What Underwriters Really See: From Application Pitfalls to Threat Intel with Heather Mongeau

Season 2 /
/Episode 33

What Underwriters Really See: From Application Pitfalls to Threat Intel with Heather Mongeau

In this episode of the Safe House Initiative, we’re joined by Heather Mongeau, VP and Director of Cyber Product Solutions at Allied World Insurance Company. Heather takes us deep into the world of cyber underwriting and its critical role.
 
She clarifies that cyber insurance is more than just financial aid post-incident; it’s about proactive risk management, including services like penetration testing and vulnerability assessments. Heather stresses the vital importance of accurately completing cyber insurance applications, especially for SMBs, and highlights how essential Multi-Factor Authentication (MFA) and other strong security controls are for securing coverage.
 
Key insights you’ll gain:
  • Underwriting is risk evaluation: It bridges the financial gap and enables business continuity.
  • Applications are complex: Accurate details and knowledgeable brokers are crucial to avoid coverage denials.
  • Security controls are prerequisites: Lack of MFA and other basics can lead to declined coverage.
  • Cyber incidents are inevitable: Preparation is key to minimizing damage and downtime.
  • Insurers offer more than just money: They provide valuable pre-breach risk management services and immediate access to incident response teams (“breach coaches”) during an attack.
 
Heather emphasizes that cyber insurance is an evolving field, urging businesses to partner closely with brokers and carriers to find tailored coverage. Don’t face cyber threats alone – leverage these resources to strengthen your security posture. What’s one security control your business uses that you think is absolutely crucial for cyber insurance? Let us know in the comments!
 
 

Protecting Rural America from Cyber Threats: Inside the PISCES Mission with Mike Hamilton

What happens when rural hospitals, public utilities, schools, and small governments become targets of cyberattacks but lack the resources to defend themselves?

In this episode of The SafeHouse Podcast, Jeff Edwards welcomes Mike Hamilton, former Seattle CISO and CTO of PISCES International, a nonprofit organization delivering free cybersecurity monitoring and real-world workforce training to underserved communities across the United States.

This conversation is based on a real-world, three-part series designed for everyday people who suddenly find themselves dealing with a hacked account, fraud, or a suspicious alert.

Read More »

What to Do If You Get Hacked: A Practical Survival Guide with Alan Gin

In this SafeHouse episode, Jeff Edwards and Alan Gin break down what actually happens when a cyber incident hits and what you should do next.

This conversation is based on a real-world, three-part series designed for everyday people who suddenly find themselves dealing with a hacked account, fraud, or a suspicious alert.

If you’ve ever wondered what you would actually do in that moment, this episode walks you through it step by step.

Read More »

Cyber Risk: Where Mitigation Meets Insurance With Michael Phillips

Cyber risk management is often framed as a choice between prevention and insurance. In reality, the most resilient organizations combine both.
In this episode of The SafeHouse, Jeff Edwards speaks with Michael Phillips, Global Head of Cyber at Coalition, about how insurers evaluate cyber risk and why mitigation and insurance must work together.

Building on a previous discussion about the elements of risk management, the conversation explores how underwriters think about cyber exposure, what signals insurers look for when assessing organizations, and why operational resilience is becoming central to modern cyber insurance.

The result is a practical discussion about how businesses should approach cyber risk today.

Read More »

Making Sense of Risk Management with Davis Hake

Cyber risk management is often discussed in technical language. But at its core, risk is financial.

In this episode of The SafeHouse Podcast, Jeff Edwards interviews Davis Hake of Venable to break down how cyber risk should be measured, communicated, and quantified inside organizations.

For CISOs, risk managers, brokers, underwriters, and resilience professionals, this episode provides a practical framework for thinking about cyber exposure beyond compliance checklists.

If you want to understand cyber risk in terms that boards and CFOs actually respond to, this conversation is essential listening.

Read More »

When Cybersecurity Became a State Responsibility with James Saunders

Federal cybersecurity responsibility has shifted to the states. What happens next?

In this episode of The SafeHouse Podcast, Jeff Edwards welcomes James Saunders, Chief Information Security Officer for the State of Maryland, for a deep conversation on state-level cybersecurity, resilience, and leadership.

James walks through his path from early technical support roles to federal cybersecurity leadership and now to protecting Maryland’s digital ecosystem. He explains Maryland’s IT Master Plan, the state’s five-pillar cybersecurity strategy, and how partnerships, talent, and resilience come together in practice.

This episode offers a behind-the-scenes look at how cybersecurity decisions are made at scale, how states collaborate with one another, and why taking care of people matters as much as taking care of systems.

Read More »