Your Cyber Policy Assumes Controls You May Not Have

Cyber insurance has changed a lot in a short time. After several years of brutal ransomware losses, carriers stopped writing cover off the back of a short questionnaire and started making specific security requirements a condition of the policy.

Multi-factor authentication on remote access and privileged accounts. Offline or immutable backups that have been tested. Endpoint detection and response. A documented patching regime. These are now requirements rather than nice-to-haves. They show up in the application, and your answers become part of the policy.

That last bit matters more than people realise. Statements made in an application are generally warranties. If something wasn’t accurate when you said it, or the control lapses partway through the policy period, the carrier may have grounds to deny the claim or rescind the policy altogether. After the incident, when that cover is the only thing between you and the loss.

The realistic way this goes wrong isn’t dishonesty. It’s that whoever filled in the application answered in good faith about a control the organisation meant to have, or had in one place but not everywhere. MFA switched on for email but not the VPN. Backups running nightly but never once tested for restore. EDR on the laptops but not the servers.

The fix is procedural. Before you bind, check that every control you’ve attested to exists right across the environment, and write down that you checked. Then check again at each renewal, because environments drift. A new system goes in. An administrator leaves. Somebody grants a temporary exception that nobody ever revokes.

Cyber cover is well worth having, and the response services attached to a good policy actually keep losses down. But it’s one of the very few lines where what you do operationally decides whether the policy pays out at all, and you would never guess that from looking at the certificate.

This is general information, not advice. The right answer depends on your structure, your state and your specific facts. Talk to us about your situation.

Applies to you?

Find out where you really stand.

Most of what we write about is quantifiable for your specific business in a short conversation.