Obsidian Ridge

Cyber insurance

Real coverage, $0 deductible, attached to the security you actually run.

Eligible Obsidian Ridge clients running both Managed EDR and Managed ITDR can apply for the Huntress × Acrisure Cyber Insurance Program — placed through Acrisure, with a $0 deductible described for eligible applicants in the public program materials. The application is a Statement of Fact attesting to the managed detection and response we already operate for you, not a multi-page security questionnaire.

Are you eligible?

A 30-second self-sort before you keep reading.

The program is eligibility-gated — built around qualifying Huntress Managed EDR + ITDR coverage and Acrisure underwriting review. If you don't fit that path, use one of the linked alternatives below. We'd rather route you correctly than have you read 1,500 words about a program that excludes you.

Your profileRight next stepWhy
Running, or willing to onboard, qualifying Managed EDR + ITDRYou're on the right page. Keep reading.The public program materials tie access to qualifying Huntress EDR + ITDR coverage, with eligibility reviewed during application.
Not ready to run Managed EDR + ITDR yetCyber Insurance Readiness Sprint →The Sprint prepares your evidence packet for whichever traditional carrier you apply to, without depending on this specific program.
Unsure about industry, revenue, state, or entity fitTalk with us →Acrisure confirms applicant-specific eligibility; we help you gather the control evidence before you apply.
On a different EDR, won't swap from CrowdStrike / SentinelOne / DefenderMulti-vendor managed security →Program eligibility is contingent on this specific EDR + ITDR stack being live. Different stack → different insurance path, but we still operate yours.
Program structure
Broker: AcrisureUnderwriter: Dual North America (at launch)Security stack: Managed EDR + ITDRDeductible: $0
Obsidian Ridge — Huntress Secure PartnerCISSP-led practitioner program

Why this broker matters

Acrisure is the broker placing the policy.

Acrisure is the broker placing the policy — not a niche startup riding a vendor channel.

Huntress's May 12, 2026 blog post describes Acrisure as “one of the largest brokerages in the world, insuring around 3 million businesses.” The May 12, 2026 press release names two figures:

  • “Acrisure has grown in revenue from $38 million to approximately $5 billion.”
  • “employs over 19,000 colleagues in 24 countries.”

Scale matters at claim time: the broker has to still exist, and still have a working claims function, the day you need to file.

Underwriting at program launch is by Dual North America, with policies placed by Acrisure. Coverage is issued on non-admitted or surplus-lines paper, subject to:

  • Underwriting review
  • Insurer approval
  • Eligibility requirements
  • State availability
  • Policy terms

Carrier panels can change, so confirm the issuing insurer and policy form with Acrisure before binding.

TL;DR

What this is, what we do, what we don't do.

The program was announced as a joint cyber insurance offering placed through Acrisure on 2026-05-12.

Eligible buyers running Managed EDR and Managed ITDR can apply through Acrisure for a streamlined cyber policy with a $0 deductible on covered losses, subject to underwriting review and the final policy form.

The application is a Statement of Fact attesting to the managed security deployment, not a 40-page questionnaire.

Obsidian Ridge is your Huntress MDR Partner. We operate the EDR and ITDR coverage your eligibility depends on, we walk you through the Statement of Fact during your briefing, and we coordinate with the Acrisure agent placing the policy. We do not sell, broker, or rebadge the insurance. The policy, premium, and claim-handling live with Acrisure and the carrier.

The point: the security investment you already make through us is what makes the policy possible. The insurance is a downstream consequence of running EDR + ITDR correctly, not a separate product line.

Two policies, two audiences

Cyber Insurance and Tech E&O are separate products.

The program publishes two distinct policy paths under the same umbrella. Don't confuse them on the application.

