Fig Group logo

Fig Group

GRC and compliance platform for managed service providers with embedded cyber insurance intelligence.

Compliance & Regulatory Startup Bootstrapped
Visit Website

Overview

Fig Group is a governance, risk, and compliance (GRC) platform for managed service providers, managed security service providers, and corporate risk teams, with an embedded cyber insurance module tied to underwriting. The London-based platform brings compliance monitoring, assurance, and insurance reporting into one working environment, feeding continuous compliance evidence directly into premium and underwriting decisions for cyber, professional indemnity, directors and officers, and crime coverage.

The platform maps 65+ compliance frameworks, including Cyber Essentials, ISO 27001, NIS2, DORA, and GDPR, connects to 300+ third-party integrations across common cloud and security tools, and deploys within 48 hours with no onboarding fees. Compliance and vulnerability data collected on the platform feeds the embedded insurance module, where verified improvements in security posture are meant to lower premiums and speed claims handling rather than waiting for periodic manual reassessment.

Fig Group also operates as an IASME-licensed certification body for Cyber Essentials, Cyber Essentials Plus, and Defence Cyber Certification, offering Cyber Essentials assessments from GBP 299.99 plus VAT with a 6-hour turnaround guarantee and a reported 100% pass rate on compliant submissions. Every certificate issued includes GBP 25,000 of bundled cyber liability insurance. The company was incorporated in November 2025 and is bootstrapped, with no external funding identified.

Products & Services

Resilience Platform

The core platform organizes governance, risk, and compliance activity across five phases: Discover (asset and data discovery, configuration drift detection), Protect (vulnerability scanning, third-party risk monitoring, business continuity planning), Respond (incident management with regulatory notification tracking), Prove (compliance automation across 65+ frameworks, policy management, audit evidence), and Insure (the embedded insurance module).

Key Features

  • Mapping across 65+ compliance frameworks, including Cyber Essentials, ISO 27001, NIS2, DORA, and GDPR
  • Automated evidence collection and audit-ready workflows
  • 300+ integrations with no per-integration fees, including Microsoft 365, Google Workspace, AWS, and Azure
  • AI-assisted risk scoring and automated remediation workflows
  • Multi-tenant architecture with role-based access control and single sign-on
  • Deployment within 48 hours with no onboarding fees

Target Users: MSPs offering compliance-as-a-service to their own clients; corporate risk and compliance teams managing multi-framework obligations

Embedded Insurance

Fig's insurance module feeds continuous compliance and vulnerability data from the platform into underwriting for cyber, professional indemnity, directors and officers, and crime coverage. Premiums are calculated from live compliance posture rather than point-in-time assessments, so verified security improvements can lower premiums between renewals. Pre-documented incident evidence collected on the platform is intended to shorten claims processing from weeks to days. Fig states it does not sell, underwrite, or broker insurance directly; the module is enabled through insurance partnerships the company has not named publicly.

Key Features

  • Premiums tied to continuous compliance and vulnerability metrics rather than periodic reassessment
  • Single compliance data feed supporting multiple coverage lines
  • Pre-documented incident evidence to speed claims handling
  • Four-step onboarding: ownership assignment, source-system connection, framework mapping, pre-audit review

Target Users: Organizations seeking measurable insurance terms tied to compliance improvements

Cyber Essentials Certification

As an IASME-licensed certification body, Fig issues Cyber Essentials, Cyber Essentials Plus, and Defence Cyber Certification (DCC) assessments directly to organizations:

Key Features

  • Cyber Essentials: self-assessment from GBP 299.99 plus VAT, with a 6-hour turnaround guarantee
  • Cyber Essentials Plus: technical audit and vulnerability testing from GBP 1,499 plus VAT
  • DCC Level 0: documentation review from GBP 999.99
  • DCC Level 1: consultant-led assessment from GBP 9,999

At a Glance

Founded
2025
Headquarters
London, England, UK
Employees
1-10
Funding
Bootstrapped

Category & Focus

Category
Compliance & Regulatory
Subcategories
Compliance Automation Risk Monitoring Embedded Insurance Cyber Certification
Insurance Verticals
Specialty/E&S
Target Customers
Managed Service Providers, Managed Security Service Providers, Corporate Risk Teams

Customers

  • Liberty Towers Ltd

Last updated: 2026-08-03