Step Five: Do you do an SBOM or certification for anything that touches my systems, do you have a cyber insurance policy