Cyber protection, determined from evidence.

Know what’s true. Determine what happens next.

Halo‑IQ continuously turns operational evidence from the technology already protecting a business into explainable, auditable protection determinations — so MSPs and their customers can see what is protected, what has changed, and what needs attention.

How it works For MSPs Talk to Halo‑IQ

Technology → Evidence → TrueState → Determination → Protection

Evidence updates. TrueState updates. Determinations update. Protection responds.

THE THREAT CHANGED. THE INSURANCE MODEL DIDN’T. Threat reality (continuous) Every day. Every size. Cyber attacks don’t wait for renewal cycles. Adaptive and persistent. Threats reinvent themselves to break defences. Change is constant. People, devices, software, vulnerabilities, drift. Broker snapshot (point‑in‑time) Once a year. A view of the business at one moment. Bolted‑on cyber. Often added at the end, not built for drift. Uncertainty grows. 10 months later, reality has changed. Protection must update continuously. THREATS DON’T WAIT.

The threat is continuous. Decisions are still often point‑in‑time.

Controls drift, vulnerabilities appear, and environments change. Halo‑IQ exists to replace declarations with operational truth — and to keep determinations current as the evidence changes. Insurance is one downstream use of those determinations, not the platform itself.

The old model is point‑in‑time: a snapshot and a declaration. Months later, the facts have changed — but the decision hasn’t.

Old model vs Halo‑IQ model
Old model (point‑in‑time) Questionnaire → Declaration → Assessment → Insurance SNAPSHOT AT RENEWAL Questionnaire Declaration Assessment Insurance 10 MONTHS LATER Renewal declaration Decision reached based on a point‑in‑time view. Then the business changes — controls drift, vulnerabilities emerge. Reality moves on. REALITY CHANGED → UNCERTAINTY REALISED NEXT BREACH MAY BE UNPROTECTED Halo‑IQ model (continuous) Evidence → Determination → Protection → Change → Re‑determination → Remediation UPDATES WHEN FACTS CHANGE Continuous protection. Evidence Determination Protection Change detected Re‑determination Remediation

Halo‑IQ treats protection as continuous: when the evidence changes, the determination updates, and the protection position updates with it.

Canonical flow (inside Halo‑IQ per analysis run)
Evidence Normalisation TrueState™ Determination Protection

Halo‑IQ separates evidence from declarations, normalises it into TrueState™, and produces explainable determinations with a contemporaneous record of what Halo knew, what Halo decided, and why.

The answers already exist.

When a business needs to understand its protection position, the most important questions eventually reach the people who actually know the answers. The broker doesn’t know. The CEO doesn’t know. The MSP knows.

They know which controls are deployed.
They know whether MFA is operating.
They know which devices are protected.
They know what needs patching.
They know what vulnerabilities exist.
And increasingly, the technology can provide the evidence directly.

So why keep asking organisations to describe what their systems can prove? Halo‑IQ starts with the evidence.

Explore Halo‑IQ by audience

MSPs
Deliver a Halo‑enabled Cyber Protection Service — and turn protection gaps into clear remediation and growth opportunities.
Business Owners
Know what is true, what has changed, and what needs attention — with an auditable record of where you stood.
Technology Partners
Turn the signals your technology already produces into evidence that can drive real decisions — not just dashboards.
Insurance & Capacity
Deterministic, evidence‑backed decisions with provenance, reproducibility, and defensible audit trails.