What Underwriters Really See: From Application Pitfalls to Threat Intel with Heather Mongeau

Season 2 /
/Episode 33

What Underwriters Really See: From Application Pitfalls to Threat Intel with Heather Mongeau

In this episode of the Safe House Initiative, we’re joined by Heather Mongeau, VP and Director of Cyber Product Solutions at Allied World Insurance Company. Heather takes us deep into the world of cyber underwriting and its critical role.
 
She clarifies that cyber insurance is more than just financial aid post-incident; it’s about proactive risk management, including services like penetration testing and vulnerability assessments. Heather stresses the vital importance of accurately completing cyber insurance applications, especially for SMBs, and highlights how essential Multi-Factor Authentication (MFA) and other strong security controls are for securing coverage.
 
Key insights you’ll gain:
  • Underwriting is risk evaluation: It bridges the financial gap and enables business continuity.
  • Applications are complex: Accurate details and knowledgeable brokers are crucial to avoid coverage denials.
  • Security controls are prerequisites: Lack of MFA and other basics can lead to declined coverage.
  • Cyber incidents are inevitable: Preparation is key to minimizing damage and downtime.
  • Insurers offer more than just money: They provide valuable pre-breach risk management services and immediate access to incident response teams (“breach coaches”) during an attack.
 
Heather emphasizes that cyber insurance is an evolving field, urging businesses to partner closely with brokers and carriers to find tailored coverage. Don’t face cyber threats alone – leverage these resources to strengthen your security posture. What’s one security control your business uses that you think is absolutely crucial for cyber insurance? Let us know in the comments!
 
 

Cybersecurity Frameworks Made Practical: From Confusion to Clarity

Ryan Ettridge, CEO of CyberCert, tackles a problem many organizations struggle with – cybersecurity frameworks that look good on paper but feel overwhelming or unusable in practice.
Ryan explains how AI-driven cyber certification can help organizations predict where risk is most likely to surface, prevent disruption before it becomes a claim, and protect both insureds and carriers by creating clear, defensible signals of cyber maturity.
Chart a clear path from path from compliance to real-world readiness with fundamentals covered in this episode.

Read More »

From Bootcamps to Battlefields: Keith Gologorsky on Modern Cyber Training

Keith Gologorsky, Head of Public Sector at Hack the Box, shares his personal journey from computer science graduate to government analyst, recounting pivotal moments in military operations, threat analysis, and international collaboration. The discussion explores the limitations of traditional certifications, the importance of hands-on training, and the need for regularly updated, gamified learning experiences. Keith also addresses the cybersecurity skills gap, the evolving role of AI, and offers actionable advice for organizations of all sizes: prioritize cross-training and real-world practice to build resilient teams.

Read More »

Cybersecurity and AI for Small Businesses: Expert Insights with Chuck Brooks

Cyber & AI authority Chuck Brooks joins Jeff Edwards to give SMBs a no-nonsense playbook. Learn how agentic AI turbocharges phishing, why unmanaged IoT/OT opens doors, and the exact first steps—MFA, segmentation, backups, IR plan—that raise your resilience fast. We also cover using NIST and CMMC as practical roadmaps and when to rely on an MSP.

Read More »