Cyber is deceptively simple to intake and brutally hard to price. Two applicants can have identical revenue, the same industry code, the same number of records on file, and request the same limit — and be an order of magnitude apart in risk, because one enforces multi-factor authentication and keeps offline backups and the other does neither. In cyber, the exposure is not on the balance sheet; it is in the control posture. That means intake has to read past the headline numbers and pull out the operational security answers that actually move the loss curve.

InsightXtract runs an agentic, multi-document pipeline across the cyber submission: it classifies each file, extracts the broker email and the cyber application to their own schemas, consolidates everything into one unified account record by source priority, links it into an entity graph, and validates it against your rules and reference data. The underwriter opens a single coded, cited record — identity, records exposure, controls, compliance, prior incidents, and the requested tower — instead of scrolling a PDF application.

flowchart LR A[Broker email
Cyber application] --> B[Classify
each document] B --> C[Extract to the
right schema] C --> D[Consolidate
by source priority] D --> E[Link into an
entity graph] E --> F[Validate
rules + reference data] F --> G[One coded,
cited account record]

One submission, two documents, one connected record — classify, extract, consolidate, link, validate.

The idea that governs everything: controls are the price

Before the categories, the single most important concept. In cyber, the exposure numbers tell you the potential loss; the controls tell you the probability. Records held and revenue set the ceiling on a breach — how big the bill could be. But whether that loss actually happens is decided by a short list of operational answers: is MFA enforced, is EDR deployed, are backups held offline and immutable, how quickly are systems patched, are employees trained, is there a tested incident-response plan. Those fields are the difference between a quotable account and a decline, and they are exactly what a busy application buries in yes/no checkboxes.

So InsightXtract treats the control set as a first-class category, not a footnote. In the tables below, the Captured column flags how each parameter is read:

  • Point-in-time — a single static fact about the account.
  • Current term — a value tied to this submission and its coverage ask.
  • Control — a security-posture answer that drives the underwriting decision.

A · Insured & identity

Who the account is — legal identity, structure, operations classification, and where the risk sits. Sources: cyber application, broker email.

ParameterCapturedWhy it matters
Named insured · DBA · FEINPoint-in-timeThe contract party and unique account key — drives clearance, conflicts, and de-dupe.
Mailing / physical address · risk statePoint-in-timeBreach-notification statutes and regulatory regime vary by state — venue changes the cost of a loss.
NAICS code · SIC code · industryPoint-in-timeClass-based appetite and rating — healthcare, finance, and retail carry very different threat profiles.
Entity type · business descriptionPoint-in-timeLegal form and the nature of operations — the hazard grade beyond the code.
Years in businessPoint-in-timeOperational maturity and stability — a proxy for security discipline.

B · Financial & digital exposure

The scale of the operation and how much of it lives online — the base the loss ceiling is drawn from. Sources: cyber application.

ParameterCapturedWhy it matters
Estimated revenue · annual revenuePoint-in-timePrimary exposure base — revenue anchors business-interruption loss and the rating basis.
Annual online revenuePoint-in-timeDigital dependency — the share of income that stops if systems go down.
Total payroll · employee countPoint-in-timeWorkforce size and the human attack surface — more endpoints and inboxes to phish.

C · Records exposure

The single biggest driver of breach severity — how many sensitive records the insured holds, and of what kind. Sources: cyber application.

ParameterCapturedWhy it matters
Records held · number of recordsPoint-in-timeThe volume of data at risk — notification and remediation cost scales per record.
PII recordsPoint-in-timePersonally identifiable information — the core driver of breach-response and legal cost.
PHI recordsPoint-in-timeProtected health information — HIPAA exposure and the highest per-record loss severity.

Why records count is the exposure ceiling

Breach cost is largely a function of how many records must be investigated, notified, credit-monitored, and potentially litigated. An account holding a few thousand records and one holding several million have fundamentally different loss ceilings even before you look at their controls — which is why the split between PII and PHI is captured separately, not lumped into a single count.

D · Security controls — the underwriting decision

This is the category that decides quote-or-decline. Each answer is a control the market now treats as table stakes; the absence of any one of them can move an account from “preferred” to “uninsurable.” Sources: cyber application.

ParameterCapturedWhy it matters
MFA enabledControlMulti-factor authentication — the single strongest predictor of a ransomware or account-takeover loss. Its absence is a common hard decline.
EDR enabled · EDR deployedControlEndpoint detection and response — whether the insured can detect and contain an intrusion before it spreads.
Offline backupsControlImmutable, offline backups — the difference between recovering from ransomware and paying the ransom.
Patch cadenceControlHow quickly known vulnerabilities are closed — the window attackers exploit.
Employee security trainingControlPhishing awareness — the human control against the most common initial-access vector.
Incident response planControlA tested plan — response speed directly reduces business-interruption and breach cost.