PolicyWho it coversWhat it coversPlacement & underwriting
Cyber InsuranceThe operating business — your dental practice, law firm, accounting firm.Covers the operating business when an incident hits. Common scenarios named publicly include ransomware, business email compromise, and data breach response.Placed by Acrisure; underwritten at launch by Dual North America.
Tech E&OMSPs, MSSPs, and IT providers in their professional-services capacity.Covers the technology provider for errors-and-omissions exposure tied to delivering technology services to clients. Not a substitute for the end-customer's cyber policy.Placed by Acrisure; underwritten at launch by Dual North America.

Most operating businesses need the Cyber Insurance path, not Tech E&O. If you are an IT or MSP partner and need Tech E&O on your own services entity, we can route you the same way — same broker, same underwriter, same program path.

Eligibility

Who can apply

Active Managed EDR.

Agents deployed and reporting in across every endpoint in scope, operated end-to-end by Obsidian Ridge. Coverage is contingent on the platform being live in the environment, not on shelf.

Active Managed ITDR.

Microsoft 365 or Google Workspace identity coverage in place — both products are required for the streamlined application, not either/or.

Eligible organization profile.

Huntress's blog post describes eligibility as "sub-$100M revenue bands" and requires qualifying Managed EDR + ITDR. Acrisure confirms applicant-specific eligibility during the application.

Statement of Fact at application.

Acrisure replaces the usual multi-page technical questionnaire with basic firmographics plus a Statement of Fact attesting to the managed security deployment. The practitioner side of the prep is on us.

Before you apply

See where your controls stand first.

Eligible or not, the free 2026 Cyber Insurance Questionnaire scores you against the exact controls carriers ask about — in their own words — so the application holds no surprises.

Get the free questionnaire

Where it lands hardest

Regulated SMB — the segments that ask first.

The program is most useful for the buyers who already face the hardest cyber-insurance renewal pressure: regulated SMBs whose carriers want to see security investment before they quote.

Dental practices

PHI exposure is the carrier's first question. EDR + ITDR + the Acrisure application path puts a written, attested security baseline in front of underwriting — instead of a guess on the renewal form.

Law firms

ABA Formal Opinion 483 and most state-bar reasonable-care obligations push toward documented, monitored security. The same controls satisfy the Acrisure Statement of Fact, so the application is a paperwork step, not a months-long control build.

Accounting & advisory firms

IRS WISP requirements under Publication 5708 and FTC Safeguards Rule align with what the managed security stack already attests to. The carrier sees an environment that reflects the security investment, not just a checked box.

How Obsidian Ridge fits

We operate the security; Acrisure places the policy.

The program is designed so that practitioners like us aren't turned into insurance providers. That is the right shape.

Our job is to deliver the security posture the carrier is pricing against:

  • Agents healthy
  • Identity coverage live
  • Alert-handling logged
  • Incident-response playbook current

We provide the operational evidence behind the Statement of Fact, and we hand you cleanly off to the Acrisure agent for the application itself.

That separation is intentional. We don't earn commission on your premium, we don't adjust claims, and we don't decide what gets paid. We do make sure the security that supports the policy is actually running — which is the part that has tripped up most SMB cyber-insurance applications in the carriers' loss data over the last three years.

How the Huntress partner layer works →

What we don't yet know

Honest gaps in the public record (as of 2026-06-12).

Several program details are not yet publicly disclosed by Huntress or Acrisure. We tell you what's known and what isn't rather than pretending otherwise.

Coverage limits. Per-claim and aggregate limits are not published; ask Acrisure for a quote based on your firmographics. The bound policy form names the specific limits that apply to your organization.

Premium pricing. Acrisure provides individualized quotes; no rate card or sample-quote range is published. Pricing is driven by industry, headcount, revenue, and other underwriting inputs.

Covered perils, exclusions, and sub-limits. The program is built around ransomware, business email compromise (BEC), and data breach response. The full named-perils list, sub-limits, waiting periods, and exclusions are in the policy form Acrisure provides at quote time.

State-specific availability (including North Carolina). Coverage is issued on surplus-lines paper, which varies by state and is not pre-published. Confirm NC availability — and any other client-domiciled state — with the Acrisure intake team via huntress.com/hac.

