Skip to content

Every cyber submission, checked against your controls.

Applications, supplements, questionnaires and incident history resolved into one control picture. Missing controls and appetite conflicts surface before the first read.

Lattice Health Partners, Inc.HEALTHCARE · $42M REV88 Federal St, Boston, MA 02110SUB-2026-05903

Received

2:41 PM

Decision-ready

3:12 PM
4 documents · 41 answers
REFER — Program Headimmutable backups unevidenced above $25M revenueWhy?
Control
State
Source
Multi-factor authentication
partial
Questionnaire p.4
Endpoint detection & response
satisfied
Questionnaire p.5
Immutable / offline backups
not evidenced
— no document
Privileged access management
satisfied
Questionnaire p.6
Critical patch SLA
conflicting
App p.2 vs Questionnaire p.5
Email security / BEC controls
satisfied
App p.3
Revenue band · $42M✓ IN APPETITE
Sub-limit thresholds✓ IN APPETITE
Control requirements⚑ REFERRED
4 documents merged · 2 controls unevidenced · 1 conflict · every answer cited
Cyber applications parsed across any format, no rigid forms
Control requirements checked against your appetite, mismatches flagged
Every answer traced to the document it came from
MFA · remote access & privilegedEDR / XDR coverageImmutable backupsBackup restore testingCritical patch SLAAttack surface scanLegacy VPN exposureEmail security / BECSecurity awareness trainingIncident response planThird-party / supply chainMFA · remote access & privilegedEDR / XDR coverageImmutable backupsBackup restore testingCritical patch SLAAttack surface scanLegacy VPN exposureEmail security / BECSecurity awareness trainingIncident response planThird-party / supply chain
Ransomware sub-limitCoinsurance on extortionWaiting period · BIDependent business interruptionFunds transfer fraud sublimitSocial engineering endorsementWidespread event exclusionWar & state-backed exclusionFailure-to-maintain-controlsPrior acts / retroactive datePHI / PII record countRansomware sub-limitCoinsurance on extortionWaiting period · BIDependent business interruptionFunds transfer fraud sublimitSocial engineering endorsementWidespread event exclusionWar & state-backed exclusionFailure-to-maintain-controlsPrior acts / retroactive datePHI / PII record count

The cyber desk

Three things that slow your cyber desk down.

App p.2 — “MFA: Yes”
Questionnaire p.4 — “Email only. Remote access: planned Q3”
Supplement p.1 — “MFA on all critical systems”
Broker email — “confirmed enabled”
01The answers are spread across four documents.

Application, supplement, security questionnaire, incident history. The same control is answered three times, three different ways. Someone reconciles it by hand.

One control · four answers · none of them wrong
Inbox412
RE: RE: Fwd: Lattice Health — questionnaire attached (2)
Is the backup documentation coming?
Need indication by Thursday COB
Broker asking again
02Brokers shop every account in a soft market.

Same-day acknowledgment is table stakes. The first credible response sets the terms. Slow answers move the account.

Program guidelines — Cyber
Immutable backups required above $25M revenue
Ransomware sub-limit gated on restore testing
Refer healthcare above 250k PHI records
Last updated Mar 2023
min MFA scope for healthcare — ask Dave
03Appetite lives in people's heads.

Revenue bands, sub-limits, industry exclusions, minimum control sets. The manual is tribal knowledge. The file holds documents, not reasoning.

The cyber desk

From application to signed-off decision.

Every document resolved into one control picture. Every guideline running as a rule. Every decision recorded as it happens.

One risk pictureSUB-2026-05903
Cyber_App.pdfSecurity_Questionnaire.xlsxRansomware_Supplement.pdfIncident_History.pdf
Multi-factor authentication1
partial
Endpoint detection & response2
satisfied
Immutable / offline backups3
not evidenced
Privileged access management4
satisfied
Critical patch SLA5
conflicting
Email security / BEC controls6
satisfied
4 documents · 1 control picture · 2 gaps · 1 conflict

Live · one submission, end to end

One questionnaire, broker email to decided file.

