HDI Global Cyber Services - Digital Magazine

Improve your Cybersecurity HDI Global's "Cyber as a Service" approach provides comprehensive protection through innovative three sectors. Discover how Cyber Services can safeguard your digital future. HDI Global Cyber Services

2 | Contents 03 Protect your business with comprehensive Cybersecurity 04 Your three-sector Cyber Service selection 23 Ready to strengthen your Cybersecurity? 24 HDI Global SE – Your trusted partner in Cyber resilience 20 Why HDI Global as your Cybersecurity Partner? 14 Sector 3: Incident Response & Monitoring 08 Sector 2: Risk Mitigation 05 Sector 1: Risk Analysis Contents WHY HDI GLOBAL SERVICES PARTNER CONTACT

Effective Cybersecurity must safeguard confidentiality by ensuring data remains private and accessible only to authorised personnel, integrity by maintaining data accuracy as well as preventing unauthorised modifications, and also availability by keeping systems and data accessible when needed. HDI Global provides comprehensive Cybersecurity protection through the "Cyber as a Service" approach, a comprehensive Cyber Service designed to protect your business beyond traditional insurance coverage. HDI Global provides own Cyber Risk Engineers and access to a broader Cyber partner network. Protect your business with comprehensive Cybersecurity Cyber threats have become a business reality that no organisation can ignore. With global Cyber incidents costing billions annually and attack methods growing more sophisticated, organisations need comprehensive protection strategies that go beyond traditional security measures. 3 | Services WHY HDI GLOBAL SERVICES PARTNER CONTACT

4 | Services Your three-sector Cyber Service selection HDI Global’s approach recognises that effective Cybersecurity follows a process with three different sectors. 1. Risk Analysis  Risk Assessment + Rent-a-Risk-Engineer + Risk Dialogue incl. report + Risk Dialogue Light excl. report (with note) 2. Risk Mitigation + Value Added Service network (VAS) + Live-Attack Simulation + 1:1 Support + Attack-Centric Cybersecurity Strategy + Extended Vulnerability Analysis (EVA) 3. Incident Response & Monitoring  Welcome Package  Threat Alerts + BitSight Monitoring and Report + Incident Response Management Onboarding + Incident Response Plan Review + Readiness Workshop  Included + Optional WHY HDI GLOBAL SERVICES PARTNER CONTACT

Sector 1: Risk Analysis Building your Cybersecurity foundation pre and post contract closing HDI Global’s Cyber Risk Engineering specialists work with you to establish a strong Cybersecurity foundation and assess your current Cyber maturity level. This preparatory phase checks if you are ready for Cyber insurance and identifies gaps and solutions for improvement. In addition to the Risk Assessment, you have further optional possibilities: Rent-a-RiskEngineer Flexible specialist support for specific challenges. Risk Assessment Comprehensive evaluation of your current security maturity level based on completed questionnaire. Risk Dialogue incl. report Detailed analysis with actionable recommendations also without any questionnaire. Risk Dialogue Light excl. report Quick assessment to clarify questions based on completed questionnaire.  Included + Optional 5 | Services | Risk Analysis WHY HDI GLOBAL SERVICES PARTNER CONTACT

A risk assessment/desktop analysis is conducted based on a questionnaire. This may be supplemented by existing information or by additional research (e.g. OSINT). Various small support activites that require, or would benefit from, the use of a Cyber Risk Engineer. Timeframe: Time it takes to fill in the questionnaire Timeframe: Up to one hour Benefit: The risk assessment is designed to give an accurate idea of the Cyber maturity of a given organisation and covers both organisational and technical aspects. You will receive a brief report and an overview of your current Cyber maturity level. Benefit: Direct, dedicated digital support from a Risk Engineer that covers both technical and organisational topics. Rent-a-Risk-Engineer Risk Assessment Sector 1: Risk Analysis  Included + Optional 6 | Services | Risk Analysis WHY HDI GLOBAL SERVICES PARTNER CONTACT

A Risk Engineer will lead a Risk Dialogue with you. Following this detailed dialogue and subsequent processing of the information obtained, a comprehensive risk report will be produced. Similar to a Risk Dialogue but less formal in nature, this dialogue seeks to clarify open questions concerning risks while also answering any questions you might have. Opportunity to present support possibilities. A small note will be written following the dialogue. Timeframe: Two to four hours Timeframe: Up to two hours Benefit: A detailed picture of the client's Cyber maturity can be made; all HDI Global questions should be able to be answered in this format. The report documents this information for distribution to you and other insurers. Benefit: A detailed picture of your Cyber maturity can be made and most of HDI Global's questions should be able to be answered. Risk Dialogue incl. report Risk Dialogue Light excl. report (with note)  Included + Optional 7 | Services | Risk Analysis WHY HDI GLOBAL SERVICES PARTNER CONTACT

