For cyber-insurance brokers

Fix externally visible security issues before cyber renewal.

A managed external security assessment for insurance brokers. We identify issues on one client's public-facing domain, manage remediation follow-up with their MSP, confirm externally detectable fixes through a rescan, and deliver a co-branded summary before renewal.

Founding pilot, one client for $149. No ongoing commitment.

Written client authorization No credentials required No internal access One domain Manually reviewed
acmeltd.comExternal Security Remediation Summary
Remediation underway
  • DMARC policy set to monitoring only
  • TLS certificate expires in 14 days
  • Vulnerable client-side library detected
  • Missing HSTS header — accepted for review
MSP follow-up: in progress Rescan: Aug 1, 2026

Why external issues become a broker's problem

External issues surface too late

Publicly visible configuration problems can be discovered during underwriting, after the renewal process has already started.

Brokers become the coordinator

When an issue is flagged, the broker gets stuck between the client, the MSP, and the underwriting process.

Free scores don't manage remediation

Generic scanners identify issues, but they don't manage remediation follow-up, confirm completion through a rescan, or provide a broker-facing summary.

We identify externally visible issues, manage follow-up directly with the client's MSP, and confirm externally detectable fixes through a rescan, so you are not stuck coordinating between the client, their IT provider, and underwriting.

Where a client uses an MSP, we work with them directly on fixing what we find — you're not the go-between.

How it works

Test it on one upcoming renewal.

Run manually during this pilot — not yet a self-serve platform.

What we check

Headers, TLS/certificate health, SPF/DMARC, exposed-file patterns, vulnerable JS libraries, CORS, and subdomain discovery.

What we handle for you

We translate findings into specific actions for the client's MSP, manage follow-up, confirm externally detectable fixes with one rescan, and hand you a consistent summary — so you're not the one chasing status updates.

How your renewal will be summarized

Sample data — the format your completed summary follows.

Acme Ltd — External Security Remediation Summary
Assessment date: Jul 14, 2026 · Scope: acmeltd.com (domain-based external security assessment)
Remediation underway
FindingSeverityStatus
DMARC policy set to monitoring onlyMediumMSP action pending
TLS certificate expires in 14 daysMediumRenewal scheduled
Detectable client-side library with a known vulnerabilityLowMSP action pending
Missing HSTS headerLowAccepted for review

Remediation status

0 of 4 items resolved; remediation is underway with the client's MSP

Rescan status

Scheduled once remaining items are addressed

Who runs this assessment

Operated by Pepaco Group LLC, trading as Tessera Cyber. All findings are manually reviewed before delivery using a documented external-assessment methodology. Assessments require written client authorization and are limited to the agreed domain and checks. Full details are in the Methodology and Privacy Notice, linked in the footer below; pilot terms are agreed directly with each broker.

The pilot offer

Assess Remediate Rescan Report
Founding pilot — start here
$149

Single Renewal Pilot — one client, one external security assessment, remediation follow-up with their MSP, one rescan, and one co-branded External Security Remediation Summary. No ongoing commitment.

  • External security assessment for 1 client
  • We manage remediation follow-up directly with the client's IT provider or MSP — not you
  • Tracked through to one rescan
  • Co-branded External Security Remediation Summary
Start the one-client pilot — $149

Scoped to: one domain, one external assessment, one remediation coordination round with the client's MSP, and one rescan, delivered within 21 days. Remediation implementation itself isn't included — that stays with the client's MSP.

If it's useful: continue with four additional clients for $350 after reviewing the first summary.

ClientRenewalStatusPriority findingsAction
Acme LtdAug 24Action required3Review
Nova IncSep 12Remediation underway1Rescan
Delta CoSep 30Assessment complete0Export

Future service and platform pricing will be determined after the pilot.

Scope

This is a domain-based, non-intrusive external security assessment — not a penetration test, internal-controls audit, or certification. It does not access internal systems and does not evaluate internal controls such as MFA, backups, or endpoint protection — only what's already publicly visible about the domain. It is not an underwriting report or a guarantee of coverage or pricing. Full methodology and the authorization process are covered in the pilot agreement.

Frequently asked questions

Does this guarantee a client's renewal gets approved, or a better premium?

No. It identifies publicly visible security issues that may surface during underwriting or an insurer's external assessment. It does not complete the client's internal-control application questions, and underwriting decisions and pricing remain entirely the insurer's.

Does this cover internal controls like MFA or backups?

Not in this pilot. It's scoped to externally visible risks only — the internal-controls side of a renewal application stays with the client and their IT provider.

How is this different from SecurityScorecard or UpGuard?

Security-rating platforms provide external posture data and monitoring. This pilot is a hands-on, renewal-specific service: we review one client's findings, translate them into MSP actions, manage follow-up, confirm completed fixes through a rescan, and return a co-branded broker summary.

Is this available for MSPs?

This pilot is scoped to brokers. If an MSP handles remediation for one of your clients, reply and we'll manage the follow-up with them directly.

The pilot is limited to a few brokers

Tell us about your firm and we'll follow up to schedule the pilot.