Direct answer
A cyber-insurance claim may be denied, reduced, reserved, or disputed for reasons connected to the application, policy language, endorsements, exclusions, notice, consent requirements, cooperation duties, causation, applicable law, and facts of the loss. Security controls such as MFA, endpoint protection, and backups matter when they were represented during underwriting, required by a policy or endorsement, or material to the event. No single checklist predicts a carrier's decision.
Author: Joseph Boyd, Founder and Principal Advisor at Infosec Check. Last reviewed . Scope: general educational and risk management information about cyber-insurance application, policy, control, notice, and response considerations. It is not legal advice, a coverage opinion, or a claim determination.
Scope and limitations
This page provides general educational and risk-management information. It is not a legal opinion or claim determination. The application, policy, endorsements, applicable law, jurisdiction, insurer communications, and facts control. A business facing an incident, reservation of rights, denial, or coverage dispute should promptly consult appropriate coverage counsel and licensed insurance professionals.
Why this matters
Cyber insurance can be an important financial backstop after a security incident. For a CPA firm during tax season, a law firm holding client trust funds, or a lender wiring closings, a coverage dispute can leave forensics, breach counsel, notification, and business interruption costs unresolved while the business is still recovering.
Leadership, not the IT contractor, signs the application and answers for the organization's representations under the policy. Security and governance resources from the Federal Trade Commission and the IRS support that governance work. They do not decide how an insurer will handle a specific claim.
Ten issues that may create a coverage dispute
1. An application answer may not match the evidence
Cyber-insurance applications may ask about MFA, backups, endpoint protection, training, incident response, and other practices. If an answer was material to underwriting and the available evidence does not support it, the insurer may investigate the discrepancy. The legal and coverage consequences depend on the wording, materiality, applicable law, and facts.
2. MFA may have been represented or required for a defined scope
Missing MFA does not produce the same result under every policy. The question is whether MFA was represented, required, or relevant to the event, which accounts and systems were within scope, and what the policy and applicable law provide. Leadership should verify coverage rather than rely on the statement “we use MFA”.
3. Endpoint protection may not cover the systems described
A business may believe endpoint protection or EDR covers every relevant device while reports show exceptions, inactive agents, contractor devices, or unmanaged systems. If the application or underwriting process addressed that coverage, the difference between belief and evidence can become material during a claim investigation.
4. Backup capabilities may differ from what was represented
Backup frequency, protected or isolated copies, retention, and restoration testing are different questions. A policy or application may address some or all of them. The business should preserve evidence showing what was backed up, how the copies were protected, and whether restoration had been tested.
5. Notice may not follow the policy's requirements
Policies differ on when, how, and to whom notice must be given. Some also contain consent or cooperation requirements. During an incident, leadership should use the actual policy and current insurer instructions rather than rely on a general website, memory, or vendor assumption.
6. Vendors, counsel, or forensic providers may require consent
Some cyber policies provide panel resources or require insurer consent before particular expenses are incurred. Others are structured differently. The business should identify the applicable provisions before an event and obtain incident-specific direction when an event occurs.
7. Written policies may not reflect actual operations
A document alone does not prove that a practice was assigned, communicated, implemented, reviewed, or maintained. If the company represented that a program or plan existed, it should retain the approved version and evidence showing how the program operated.
8. Unsupported or unpatched systems may affect the investigation
Unsupported technology and delayed remediation can increase security risk. Their insurance significance depends on the policy, application, cause of loss, representations, exclusions, conditions, and applicable law. Avoid describing an outdated system as an automatic exclusion or automatic denial.
9. The loss may fall outside the purchased coverage
Cyber policies can contain separate insuring agreements, definitions, exclusions, endorsements, retentions, and sublimits. Social engineering, funds-transfer fraud, business interruption, cybercrime, and other losses may be treated differently. The declarations and full policy should be reviewed rather than relying on a summary.
10. Evidence preservation and cooperation may become material
The policy may impose cooperation duties, and the response process may require preservation of logs, systems, communications, and decisions. The exact duties and consequences depend on the policy and law. The incident-response process should coordinate insurer, legal, forensic, regulatory, and operational needs.