Sector 2: Risk Mitigation Strengthening your defences during and after policy inception HDI Global’s Cyber Service team provides ongoing risk mitigation measures that strengthen your Cybersecurity maturity level and demonstrate your commitment to Cyber resilience. The following services are optional and can be selected individually to help with insurability whilst building robust defences: 1:1 Support Direct Cyber Risk Engineering coaching and support. Value Added Service network Access to a large, preselected HDI Global Cyber partner network to close specific gaps. Live-Attack Simulation Demonstration of a real phishing scenario from the attacker's point of view.  Included + Optional WHY HDI GLOBAL SERVICES PARTNER CONTACT 8 | Services | Risk Mitigation

Extended Vulnerability Analysis Detect internal vulnerable systems and IT services incl. detailed report. Attack-Centric Cybersecurity Strategy Proactive defences focused on tactics, techniques and procedures (TTPs).  Included + Optional 9 | Services | Risk Mitigation WHY HDI GLOBAL SERVICES PARTNER CONTACT

Access to various network partners with different qualitychecked IT providers and manufacturers. Largely pre-negotiated conditions and/or time availabilities. Range of services from major projects such as network segmentation or SOC implementation to awareness and MFA solutions as well as to cost-effective active directory and darknet scans. HDI Global also offers consulting services on incident response topics and/or certifications and compliance requirements such as NIS2 in addition to many more services. Timeframe: Depending on the service Benefit: There are more than a dozen services from specialist partners that are of great benefit to companies as preventative measures. These include the securing of access to IT systems, the implementation of early warning systems, emergency management and stress tests. The overall aim of the services is to help you shield yourself against Cyber risks and fulfil the required IT maturity level and the minimum requirements for Cyber insurance. Value Added Service network (VAS) Sector 2: Risk Mitigation Group size: Five to 50 participants. Digital and/or on-location simulation of a phishing attack with phishing tests and live phishing attempt on a testing environment. Scenarios: one on-premise and one cloud phishing attempt in one session. Timeframe: Two hours Benefit: You will get a better understanding of how a hacker attack works. By highlighting both perspectives (hacker and targeted party), risk awareness in relation to phishing attacks is heightened. This also highlights the IT systems that are activated during such an attack. Live-Attack Simulation  Included + Optional 10 | Services | Risk Mitigation WHY HDI GLOBAL SERVICES PARTNER CONTACT

HDI Global's 1:1 Support is an innovative approach with the aim of improving Cybersecurity in the medium term by coaching IT & OT management. The concept pursues the approach of providing customised and resource-oriented improvement solutions and being a valuable source of information on general IT and OT issues. Building on the HDI Global's 1:1 Support initial Workshop, a closely coordinated catalogue of measures is developed with the aim of achieving significant and sustainable improvements in Cybersecurity within six to nine months. At the centre of all efforts are solutions that are precisely tailored to the industry-specific requirements, the size of your company and the available internal resources. The continuous support provided by HDI Global's 1:1 Support ensures a very high level of client satisfaction with a particular focus on short-term improvement measures. Timeframe: Six to nine months Benefit: HDI Global's 1:1 Support provides targeted assistance and tips based on expertise and industry knowledge. At the same time, this service provides you with support to achieve improved Cyber resilience. Additionally, you get a better understanding of the IT & OT maturity level through regular exchange as part of the HDI Global's 1:1 Support, subsequently reducing the effort involved in future Risk Dialogues. This process is supported by HDI Global's Cyber QuickWin FactSheets, which provide solution outlines to many questions in IT & OT security. In addition, with the Advanced Trust approach, you can immediately become eligible for subscription or better conditions can be determined. 1:1 Support  Included + Optional 11 | Services | Risk Mitigation WHY HDI GLOBAL SERVICES PARTNER CONTACT

Sector 2: Risk Mitigation Stay ahead of Cyber threats with an attackcentric strategy. Cyber attackers are constantly evolving, so your defenses need to stay one step ahead. The most effective way to do this is by understanding how attackers operate, meaning their tactics, techniques, and procedures (TTPs). An Attack-Centric approach, powered by frameworks like MITRE ATT&CK and the Intrusion Kill Chain helps you move from reactive to proactive: • Identify and close critical security gaps • Strengthen defenses across every stage of an attack • Make breaches harder, slower, and far less likely Timeframe: Three to five days Benefit: • Proactive protection: Anticipate and disrupt attacks before they succeed. • Faster detection & response: Reduce dwell time and limit damage. • Stronger resilience: Layered defenses make breaches harder and more costly for attackers. • Business alignment: Security investments tied to real-world threats, not checklists. Attack-Centric Cybersecurity Strategy  Included + Optional 12 | Services | Risk Mitigation WHY HDI GLOBAL SERVICES PARTNER CONTACT

