, service accounts, and third-party integration keys.

Patch Management

Assessment of patching cadence and coverage across operating systems, applications, and critical infrastructure components.

Configuration Drift

Continuous monitoring for deviations from security baselines across cloud, network, and application configurations.

Backup Health

Verification of backup integrity, encryption, offline copies, and recovery testing - critical indicators for ransomware resilience.

Business Continuity Readiness

Assessment of incident response plans, disaster recovery procedures, tabletop exercise history, and recovery capability.

BEC & Fraud Indicators

Monitoring for business email compromise patterns, executive impersonation attempts, and financial fraud precursors.

Domain & Brand Spoofing

Detection of typosquatted domains, lookalike sites, and domain infrastructure used in phishing campaigns targeting the organization.

Security Awareness Metrics

Integration with phishing simulation platforms to assess employee susceptibility and training effectiveness across the organization.

Vulnerability Intelligence

Continuous scanning and enrichment of known vulnerabilities against the organization's technology inventory and exposure profile.

Signal Sources

Signals collected from
every layer of the environment.

Our platform aggregates intelligence from every layer of an organization's digital infrastructure - cloud platforms, identity providers, endpoint protection, threat intelligence feeds, and beyond.

Cloud Platforms

  • Microsoft Azure
  • Amazon Web Services
  • Google Cloud
  • Multi-cloud Environments

Identity & Access

  • Azure Active Directory
  • Okta
  • Google Workspace
  • CyberArk PAM

Email & Collaboration

  • Microsoft Exchange
  • Google Workspace
  • Proofpoint
  • Mimecast

Endpoint Protection

  • CrowdStrike Falcon
  • Microsoft Defender
  • SentinelOne
  • Carbon Black

Network & Firewall

  • Palo Alto Networks
  • Fortinet
  • Cisco Meraki
  • Check Point

Threat Intelligence

  • VirusTotal
  • Recorded Future
  • CrowdStrike Intel
  • Mandiant

Dark Web Sources

  • Credential Markets
  • Paste Sites
  • Criminal Forums
  • Data Breach Feeds

SIEM & Logging

  • Microsoft Sentinel
  • Splunk
  • IBM QRadar
  • Elastic Security

Backup & Recovery

  • Veeam
  • Cohesity
  • Commvault
  • Backup Health APIs

Attack Surface

  • Domain Intelligence
  • Certificate Transparency
  • Shodan
  • Open Port Scanning

Vulnerability Management

  • Tenable Nessus
  • Qualys
  • Rapid7
  • CVE Intelligence Feeds

Security Awareness

  • KnowBe4
  • Proofpoint TAP
  • Cofense
  • Phishing Simulation APIs

Financial Systems

  • Authorized Read-Only Access
  • Transaction Monitoring
  • BEC Detection
  • Anomaly Alerts

Deception Environments

  • Honeypots
  • Canary Tokens
  • Decoy Credentials
  • Attacker Profiling

Business Applications

  • CRM Systems
  • ERP Platforms
  • HRIS Systems
  • Critical SaaS Tools

Third-Party Vendors

  • Vendor Risk APIs
  • Supply Chain Intelligence
  • Fourth-Party Exposure
  • Security Ratings
Secure read-only access - no business disruption
GET /api/v1/organizations/{orgId}/risk-score

AI Risk Assurance

Enabling insurers to confidently
underwrite AI systems.

Businesses are rapidly deploying AI agents capable of making autonomous decisions - approving purchases, managing infrastructure, executing workflows. Yet one question remains unanswered: who bears financial responsibility when an AI system independently causes loss? Barbon exists to answer that question.

Security Assessment

Evaluation of the AI system's underlying infrastructure, API exposure, authentication mechanisms, and attack surface.

Governance Review

Assessment of AI governance frameworks, accountability structures, change management processes, and board oversight.

Reliability Testing

Systematic testing of AI system performance under stress, edge cases, and degraded conditions - including fail-safe behaviour.

Prompt Injection Resistance

Structured adversarial testing to determine whether the AI system can be manipulated through crafted inputs.

Jailbreak & Evasion Testing

Assessment of the system's resilience to attempts to bypass its operating constraints or extract sensitive information.

Tool Permission Audit

Review of what actions the AI agent is permitted to take autonomously - and whether those boundaries are enforced.

Data Leakage Analysis

Assessment of whether the AI system exposes sensitive organizational, customer, or third-party data through its outputs.

Hallucination Risk

Evaluation of the probability and potential financial impact of the AI system generating confidently incorrect outputs.

Decision Consistency

Testing whether the AI system produces consistent, auditable, and explainable decisions across identical or similar inputs.

Human Oversight Mechanisms

Verification that adequate human approval workflows, review processes, and emergency stop capabilities are in place.

Compliance Readiness

Assessment against emerging AI regulatory frameworks - including EU AI Act, NIST AI RMF, and sector-specific requirements.

Financial Exposure Modelling

Quantification of maximum financial loss scenarios arising from AI system failures, errors, and autonomous decision-making.

AI Assurance Index - Barbon Scoring Framework

Overall AI Assurance ScoreSecurityGovernanceReliabilityPrivacyComplianceHuman OversightFinancial ExposureOperational StabilityAutonomy ClassificationRecommended Insurance Class

Who We Serve

Trusted across the
technology insurance ecosystem.

One intelligence platform - configured for every stakeholder involved in underwriting, managing, and insuring modern technology risk.

Underwrite cyber risk with measurable confidence.

Barbon provides insurers with continuous technical intelligence across their cyber book - enabling better risk selection, more accurate pricing, and earlier identification of deteriorating accounts before claims occur.

Cyber Risk ScoringUnderwriting ReportsPortfolio IntelligencePosture Trend AnalysisRenewal IntelligenceLoss Prevention Alerts

Why Barbon

Built for the next decade
of technology risk.

Technology risk has outgrown traditional underwriting models. Cyber threats change every hour. AI systems evolve continuously. Barbon exists to close the gap between what technology actually does and what insurers can see.

Dimension
Traditional Approach
Barbon
Assessment Frequency

Annual questionnaire completed at renewal. Posture changes throughout the year go undetected until the next cycle.

Continuous monitoring across the entire policy lifecycle. Material risk changes flagged in real time - not twelve months later.

Intelligence Source

Self-reported answers from insured organizations. No independent verification of the accuracy or completeness of responses.

Independent technical assessment of the actual environment. Validated against live infrastructure - not self-attestation.

Risk Measurement

Qualitative risk categories based on questionnaire scoring. Limited ability to quantify or compare risk across the portfolio.

Proprietary Cyber Risk Score (0–100) built from hundreds of technical signals. Quantified, explainable, and comparable.

AI Risk

No established framework for assessing autonomous AI systems. AI risk excluded or approximated using cyber questions.

Purpose-built AI Risk Assurance framework. Independent evaluation of AI agents before deployment and continuous monitoring once live.

Vendor Validation

Security vendors listed on questionnaires taken at face value. No verification of effective implementation or actual risk reduction.

Independent validation of every major security vendor - confirming effective deployment, correct configuration, and genuine risk reduction.

Underwriting Confidence

Underwriting decisions made on incomplete, unverified, and potentially outdated information about the insured's true posture.

Underwriting decisions supported by continuous, independently verified technical intelligence - reducing adverse selection and surprise losses.

Get Started

Ready to underwrite technology
risk with confidence?

Talk to our team. We'll walk you through our risk intelligence platform, discuss how continuous assessment differs from traditional approaches, and help you determine the right programme for your underwriting operation.

We respond to all briefing requests within one business day.