FIRST WORD

Welcome to the first Steelbrook Brief.

We don't need another inbox full of generic tech tips, and you don't either. Each issue shows you what we're seeing in real client environments: risks that don't show up until someone looks, and decisions leaders need to make before a deadline forces them.

This month's theme is simple. What you believe about your IT and what's actually true are often different, and insurers, attackers, and Microsoft's pricing all notice the gap.

If something here hits close to home, reply. I read every one.

Chris Moore
Chief Vision Officer, Steelbrook Technology Group

Your Cyber Insurance Application Is A Signed Statement, Not A Questionnaire

Why it matters: When a CEO signs a cyber insurance application, the security answers become representations. If a claim investigation finds they weren't true, the insurer can void the policy. It doesn't have to deny just the claim.

The case to know: In 2022, Travelers rescinded a $1M cyber policy after a ransomware attack. The insured had attested to using MFA for admin access, but MFA was only on its firewall. The court declared the policy void from inception.

What we're seeing: Renewal applications now ask about specific controls. The ones that come up most:

  • Removing local admin rights from workstations

  • Retiring end-of-life hardware

  • Separating cameras and door-access systems from the business network

The catch: These take longer than the renewal calendar allows. At one client this quarter, removing admin rights required a pilot to test line-of-business software first. Network segmentation for cameras turned into a multi-month engineering project, not a checkbox.

What we did: Told the broker before renewal, in writing, with dated completion plans.

The bottom line: Disclosing a known gap is part of the negotiation. The same gap discovered after a breach can cost you the policy.

What We Find In The First 30 Days

When we take over an environment from another provider, the first month tells us what was actually being managed. Here is one recent onboarding: a mid-size construction-sector firm.

By the numbers:

  • ~6,000 → 3,234: Unique vulnerabilities, after one manual patch pass. No vulnerability management program existed.

  • 60% → 90%: Staff covered by endpoint protection.

  • 0 → 90%: Device inventory built. None existed.

  • Expired: The server backup platform's license.

  • 80% → 60%: Share of our hours spent on support tickets, mostly a backlog that predated us.

The hidden cost: Of the first 38 machines scanned, 15 were still running a design application whose perpetual licenses had been out of maintenance since 2023. That is licensing exposure nobody was tracking.

The takeaway: "Nothing's broken" is not the same as "it's managed." If your provider can't give you a device count, a vulnerability trend, and a backup verification date, you don't have a baseline.

Windows 10 Costs Double On October 13

What's happening: Year one of Microsoft's paid Extended Security Updates for business ends October 13. Year two costs $122 per device.

The trap: Coverage is cumulative. A business that skipped year one pays $183 per device to enroll now. The free consumer extension doesn't apply to company-managed PCs.

The business takeaway: Compare $122 to $244 to replacement, per machine, this month. Pay for ESU only on the devices you can't replace yet.

Renewal Readiness Check

Before you sign your next cyber insurance application, we'll compare your answers against what's actually deployed in your environment. That covers MFA, admin rights, backups, end-of-life devices, and network segmentation.

You get:

  • A plain-English list of any answers that don't match reality

  • A dated remediation plan you can hand to your broker

  • A Windows 10 device count with replace-vs-extend costs ahead of October 13

September 9, 1947: The first "bug" gets taped into a logbook

Operators working on Harvard's Mark II computer traced a malfunction to a moth trapped in a relay. They taped it into the logbook with the note "First actual case of bug being found." Grace Hopper, who worked on the team, made the story famous.

The twist: Engineers were already calling glitches "bugs," a usage that goes back at least to Thomas Edison. The joke was that this time it was literal. The logbook page, moth included, is now held by the Smithsonian.