Simulate real-world threats, strengthen your defenses Cyber attackers often gain entry through phishing or misconfigurations – and once inside, they move fast. Our Extended Vulnerability Analysis (EVA) service helps you stay ahead by simulating these real-world scenarios and uncovering hidden risks before attackers do. We focus on two critical areas: Assume breach scenario: Starting from a simulated phishing compromise, we identify misconfigurations, escalate privileges, and test lateral movement – just like an attacker would. Azure & Entra ID review: We assess your cloud identity and access controls, validate conditional access policies, and test monitoring and logging capabilities to ensure your cloud environment is secure. Timeframe: Five days Benefit: • Realistic testing: Simulate real-world attack scenarios to uncover hidden risks. • Actionable insights: Clear, prioritised recommendations to close critical gaps. • Improved security posture: Reduce your attack surface across on-premise and cloud environments. • Compliance & confidence: Validate identity, access, and monitoring controls against best practices. • Financial advantage: Stronger security can lead to better insurance terms and lower premiums. Extended Vulnerability Analysis (EVA)  Included + Optional 13 | Services | Risk Mitigation WHY HDI GLOBAL SERVICES PARTNER CONTACT

Sector 3: Incident Response & Monitoring Comprehensive protection post policy inception HDI Global's Incident Response & Monitoring solutions provide ongoing support and immediate response capabilities. These services assist business continuity and help you respond effectively when incidents occur: Welcome Package Information package about your 24/7 Incident Manager and claims handling. Threat Alerts Real-time intelligence feeds and notifications. BitSight monitoring and report Continuous risk monitoring and reporting.  Included + Optional 14 | Services | Incident Response & Monitoring WHY HDI GLOBAL SERVICES PARTNER CONTACT

Incident Response Management Onboarding First touch to your external 24/7 Incident Manager. Readiness Workshop Incident response preparation with external 24/7 Incident Manager and forensic partner. Incident Response Plan Review Feedback and support for improvement to your existing Incident Response Plan.  Included + Optional 15 | Services | Incident Response & Monitoring WHY HDI GLOBAL SERVICES PARTNER CONTACT

Sector 3: Incident Response & Monitoring In addition to the insurance documents, you will receive a detailed Welcome Package by email, which is customised to the formalities typical of the country in question. In addition to the 24/7 hotline, the Welcome Package includes all other important documents so that you can contact and involve the Incident Response Manager mentioned above without any problems in the event of a claim. Timeframe: One mail Benefit: You will be informed in advance of all important emergency numbers and contact details. You will also receive important documents that should also form part of your Incident Response Plan. This enables you to act professionally and efficiently in the event of an incident. However, we also recommend booking the Readiness Workshop or at least a short Onboarding if Crawford & Company is the responsible Incident Manager. Welcome Package If you and your brokers are willing to share your contact details for this service, you will receive information regarding the most critical vulnerabilites from an HDI Global perspective (frequency is reasonable – not "just" all CVSS > 9) Timeframe: One mail Benefit: You will receive an impression of the vulnerabilities focused on by HDI Global to help prioritise mitigation of cyber threats. Threat Alerts  Included + Optional 16 | Services | Incident Response & Monitoring WHY HDI GLOBAL SERVICES PARTNER CONTACT

BitSight is a Cybersecurity ratings platform that assesses an organisation's security by analysing external data such as vulnerabilities, incidents, and third-party risks associated with the organisation. It provides a score that can be used to benchmark, compare, and monitor security performance over time. Additional risk information and reports can be sent to you. Timeframe: You have access for 60 days Benefit: The benefits of BitSight are its data-driven approach, allowing for an objective view of your external Cyber risk. This offers you an extended view. The detailed reports and access to the platform provide you with valuable information about your company's vulnerabilities and optimisation potentials. BitSight Monitoring and Report  Included + Optional 17 | Services | Incident Response & Monitoring WHY HDI GLOBAL SERVICES PARTNER CONTACT

