Cyber Insurance & Gap Coverage
Options For Your Business
A new way to look at cyber insurance coverage options based on definable, measurable metrics for determination of coverage.

Our Cyber Warranty Options
Protect Plus
• Annual Coverage Up to $100,000
• Instant Fund Access
• Covers Wire/ACH transfer losses
• 1x phishing or smishing payment
• Cyber insurance deductible gap coverage
Protect Premier
• Up to $500,000 claim limit per year
• Instant Fund Access
• Covers Wire/ACH transfer losses
• 3x phishing or smishing payment
• A portion of or all costs related to escalated incident response expenses, data recovery costs and business interruption loss
• A portion or all of the ransom payment to get encrypted data restored

What is a Cyber Warranty?
A Cyber Warranty helps prevent and remediate an incident before it happens. Just like purchasing a car warranty for the inevitable repairs your car will need to continue reliable operation, a Cyber Warranty fills the gap between a Cyber Insurance plan and no insurance whatsoever.
Cyber Attacks Continue to Rise
Malicious cyber attacks continue to increase at over a 50% rate year over year. In 2024, an attack occurs every 43 seconds in the United States.
Cyber Insurance Cost Increases
Our customers routinely see policy price increases of 100% year over year for Cyber Insurance. And there’s no guarantee the claim will be covered.
Inside Out Monitoring
Skip the extensive insurance questionnaires. Our unique approach to Cyber Warranty provides risk monitoring the inside out, to ensure an Always On warranty and Active Loss Prevention monitoring.
Protect Your Business
TorchLight Cyber Warranty provides peace of mind financial coverage, reduced out of pocket expenses and quantifies risk to provide data for accurate decision making.
Reduce Complexity. Increase Productivity.
And Make Your Systems Bulletproof.
Why TorchLight?
At TorchLight, our “why” is simple: we exist to serve our customers and protect them from the relentless threat of hackers. This mission drives everything we do, setting us apart in the Secured and Managed IT landscape.
We foster a culture of candor, transparency, service, proactive communication and a growth mindset, all aimed at supporting our clients’ needs. We seek trusted partnerships with organizations that share our values, prioritizing open dialogue and a win/win mindset.
Together, we ensure that IT security goals are not only met but exceeded, safeguarding business continuity every day. Our people are our greatest asset, unified by our mission to secure and serve our customers and frustrate the hackers.
Latest Insights & Blog
Expert insights on cybersecurity, compliance, and IT strategy.
-

FortiBleed: 73,000 Fortinet Firewalls Exposed, and What Every Organization Must Do Now
FortiBleed is one of the largest firewall credential leaks ever found: working VPN logins for 73,932 Fortinet firewalls across 21,600 organizations and 194 countries. Strong passwords did not stop it. See what the leak means for your sector and the steps to take in the next 24 hours.
-

How Ransomware Enters a Credit Union Network
Ransomware rarely breaks into a credit union through the servers. It enters through a person or a weak remote login, then moves laterally in about 29 minutes. This is the real entry chain behind the Akira attacks on Ellafi and MetroWest credit unions, and the controls that stop it.
-

Penetration Testing Cost: What to Expect in 2026
If you’ve been tasked with budgeting for a penetration test, or justifying the expense to leadership, you’ve probably already discovered that penetration testing cost isn’t as straightforward as a line item on a vendor’s website. Prices vary wildly, scope is rarely apples-to-apples, and the cheapest option is often the most expensive mistake you can make.…
-

What is a vCISO? Cost, Role, and When to Hire One
When businesses think about cybersecurity leadership, a Chief Information Security Officer (CISO) often comes to mind. However, hiring a full-time CISO may not be practical for every organization. A vCISO provides businesses with experienced cybersecurity services, leadership, strategy, and guidance on a flexible basis without the cost and commitment of a permanent executive hire. A…
-

2026 Cyber Insurance Requirements
Cyber insurance changed. The questionnaire is now an audit, and the controls you check off are the ones you must prove were running when an attacker got in. Here is what shifted in 2026, why claims get denied over MFA, and what it means for credit unions, healthcare, RIAs, mid-market firms, and schools.
-

The LLMShare Attack: When a Trusted AI Link Becomes a Malware Delivery Truck
Attackers have found a way to deliver malware through pages hosted on the real ChatGPT and Claude domains, sailing straight past the security checks that trust those sites. The LLMShare attack is the latest evolution of ClickFix, and it matters whether you already run AI tools or are just deciding to.
-

Support Automation Is Great Until It Becomes an Attacker’s Help Desk: The Meta AI Instagram Exploit and What It Reveals
On June 1, hackers used Meta’s AI support chatbot to take over Instagram accounts belonging to the Obama White House, Sephora, and the Chief Master Sergeant of Space Force. The architecture problem behind it should worry every operator.
-

Why Device Logins Just Became a Liability
A new phishing technique has compromised more than 340 Microsoft 365 organizations since February 2026, and not one of them lost a password. Here is what credit unions, healthcare practices, and RIA firms need to ask their IT team this week, before an examiner does.
-

How Credit Unions Can Stay Audit-Ready Using Outsourced IT Managed Services
How Credit Unions Can Stay Audit-Ready Using Outsourced IT Managed Services Every credit union leader knows the feeling: an NCUA exam is approaching, and the scramble begins, pulling together logs, chasing down documentation, trying to prove that controls are actually in place. It’s stressful, expensive, and entirely avoidable. The root problem is almost always the…
-

Three Days to Patch a 10.0: What The Cisco SD-WAN Vulnerability Says About Every Network in 2026
Two critical ScreenConnect vulnerabilities, including a CVSS 9.0 flaw under active exploitation by nation-state actors, have opened a direct tunnel into the networks of banks, RIAs, and healthcare practices. The federal patch deadline is May 12, 2026. Here’s what to check, what to hunt for, and how to close the door before examiners or attackers…
