Estimated reading time: 8 minutes
A defense supplier held every certificate on the list. Then it moved its servers. And issues arrived. On this episode of the Cyber Insurance News Podcast, Cyber Tzar CEO Andrew Horkan on why compliance is paperwork, what an outside-in scan sees, and why brokers are starting to use a cyber score before they bind.
Oh, that defense supplier, it delivered warheads.
Andrew Horkan, chief executive of Cyber Tzar, tells the story early in this episode. His firm sells continuous cyber risk monitoring. His company was monitoring 2,000 suppliers for a defense client. One of them held NIST, SOC 2, ISO 27001, and Cyber Essentials Plus. From January to May, it was compliant on paper.
In June, the scans changed. More than 17,000 ports were open and returning data.
The supplier’s tech team had moved its servers from France to Germany. Nobody told the auditors, because nobody had to. “You might be compliant, but there are things that every company, it doesn’t matter the size or the security, will accidentally let slip,” Horkan said. The supplier fixed it within a week. Without the monitoring, he says, the gap could have sat open until the next annual review, or a cyberattack became obvious.
Get The Podcast Here
Watch On YouTube
Watch Or Listen On Spotify
Listen On Apple Podcasts
Listen On Amazon Music
This episode is brought to you in association with Cyber Tzar and Source Consulting London.
Continuous Cyber Risk Monitoring And The Claims File
The claims question follows directly. If that supplier had suffered a loss in June, what would its insurer have seen?
Horkan’s answer is that the evidence would have cut against the policyholder. The controls stated on paper would not have matched the controls in place. “There was a high chance they wouldn’t have paid out,” he said.
He pitches the reverse case as the product. Clients use continuous cyber risk monitoring as a monthly system of record. It logs what was found and what was fixed. He says 15 client incidents over five years went to insurance claims with that record in hand. “If you’re getting a claim put in, here’s all the evidence in one location,” he said.
Security Is Still A Cost Center
Horkan got his first tech job at 15. He started in a data-entry role. Within two hours, he had automated it with the macro tool he used on RuneScape. The company made him head of integrations at 16.
What he learned there still holds, he says. Businesses value speed and sales. Security comes second. “I very rarely meet someone who is pro cyber unless they’ve already been breached,” he said.
Small firms ask two questions, in his experience. Are we insured? Can we win the tender? The UK’s Cyber Security and Resilience Bill is pushing more of them toward compliance for the second reason. That lines up with flat security budgets this publication has reported against rising threats.
What An Outside-In Scan Sees
Cyber Tzar’s first scan is non-intrusive. It finds every subdomain, checks open ports, tests email authentication records, and scans web code for known weaknesses. It checks breach data for staff email addresses. And it also benchmarks a company against similar firms in its region.
Horkan explains it with a house.
“I have stood outside your house, Martin, and I’ve gone, your alarm is out of date. It’s 10 years out of date. On top of that, we can see that it’s actually switched off,” he said. “We’ve stared right into the window, and I can see you’ve got a safe in the window and you can see what version that safe is.”
That is the public pavement, legally speaking. With consent, the testing moves inside. “We’ll kick the door down,” he said.
The Cyber Risk Score, From Zero To 999
The output is a score out of 1,000. Nobody gets the maximum. “The best potential score you can get is 999,” Horkan said. “That is because we don’t know the unknown unknowns.”
His bands run like this, drawn from the company’s own data:
- 850 and above: the target.
- About 700: the average across the 7.5 million organizations Cyber Tzar says it has scanned.
- 400 to 600: exposed to a targeted attacker with the know-how.
- Below 400: exposed to automated attacks.
He cites one company scored at 575. Outdated JavaScript libraries left weaknesses in its code. The attack that followed leaked about 1.2 million customer records within a day, he says.
The number he is proudest of is engagement. Cyber Tzar says 98% of suppliers who receive a report improve their posture within a month.
Take The Cyber Insurance News Survey
Respondents get the results first.
How Brokers Are Using A Cyber Score
Cyber Tzar works with three insurance organizations, Horkan said. One is an underwriter, and two are brokers.
