Compliance & Insurance

Aligned to the frameworks
that matter to your stakeholders.

AnchorOne doesn't produce compliance as a separate project. The standard itself is the compliance posture — continuously active, continuously documented, continuously verifiable. Organizations operating inside AnchorOne inherit compliance. It is not assembled on request. It is the state the environment is always in.

When your carrier asks for documentation of your security controls — what do you hand them?

Aligned with the frameworks
your stakeholders recognize.

The AnchorOne standard addresses the technical requirements found in the frameworks and regulations your insurers, auditors, and regulators rely on.

NIST
NIST Cybersecurity Framework

Addresses identify, protect, detect, respond, and recover functions across the full environment.

CIS
CIS Controls

Prioritized security best practices from the Center for Internet Security — addressed at the baseline configuration level.

SOC 2
SOC 2 Trust Services

Technical controls aligned with availability, confidentiality, and security criteria for SOC 2 audit readiness.

FINRA
FINRA / SEC Guidelines

Controls addressing cybersecurity expectations for registered investment advisers and broker-dealers.

ABA
ABA Cybersecurity Guidance

American Bar Association cybersecurity guidance for law firms — addressed through identity, device, and data controls.

Ins.
Cyber Insurance Questionnaires

Every mandatory control required by leading cyber insurance carriers is documented and continuously active.

The standard remains
continuously verifiable.

These controls maintain the integrity of the AnchorOne environment and ensure the standard remains continuously verifiable — not assembled on request, but active at all times.

ControlPlatformScope
Multi-Factor AuthenticationEntra IDAll users — no exceptions
Conditional AccessEntra IDCompliant device and MFA minimum
Privileged Access ManagementEntra ID / PIMAll admin roles
Endpoint Detection & ResponseDefenderAll enrolled devices — block mode
Device EncryptionIntune / DefenderBitLocker, Secure Boot, TPM 2.0
Immutable BackupsM365 BackupDaily, tested quarterly
Unified Audit LoggingMicrosoft 365All workloads, retained per compliance
Data Loss PreventionMicrosoft 365Exchange, SharePoint, Teams
Incident Response PlanOperationsDocumented, reviewed annually
Start Here

See where your environment
stands right now.

The AnchorOne Score measures your current environment against the standard across all five domains — including the controls your insurer will ask about.