A practical technology reference

Technology explained for CFOs.

Understand what you are funding, the loss it helps reduce, and the evidence that shows it is working.

Reviewed October 10, 2026 · Published by SecureStepPartner

Start with the business question.

Each explanation covers the purpose, a manufacturing example, baseline protection, insurance considerations, and a documented incident. Product names are examples of how a control can be delivered.

Public websites and portals

Cloudflare WAF

Screens requests to your website so suspicious traffic can be blocked before it reaches the application.

Read the business explanation
Remote staff and suppliers

Cloudflare Zero Trust

Checks who is connecting and, where configured, whether their device meets your rules before allowing access.

Read the business explanation
Private applications and internet access

Zscaler Zero Trust

Provides controlled connections to private applications and, through separate services, helps protect internet use.

Read the business explanation
Employee identity and permissions

Microsoft Entra ID

Manages work identities and sign-in rules for Microsoft 365 and connected applications.

Read the business explanation
Computers, servers and response

Microsoft Defender / EDR

Looks for suspicious activity on devices and gives responders tools to investigate and contain it.

Read the business explanation
Network boundaries and plant separation

Cisco firewalls

Controls connections between networks and can inspect traffic for threats, depending on the product and configuration.

Read the business explanation
Consistent security across sites

Cisco Meraki MX

Combines site networking and firewall functions with centralized cloud management.

Read the business explanation
Site networking and protection

UniFi gateways and firewalls

Provides network management and firewall capabilities; supported gateways also offer threat detection and prevention.

Read the business explanation
Productivity, identity and security licensing

Microsoft 365 licensing

Determines which Microsoft productivity, identity, device management and security capabilities the company can actually use.

Read the business explanation
Business continuity and ransomware recovery

Backup and recovery

Keeps recoverable copies of critical information and provides a tested way to restore operations after failure or attack.

Read the business explanation
Detection, investigation and response

SOC, SIEM and security monitoring

Collects security records, looks for suspicious activity and gives responders a process for investigation and escalation.

Read the business explanation
Known weaknesses and software maintenance

Patch and vulnerability management

Finds software weaknesses, prioritizes the ones attackers use and tracks repairs or approved exceptions.

Read the business explanation

Preparing for underwriting

What level will insurance ask for?

There is no universal revenue, employee-count, or policy-limit threshold that makes a named product mandatory. Requirements vary by insurer, business exposure, requested cover, and application. The levels below are this guide’s planning framework, not insurer ratings.

1. Establish the baseline
Know what is covered, enforce the control, assign an owner, and record exceptions. A purchased license is only the beginning.
2. Prove it operates
Produce current coverage reports, access reviews, update records, and alert response evidence. Include suppliers and older systems.
3. Match the consequence
Where a failure could stop production or payments, discuss stronger authentication, tighter separation, response outside office hours, and tested recovery with IT and the broker.

The public CRC application is one example: it asks where MFA is enforced, whether EDR covers the environment, and which device protections are used. Its questions are useful evidence of underwriting scrutiny, not a universal checklist or a form to submit through this site. CRC: example cyber insurance application (PDF, broker reference).

An At-Bay underwriter recommends MFA and EDR and suggests considering managed response. At-Bay also emphasizes deployment and monitoring. These support evaluating how controls operate rather than assuming that a product purchase ensures favorable terms. At-Bay: an underwriter on MFA, EDR and MDR; At-Bay: why deployment and monitoring matter.

Before signing an applicationHave the accountable IT owner verify each technical answer and exception. Have the broker explain the insurer’s required scope and wording. Avoid describing a planned control as already implemented.

How these controls fit together

Identity controls decide who can sign in. Licensing determines which features are available. Zero trust services limit application access. EDR watches devices. Firewalls separate networks. A WAF screens public application traffic. Backups support recovery, patching reduces known exposure, and monitoring helps people detect and respond.

Staff training, payment verification, privacy governance and an incident plan still need owners. The topics here explain common technology proposals; they are not a complete security program.

Read the incident evidence carefully

We link to regulator findings, company disclosures and testimony. Where an incident illustrates a related control rather than a proven absence of the named product, we say so. A technology brand is not a guarantee against a breach.

Understand SOC 2 Type II, GDPR and California privacy
See who should own the work

Questions to take to your IT provider