01Assembled
02Resolved
03Checked
04Triggered
05Held
06Recorded
Lattice Health Partners, Inc.Assembled2:41 PM
Cyber_App.pdfSecurity_Questionnaire.xlsxRansomware_Supplement.pdfIncident_History.pdf0 answers
01The full picture, already assembled.

Applications, supplements, security questionnaires, incident history. Any format, parsed into one risk picture before anyone opens the file.

02The same control, answered once.

Where documents disagree, both answers are shown and the more specific instrument wins. MFA presence is not MFA scope.

03Controls checked, not chased.

MFA, EDR, backups, patch SLA, training. Gaps surfaced instantly, with the chase message drafted where documentation is missing.

04Referral triggers fire early.

Revenue bands, sub-limit thresholds, industry conflicts, minimum control sets. Triage lands in-appetite, refer or out-of-appetite before hours are spent.

05You decide. Exceptions come to you.

Referrals reach you with the control state and evidence assembled. Terms stay your call. Override anytime, and the reasoning is recorded.

06Decided, and already defensible.

Inputs, sources, control state at bind, rules fired, rationale, approver. Recorded as you decide, reconstructable per decision.

Every referral becomes a rule. Every rule runs on the next submission.

Explainability

Nothing on this screen is a guess.

Every answer traces to the document it came from. Every control shows the evidence behind its state. When two documents disagree, both are shown and the choice is explained.

Multi-factor authentication

partial1

Click any control → the document and question that evidenced it

Conflicting answers resolved by instrument specificity, both shown

Control state at bind, preserved on the decision record

Security_Questionnaire.xlsx · p.4
EmailYes
Remote accessPlanned Q3
Privileged accountsNo
MFA: YesCyber_App.pdf

Questionnaire preferred by source confidence — scope-level instrument over yes/no · RES-CTRL-04

Control state partial — CYB-SUB-03 caps ransomware sub-limit

Appetite

Built for the cyber classes you write.

Healthcare
Highest average incident cost. PHI record counts and backup evidence decide it.
Professional services
High claim share by value. Funds transfer fraud and email compromise.
Financial services
Regulatory exposure and social engineering. Wire verification controls.
Manufacturing
Operational technology and downtime. Dependent business interruption exposure.
Retail & e-commerce
Payment card and PII volume. Third-party and plugin exposure.
Technology & SaaS
Dependent BI both ways. Supply-chain and downstream aggregation.
Education
Large record counts, constrained budgets. Legacy systems and patch discipline.
Public entities
Ransomware target profile. Recovery capability over prevention maturity.
< $10M$10M–$25M$25M–$100M$100M–$250M> $250M

Minimum control set and sub-limit availability change at each band.

Controls

Five controls decide most cyber accounts.

Presence is not scope. Each of these is checked against your minimum set, per industry and revenue band, with the evidence attached.

Multi-factor authentication

Checked at scope, not yes/no. Email, remote access and privileged accounts assessed separately.

Scope-level checkMost common partial state
Endpoint detection & response

Coverage percentage matters more than presence. Partial deployment is the common finding.

Coverage %Deployment evidence
Immutable & offline backups

The control that gates the ransomware sub-limit. Restore testing evidence requested where missing.

Gates sub-limitRestore test evidence
Critical patch SLA

A stated window is not a demonstrated one. Conflicting answers across documents are common here.

Stated vs. evidencedFrequent conflict
Email security & BEC controls

Business email compromise dominates claim frequency. Wire verification procedure checked alongside.

Dominant claim type by volumeWire verification
Multi-factor authentication
partial
Questionnaire p.4
Immutable / offline backups
not evidenced
— no document
Critical patch SLA
conflicting
App p.2 vs Q p.5

See it on a submission you actually write.

Send us one live submission. We map your program and run it. Fifteen minutes to first output, no pitch deck.