Common mistakes
- Letting an IT provider complete the cyber application without executive review of the answers.
- Treating the application as a sales form rather than an underwriting record that should be supportable.
- Assuming ransom payment, negotiation, or funds-transfer loss is covered without reading the policy.
- Calling the IT provider and delaying insurer notice without checking the policy's notice provisions.
- Restoring or wiping affected systems before evidence is preserved and direction is obtained.
- Selecting limits without reviewing sublimits and endorsements for the losses most relevant to the business.
Practical business checklist
Use this list before your next renewal and again after any material change to your environment. Have the executive sign off, not just the IT lead.
- Verify the MFA scope represented or required, including email, remote access, and administrator accounts.
- Verify endpoint-protection coverage and document exceptions, inactive agents, and unmanaged devices.
- Document backup protection, retention, and restoration testing rather than assuming a posture.
- Retain approved written information security, incident response, and vendor management documents with evidence of how they operate.
- Maintain a defined patching and remediation process with records for internet-facing systems.
- Train staff on payment and wire verification procedures and retain training records.
- Review social-engineering and funds-transfer provisions, sublimits, and endorsements in the actual policy.
- Verify material application answers against available evidence before signature at application or renewal.
- Save the insurer's incident reporting contact and current instructions where leadership can reach them.
- Run a tabletop exercise so leadership knows the notice, consent, and preservation steps the policy requires.
Glossary
- MFA (multi-factor authentication)
- A sign-in method that requires a second factor in addition to a password, typically a mobile app prompt or hardware key.
- EDR (endpoint detection and response)
- Software installed on laptops and servers that detects, records, and can block malicious activity.
- Business email compromise
- A fraud in which an attacker uses a spoofed or hijacked email account to trick staff into wiring funds or sending sensitive data.
- Rescission
- A carrier's right to void a policy from inception if material statements on the application were inaccurate.
- Sublimit
- A cap inside the overall policy limit that applies to a specific type of loss, such as social engineering or regulatory fines.
When should you seek professional help?
Consider involving a security advisor, coverage counsel, or licensed insurance professional when any of the following are true.
- You are preparing a new cyber insurance application or renewal.
- Your insurer has requested additional controls in connection with coverage.
- You handle regulated data under HIPAA, PCI DSS, GLBA, or IRS Publication 4557.
- You have grown through acquisition and inherited unknown IT environments.
- You suspect an incident is in progress or has recently occurred.
- Your board or lender is asking for an independent assessment.
Assessment, documentation, and ongoing advisory work help leadership see where representations, evidence, and response responsibilities do not yet line up.
Frequently asked questions
Is an application answer a warranty?
Terminology and legal effect vary. An application can contain representations, warranties, attestations, or other statements used in underwriting. The consequences of an inaccurate answer depend on the wording, materiality, policy, applicable law, and facts.
Can we choose our own attorney or forensic firm?
It depends on the policy and insurer instructions. Some policies provide panel resources or require prior consent for certain expenses. Review the actual policy and obtain incident-specific direction before incurring material costs when circumstances permit.
Do backups determine whether a ransomware claim will be paid?
No single control determines every claim. Backup practices may be relevant to underwriting, restoration, business interruption, mitigation, or the facts of the incident, but the application, policy, endorsements, law, and circumstances control.
Primary sources
These are government security and readiness resources. None of them determines whether a particular insurance claim is covered.
- FTC cyber insurance guidance for businesses
Supports general business awareness of cyber insurance concepts. It does not determine whether a particular claim is covered.
- NIST Cybersecurity Framework
Supports security governance and control practices. It does not establish insurer claim behavior.
- CISA StopRansomware
Supports ransomware prevention and response practices. It does not establish coverage outcomes.
- IRS Publication 4557, Safeguarding Taxpayer Data
Supports taxpayer data protection practices for tax professionals. It does not address insurance coverage.
Businesses that want to reduce uncertainty before a loss can begin with Cyber Insurance Readiness: verifying the representations, controls, evidence, and governance that may matter later.
Related reading
Request an Infosec Check readiness review
A senior advisor will review your current controls, your cyber insurance application answers, the evidence available to support them, and your incident response process.