Sector 3: Incident Response & Monitoring Onboarding with Crawford & Company. Clarification of the most important processes and procedures relating to the topic of "Incident Response Management". In particular, clarification of how cooperation with existing IT service providers works and under what circumstances and conditions external service providers are called in. Feedback and support for improvement to the existing Incident Response Plan Timeframe: Up to one hour Timeframe: One day Benefit: You will become acquainted with Crawford & Company before a potential incident occurs. This allows the most important processes, procedures and questions to be clarified. Benefit: You will get feedback on your existing Incident Reponse Plan and receive suggestions for improvements in this regard. The review is not carried out on a legal basis, but on the basis of possible practical implementation in the event of damage. Incident Response Management Onboarding Incident Response Plan Review  Included + Optional 18 | Services | Incident Response & Monitoring WHY HDI GLOBAL SERVICES PARTNER CONTACT

Workshop together with HDI Global, Crawford & Company and their forensic network partner. You will go through a realistic scenario that could lead to data theft and business interruptions: Full encryption as a result of a ransomware incident is played out. Together with Crawford & Company as Incident Manager and a forensic expert from their partner network, all processes relating to the cyber attack are clarified and synchronised with your stakeholders. This allows the processes and reactions in the event of a Cyber attack to be optimised in order to sustainably limit any operational impact. Timeframe: Up to four hours Benefit: You will receive detailed insight into the processes in case of an incident. This allows your current IT teams and the Incident Response Manager to be synchronised with each other. Good preparation for the incident is likely to greatly limit the extent of the damage. In addition, the included workshop component "Incident Response Plan Review" provides important support for you to improve your resilience in case of an incident. Readiness Workshop  Included + Optional 19 | Services | Incident Response & Monitoring WHY HDI GLOBAL SERVICES PARTNER CONTACT

20 | Why HDI Global Why HDI Global as your Cybersecurity Partner? WHY HDI GLOBAL SERVICES PARTNER CONTACT

21 | Why HDI Global HDI Global's Cyber Services extend beyond traditional risk transfer, offering comprehensive Cybersecurity solutions that improve your defence capabilities from within your organisation. Industrial insurance expertise As a leading industrial lines insurer, HDI Global understands the specific Cyber risks facing SMEs, industrial companies and corporate clients. HDI Global delivers insurance solutions specifically tailored to industrial requirements and risk profiles. Proven Cyber Risk Engineering capabilities With decades of experience in risk management, HDI Global understands the evolving threat landscape and regulatory requirements. HDI Global's Cyber Risk Engineering team provides expert analysis to help companies significantly reduce their Cyber risks before they become targets of an attack. Global specialist network HDI Global works with specialist external service providers who have been carefully selected and vetted to deliver world-class Cyber Security Services. This partner network enables HDI Global to offer comprehensive solutions across all aspects of Cyber risk management. Why HDI Global as your Cybersecurity Partner? HDI Global works together with you to increase your resilience in the digital world. The key to this is bolstering prevention within your in a continuous risk dialogue with HDI Global's Cyber Risk Engineering experts. WHY HDI GLOBAL SERVICES PARTNER CONTACT

Continuous risk improvement HDI Global focusses on risk quality improvement through regular effectiveness reviews and adaptation to emerging threats. HDI Global's approach aims to make companies and their Cyber risks insurable whilst enhancing resilience within their core activities. 22 | Why HDI Global WHY HDI GLOBAL SERVICES PARTNER CONTACT

23 | Partner Ready to strengthen your Cybersecurity? Don't face Cyber threats with incomplete protection. Let HDI Global's Cybersecurity network partners enhance your comprehensive security strategy, coordinate the appropriate specialists for each component, and provide ongoing support to keep your business secure. Below, you will find a selection of preferred partners that HDI Global is currently working with: WHY HDI GLOBAL SERVICES PARTNER CONTACT

HDI Global SE – Your trusted partner in Cyber resilience With over 120 years of experience in industrial insurance, HDI Global delivers innovative solutions for modern business challenges. Scan the QR code to find your Cyber contact person. HDI Global offers comprehensive Cyber Services around the world across Europe, the Americas and Asia-Pacific. Our worldwide network of expert partners and dedicated Cyber Risk Engineering teams provide localised support whilst maintaining consistent global standards. Whether you're expanding into new markets or seeking to strengthen your existing Cyber defences, our international presence ensures you receive the same high-quality service and expertise wherever your business operates. 24 | Contact Details WHY HDI GLOBAL SERVICES PARTNER CONTACT

Your Partner in Transformation – HDI Cyber Insurance Cyber_VAS@hdi.global HDI Global SE HDI-Platz 1 30659 Hanover www.hdi.global Speak to us for further information and discover how our global Cyber Services can protect your worldwide. Contact our Cyber Risk Engineering team at: Cyber Risk Engineering www.hdi.global/services/cyber-risk-engineering The images in this document were generated using AI. Marketing document

RkJQdWJsaXNoZXIy MzE1MTgyMQ==