Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Cyber Insurance Readiness Check

Underwriters ask about a predictable set of controls. Rate yourself on each, and get a readiness band plus exactly what to fix before you apply. This is a preparation aid, not an insurance quote.

0 / 100 Rate the controls below

Not ready for a call yet?

Get the insurability playbook

A few short notes from Jacob on passing underwriting the first time, MFA, EDR, backups, and the rest. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want it done for you?

Cyber Insurance Readiness

We help you close the control gaps underwriters ask about, so your application goes in strong.

Explore Cyber Insurance Readiness →

Go into underwriting strong

We help you close the exact control gaps underwriters flag, MFA, EDR, backups, IR plan, so your application is not sent back or repriced. Led by a published security researcher. A Fractional CISO engagement or a round of penetration testing can close these gaps fast; see our pricing for how it's scoped.

Explore Cyber Insurance Readiness

Frequently asked questions

What controls do cyber-insurance underwriters ask about?

Applications and questionnaires commonly ask whether you enforce multi-factor authentication (especially for email, remote access, and privileged accounts), run endpoint detection and response (EDR), keep tested and segregated backups, filter email for phishing and malware, patch on a regular cadence, have a written incident response plan, and run security awareness training. This tool is built around those commonly-requested controls.

Does a high score guarantee coverage or a price?

No. This is a self-assessment to help you prepare before you apply, not an insurance quote or a guarantee. Actual underwriting, coverage terms, and pricing are decided by insurers based on their own questionnaires, your industry, revenue, and claims history.

Is it free?

Yes, the readiness check is free and requires no signup. It is meant to help you spot and close obvious gaps before an underwriter does.

What should I fix before applying?

Start with the controls insurers most often treat as baseline: MFA everywhere (particularly email and remote access), EDR on endpoints, and tested backups kept separate from production. This tool flags your weakest of these first so you can close them before an application forces the issue.

Want the full picture on NIST CSF 2.0?

This gives you the shape of the problem. The full picture is all 106 subcategories of NIST CSF 2.0, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

Start your free NIST CSF 2.0 assessment See what is in the Workspace

No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.