The broker he has worked with longest uses the score two ways. Before binding, a low score can mean remediation first. “Could you please remediate these before we insure you?” is how he describes the ask. In sales, the findings create urgency that a revenue-based limit suggestion cannot.
It is part of a wider pattern. Security firms keep proposing external signals as underwriting inputs. Silent Push and Sophos and Spektrum have both done it this year.
Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!
The Supplier Behind The Supplier
The Jaguar Land Rover attack gives the conversation its weight. The UK’s Cyber Monitoring Centre put the financial impact at £1.9bn across more than 5,000 organizations.
Horkan brings it down to one company, a client, hauled for JLR through a DHL contract. It turns over about £10m a year. Under just-in-time terms, nobody got paid when the plants stopped.
“They lost 390,000 within the first month,” Horkan said. The total ran past £1m, he said. A site closed. Drivers went. The two brothers who ran the 20-year-old family business split it into separate companies.
Government support reached the top of the chain. “The suppliers to those suppliers haven’t, so they receive no aid and no support so far,” he said.
Why doesn’t a loss like that land like a factory fire? Horkan’s answer is visibility. A client’s website was once defaced with abuse aimed at the owner’s wife. The team fixed it within an hour. Nobody disclosed it. “If someone had graffitied that on the front of their building, it would have been seen straight away,” he said.
A Credit Score For Cyber
The plan is scale. Horkan wants to scan every active domain, which he puts at 358 million. “Effectively becoming a credit score, but for cyber,” he said.
The investment angle is already arriving, he says. An investment banker asked Cyber Tzar to score the holdings in its funds. Below a certain score, the thinking goes, a breach headline becomes likely enough to trade on.
His closing argument is about where the money goes. He describes a client that paid £25,000 for a penetration test and had nothing left to fix what it found. “That’s like me saying, I paid for an assessment. They’ve told me the door’s open. I’ve not closed the door.”
Take the Cyber Insurance News 2026 survey. Eight minutes, and respondents get the results first.
Full Transcript
Download the full transcript of this episode. Transcripts are machine-generated and lightly edited. Accuracy is not guaranteed. Please refer to the audio for the record.
FAQ – Continuous Cyber Risk Monitoring
What is continuous cyber risk monitoring?
Repeated external scanning of a company’s internet-facing systems, rather than a one-off audit. Cyber Tzar checks subdomains, open ports, email authentication records, web code and breach data, then tracks changes over time.
Why isn’t compliance enough?
Certificates describe a point in time. Andrew Horkan describes a defense supplier compliant from January to May that opened more than 17,000 ports in June after moving servers. Nothing required it to tell its auditors.
How does the Cyber Tzar score work?
It runs from 0 to 1,000, with 999 the best achievable. Horkan says 850 is the target, about 700 is average, 400 to 600 is exposed to targeted attack, and below 400 is exposed to automated attack.
How are insurers using external cyber scores?
Horkan says Cyber Tzar works with one underwriter and two brokers. One broker uses the score to request remediation before binding, and to show prospective clients specific findings during the sale.
What did the Jaguar Land Rover attack cost smaller suppliers?
Horkan says On Point Logistics, which hauled for JLR through DHL, lost 390,000 pounds in the first month and over 1 million pounds in total. The UK’s Cyber Monitoring Centre estimated the overall impact at 1.9 billion pounds.
Can continuous monitoring help with a cyber insurance claim?
Horkan says a monthly record of findings and fixes gives insurers and auditors one place to verify that stated controls were in place. He says 15 client incidents have gone to claims with that record.
Related Cyber Insurance Posts
- Swiss Re: Extreme Cyber Accumulation Is Too Big For Private Capital
- A Good Cyber Report Card Can Earn Companies Insurance Discounts: SecurityScorecard & Measured Analytics(Opens in a new browser tab)
- Nearly 3 In 10 US Businesses Hit By Cyber Incidents Involving Suspected AI Use(Opens in a new browser tab)
- Black Kite 2026: Europe’s Ransomware Surge Now Runs Through Your Suppliers(Opens in a new browser tab)
- Cybersecurity Crisis: WTW 2025 Report Reveals Alarming Supply Chain Threats(Opens in a new browser tab)