E · Compliance & third-party risk

The regulatory posture and the exposure the insured inherits from everyone it connects to. Sources: cyber application.

ParameterCapturedWhy it matters
PCI compliantControlPayment-card data handling — PCI status governs card-brand fines and assessment exposure after a breach.
Third-party vendorsPoint-in-timeSupply-chain attack surface — each connected vendor is a path in and a source of aggregation risk.

F · Prior incidents

Loss history for a line where past compromise is a strong signal of future compromise. Sources: cyber application.

ParameterCapturedWhy it matters
Prior incidentsPoint-in-timeWhether the insured has been breached before — a direct adverse-selection and repeat-loss flag.
Prior incident detailsPoint-in-timeNature, cause, and remediation of past events — did they fix the root cause or just the symptom?
The InsightXtract configuration builder — a cyber submission's fields defined in the agent's output contract: identity, records exposure, security controls, coverage, and premium, each mapped to its source document
Every field is configuration — the cyber output contract defines identity, records, controls, and the coverage tower, each mapped to the document it comes from.

G · Coverage & limits

The shape of the ask — the tower being requested and the sublimits that carry the real cyber severity. Sources: cyber application, broker email.

ParameterCapturedWhy it matters
Requested / cyber limitCurrent termThe capacity being offered — the core of the ask.
Aggregate limitCurrent termTotal capacity across all covered events in the term.
RetentionCurrent termThe insured’s self-funded first layer — drives price and signals risk appetite.
Business-interruption sublimitCurrent termCaps recovery for downtime losses — one of the two severity drivers in modern cyber.
Ransomware sublimitCurrent termCaps extortion and recovery cost — the other severity driver, and the one carriers most tightly manage.

H · Submission, broker & premium

The ask itself and who is placing it — term, product, distribution, and price. Sources: broker email, cyber application.

ParameterCapturedWhy it matters
Broker name · broker emailPoint-in-timeDistribution routing, binding authority, and correspondence.
Product · effective dateCurrent termCoverage form, workflow, and the binding deadline.
PremiumCurrent termThe price — the number every other parameter on this page exists to justify.

From fields to one connected record

Pulling these parameters out of two documents is only half the job. The value is in consolidation: the insured named on the application, the broker on the email, the controls on the questionnaire, and the tower on the ask all describe one account. InsightXtract merges them into a single record by a declared source-of-truth priority — the application wins over the email on insured details and controls; the email carries the broker and the requested terms — and links the result into an entity graph: insured at the centre, connected to broker, submission, records exposure, control posture, and requested coverage. Every value is validated against reference data — NAICS and state codes are standardized and checked, the insured name is required — and cited back to the page it came from.

Why the record, not just a form

An underwriter doesn’t think in flat fields — they think in relationships: does the control posture justify the requested ransomware sublimit? Do the PHI record counts line up with the industry code and the PCI answer? The consolidated record makes those connections explicit and clickable, with every value cited back to its source.

Why it matters to the business

Comprehensive, structured, control-aware extraction isn’t a data-entry nicety — it changes the economics and quality of the book:

  • The controls are the decision. MFA, EDR, offline backups, patch cadence, training, and a tested incident-response plan are what separate a quotable account from a decline. Extracting them by default means the decision-critical answers reach the underwriter, coded the same way every time.
  • Severity is captured, not estimated. The ransomware and business-interruption sublimits are the two levers that carry modern cyber loss. Pulling them out explicitly — alongside the aggregate and retention — means the tower is priced to the exposures that actually blow up.
  • Records count sets the ceiling. Splitting PII and PHI record counts out from a single total lets you rate breach severity to the data that is genuinely at risk, not a rounded headline number.
  • Prior incidents surface adverse selection. A previously breached account that fixed the symptom but not the root cause is exactly the risk that repeats — captured by default rather than lost in a checkbox.
  • Consistency and auditability. The same categories, coded the same way, with provenance to the source document — the difference between a repeatable book and one that depends on which underwriter opened the file.

The Cyber agent extracts all of this today — the insured and its identity; the financial and digital exposure; the records at risk split by PII and PHI; the full security-control posture; PCI and third-party risk; prior incidents; and the requested tower with its ransomware and business-interruption sublimits — consolidated into one coded record, every value cited to its source document. Cyber has no schedules to tabulate, so the control set becomes the rich centre of the record instead of a table. And because it’s all configuration — fields in the agent’s output contract, not code — the schema keeps pace with the next control the market decides is table stakes.