Cyber Insurance & Gap Coverage
Options For Your Business
A new way to look at cyber insurance coverage options based on definable, measurable metrics for determination of coverage.

Our Cyber Warranty Options
Protect Plus
• Annual Coverage Up to $100,000
• Instant Fund Access
• Covers Wire/ACH transfer losses
• 1x phishing or smishing payment
• Cyber insurance deductible gap coverage
Protect Premier
• Up to $500,000 claim limit per year
• Instant Fund Access
• Covers Wire/ACH transfer losses
• 3x phishing or smishing payment
• A portion of or all costs related to escalated incident response expenses, data recovery costs and business interruption loss
• A portion or all of the ransom payment to get encrypted data restored

What is a Cyber Warranty?
A Cyber Warranty helps prevent and remediate an incident before it happens. Just like purchasing a car warranty for the inevitable repairs your car will need to continue reliable operation, a Cyber Warranty fills the gap between a Cyber Insurance plan and no insurance whatsoever.
Cyber Attacks Continue to Rise
Malicious cyber attacks continue to increase at over a 50% rate year over year. In 2024, an attack occurs every 43 seconds in the United States.
Cyber Insurance Cost Increases
Our customers routinely see policy price increases of 100% year over year for Cyber Insurance. And there’s no guarantee the claim will be covered.
Inside Out Monitoring
Skip the extensive insurance questionnaires. Our unique approach to Cyber Warranty provides risk monitoring the inside out, to ensure an Always On warranty and Active Loss Prevention monitoring.
Protect Your Business
TorchLight Cyber Warranty provides peace of mind financial coverage, reduced out of pocket expenses and quantifies risk to provide data for accurate decision making.
Reduce Complexity. Increase Productivity.
And Make Your Systems Bulletproof.
Why TorchLight?
At TorchLight, our “why” is simple: we exist to serve our customers and protect them from the relentless threat of hackers. This mission drives everything we do, setting us apart in the Secured and Managed IT landscape.
We foster a culture of candor, transparency, service, proactive communication and a growth mindset, all aimed at supporting our clients’ needs. We seek trusted partnerships with organizations that share our values, prioritizing open dialogue and a win/win mindset.
Together, we ensure that IT security goals are not only met but exceeded, safeguarding business continuity every day. Our people are our greatest asset, unified by our mission to secure and serve our customers and frustrate the hackers.
Latest Insights & Blog
Expert insights on cybersecurity, compliance, and IT strategy.
-

Canvas Breach Update: Reports Set to Resume for California’s 116 Community Colleges
The April-May 2026 Canvas breach put student data at all 116 California community colleges in scope. Instructure paused detailed breach reports over a ShareFile threat that has since cleared. Here’s what was exposed, what California’s breach-notification law actually requires, and the four steps to take this week.
-

How the SharePoint Chain Broke on July 14, 2026: CVE-2026-56164, End-of-Support, and What Every On-Prem Operator Should Do This Week
On July 14, 2026, Microsoft patched an actively exploited SharePoint zero-day (CVE-2026-56164), CISA added it to the Known Exploited Vulnerabilities catalog with a 72-hour federal deadline, and support for SharePoint Server 2016 and 2019 officially ended. Three events, one date. Here is what every on-premises operator should do this week.
-

Business Email Compromise at Credit Unions: How Attackers Redirect Wire Payments and What Stops Them
Business email compromise costs U.S. organizations billions each year, and credit unions are prime targets. Here is how attackers redirect wire and ACH payments, the four most common scenarios, and the layered controls (DMARC, out-of-band verification, and staff training) that actually stop them.
-

CMMC Phase II Suspended: What It Means and What to Do Next
On July 13, 2026, the Department of War suspended CMMC Phase II, removing the November 2026 third-party audit deadline. But DFARS 252.204-7012, NIST SP 800-171, and your SPRS self-attestation all still apply. This is schedule relief, not scope relief, and here is what defense contractors should do during the pause.
-

MSP vs MSSP: Which Does Your Business Actually Need? (2026)
Choosing between an MSP and an MSSP is becoming increasingly difficult as cyber threats grow more sophisticated and compliance requirements become more demanding. Many businesses invest in outsourced IT services expecting comprehensive protection, only to discover later that traditional IT support doesn’t necessarily include proactive cybersecurity. If you’re comparing MSP vs MSSP, understanding the difference…
-

What Is a Fractional vCISO? And Does a Credit Union Under $500M Actually Need One?
A fractional vCISO gives credit unions under $500 million the strategic security leadership of a full-time CISO, part-time and at a fraction of the cost. Here is what a vCISO actually does, how it differs from a vCIO, what NCUA examiners expect, what engagements cost, and how to tell if your credit union needs one.
-

Tempel Steel Data Breach Settlement: Incident Response Lessons for 2026
Tempel Steel confirmed its breach on March 25, 2025. Twenty days later it was named in a class action, and by 2026 it faced up to $175,000 in fees plus multi-year liability, for just 5,192 employee records. Here’s what the settlement teaches financial, healthcare, and education IT leaders about response timelines.
-
The Biggest 4th of July Breach in History & the Real Cybersecurity Lessons Behind It
The biggest 4th of July breach in history took out an entire invading fleet with a single upload. The twist is that it happened in the 1996 movie Independence Day. The aliens still lost for real reasons though: no network segmentation, blind trust, and an unsigned payload. Those are the lessons worth bringing to your…
-

Vendor Risk Management for Credit Unions: What the NCUA Expects
Credit unions rely on third-party vendors for services such as digital banking, cloud platforms, payment processing, and fintech solutions. While these partnerships improve efficiency and member experiences, they also introduce cybersecurity, compliance, operational, and reputational risks that require careful oversight. As a result, vendor risk management for credit unions remains a key focus during NCUA…
-

FortiBleed: 73,000 Fortinet Firewalls Exposed, and What Every Organization Must Do Now
FortiBleed is one of the largest firewall credential leaks ever found: working VPN logins for 73,932 Fortinet firewalls across 21,600 organizations and 194 countries. Strong passwords did not stop it. See what the leak means for your sector and the steps to take in the next 24 hours.
