THE THREAT CHANGED. THE INSURANCE MODEL DIDN’T. Threat reality (continuous) Every day. Every size. Cyber attacks don’t wait for renewal cycles. Adaptive and persistent. Threats reinvent themselves to break defences. Change is constant. People, devices, software, vulnerabilities, drift. Broker snapshot (point‑in‑time) Once a year. A view of the business at one moment. Bolted‑on cyber. Often added at the end, not built for drift. Uncertainty grows. 10 months later, reality has changed. Protection must update continuously. THREATS DON’T WAIT.

Cyber risk is continuous. Insurance still looks at you once a year.

Between renewals, controls drift, vulnerabilities appear, and reality changes. That gap is where uncertainty — and uncovered loss — happens.

The old model is point‑in‑time: a renewal snapshot and a declaration. Months later, the facts have changed — but the decision hasn’t.

Old model vs Halo‑IQ model
Old model (point‑in‑time) Questionnaire → Declaration → Assessment → Insurance SNAPSHOT AT RENEWAL Questionnaire Declaration Assessment Insurance 10 MONTHS LATER Renewal declaration Decision reached based on a point‑in‑time view. Then the business changes — controls drift, vulnerabilities emerge. Reality moves on. REALITY CHANGED → UNCERTAINTY REALISED NEXT BREACH MAY BE UNPROTECTED Halo‑IQ model (continuous) Evidence → Determination → Protection → Change → Re‑determination → Remediation UPDATES WHEN FACTS CHANGE Continuous protection. Evidence Determination Protection Change detected Re‑determination Remediation

Halo‑IQ treats protectability as continuous: when the evidence changes, the determination updates, and protection responds.

The answer is a protection model that updates when the facts change.

Halo‑IQ starts with operational reality — evidence from the technology protecting the business — and turns it into deterministic determinations, with a contemporaneous record of what Halo knew, what Halo decided, and why.

Technology → Evidence → Determination → Protection

The evidence updates. The determination updates. Protection responds.

Canonical flow (inside Halo‑IQ per analysis run)
Evidence Normalisation TrueState™ Determination Protection

This is the internal pipeline per analysis run. The operating model is continuous — but the pipeline is the repeatable, auditable mechanism.

The answers already exist.

When a business needs cyber insurance, many of the most important questions eventually reach the people who actually know the answers. The broker doesn’t know. The CEO doesn’t know. The MSP knows.

They know which controls are deployed.
They know whether MFA is operating.
They know which devices are protected.
They know what needs patching.
They know what vulnerabilities exist.
And increasingly, the technology can provide the evidence directly.

So why keep asking businesses to describe what their technology can prove? Halo‑IQ starts with the evidence.

Explore Halo‑IQ by audience

MSPs
Turn operational evidence into protectable outcomes — and recurring protection economics.
Business Owners
Know what is true, what needs to happen, and what protection you can rely on.
Technology Partners
Make your product part of the evidence ecosystem that supports protection.
Insurance & Capacity
Evidence-backed determinations with rules, remediation history, and protection status.