Application timeline. Applications are open to all eligible program customers and partners now; no rolling enablement window has been announced.

Per-applicant eligibility. Huntress's blog post positions the program for organizations in “sub-$100M revenue bands” running qualifying Managed EDR + ITDR. What is not pre-published is the final per-applicant decision, which is subject to Acrisure underwriting review, insurer approval, state availability, and policy terms.

Claims process and SLA. The public materials we verified do not publish a claim-handling SLA. Ask Acrisure how claims are routed, who the issuing insurer is, and what response expectations are written into the policy documents.

Honest fit check

What this is not

We'd rather you read this twice than buy a thing you don't need.

  • This is not a vendor warranty or guarantee. The program explicitly disclaims warranty / guarantee framing — the policy is primary insurance issued by a carrier, not a vendor pledge.
  • This does not replace existing carriers mid-term. If you already have an in-force cyber policy, the comparison is at renewal.
  • This is not a substitute for the Cyber Insurance Readiness Sprint if you are not yet running managed security through us. Start there if you need the evidence packet for a different carrier.
  • This is not a way to skip security work. Eligibility is contingent on EDR + ITDR being live and reporting. Coverage that depends on a stack you don't run is not coverage.
  • This is not legal advice. Confirm policy terms with Acrisure and, where appropriate, with your own counsel before binding.

FAQ

Questions before you ask for the application

Is Obsidian Ridge selling this insurance?

No. The insurance is placed through Acrisure. Obsidian Ridge does not sell, broker, or rebadge the policy.

We operate the Managed EDR and ITDR coverage your eligibility depends on, and we walk you through the Statement of Fact during your briefing.

The actual application, premium, issuing insurer, and policy terms live with Acrisure and the policy documents.

Why $0 deductible? Is that real?

The public Huntress program page and announcement describe no deductible for eligible applicants. The policy form Acrisure issues to your specific organization is still the document that governs the actual terms, conditions, limitations, exclusions, and any state-specific availability.

Who underwrites the policy?

Huntress names Dual North America as the underwriter at program launch, with policies placed by Acrisure. Coverage is issued on non-admitted or surplus-lines paper.

Carrier panels can change over time, so confirm the issuing insurer, financial strength, and state availability on your specific policy form before binding.

What does the policy actually cover?

The program publicly references ransomware, business email compromise, and data breach response as covered claim scenarios.

The specific covered perils, sub-limits, exclusions, retention windows, and waiting periods are determined by the policy form Acrisure issues, which the applicant reviews before binding.

What are the coverage limits?

Per-claim and aggregate limits are not published in the program launch materials. Limits are quoted per applicant during the application process, against inputs like industry, headcount, revenue, and exposure profile. The bound policy form names the specific limits that apply to your organization.

Is the program available in North Carolina?

The program's own disclaimer notes it may not be available in all jurisdictions, which is standard language for surplus-lines paper. The Acrisure agent confirms availability for each applicant's domiciled state — including North Carolina — during the application.

What if a client already has cyber insurance?

Most carriers will not double-cover the same event. The right move is to compare the existing carrier's terms — limits, deductible, exclusions, claim-handling reputation — against the Acrisure-placed program at the next renewal.

The $0 deductible and the streamlined application are typically the comparison points that matter. We help structure that comparison; we do not break an existing policy mid-term.

How does this connect to the Cyber Insurance Readiness Sprint?

Different intent. The Readiness Sprint is for organizations that need a clean evidence packet for whichever carrier they apply to — including this program or any other.

If you are already running Managed EDR + ITDR through Obsidian Ridge, you skip most of the sprint work and go directly to the Acrisure application.

If you are not yet on the platform, the sprint is how we get you ready while we onboard the managed security side.

Next step

Check eligibility on a 30-min briefing.

If you're already running Managed EDR + ITDR through Obsidian Ridge, the briefing confirms eligibility and routes you to the Acrisure agent. If you're not yet on the platform, the same call scopes the path that gets you there.

Talk with us