What Is Cyber Insurance? How to Protect Your Business from Financial Loss
Cyber insurance covers financial losses from data breaches, ransomware, and other cyber incidents, including breach response costs, legal fees, and business interruption. Most businesses buying it assume the policy pays out if something goes wrong. The honest picture is more complicated, and understanding exactly why matters more than the coverage limit on your declarations page.
What is cyber insurance?
Cyber insurance, sometimes called network security insurance, is a policy covering financial losses from cyber incidents: breach response, ransomware payments, business interruption, and third-party liability. Coverage isn’t automatic once purchased, it depends on maintaining the specific security controls declared at application.
This last part is the piece most business owners miss. Cyber insurance behaves less like general liability coverage and more like a conditional contract: you attest to specific security measures being in place, the insurer prices the policy based on that attestation, and coverage assumes those measures stay true for the life of the policy, not just on the day you signed up.
The controls insurers now treat as hard prerequisites
Insurers in 2026 treat eight controls as required, not preferred, for most policies: phishing-resistant MFA, EDR on every endpoint and server, immutable and restore-tested backups, a 14 to 30 day patch SLA, privileged access management, a tested incident response plan, enforced email authentication, and documented security awareness training.
| Control | What Insurers Verify |
| Phishing-resistant MFA | FIDO2/hardware keys, no SMS on privileged accounts |
| EDR (not antivirus) | Deployed on 95%+ of endpoints and servers |
| Immutable backups | Isolated, restore-tested, dated documentation |
| Patch SLA | 14-30 days for workstations, faster for internet-facing systems |
| PAM | Just-in-time access, separated privileged accounts |
Roughly 80% of insurers require MFA and 65% require EDR as underwriting conditions, and the pattern across every control is the same: insurers no longer accept attestation alone. They want documented evidence, deployment screenshots, policy exports, and test dates, not a checkbox on a form.
How likely is a claim to get paid?
The honest answer depends on what’s being measured, and that’s exactly where most cited statistics mislead. More rigorous industry sources, Deloitte and NAIC-sourced data, put formal denial through policy exclusion clauses at roughly 21% to 27% of claims. Broader marketing-oriented aggregations frequently cite “over 40%,” a figure that usually blends outright denial with claims closed for other reasons.
This discrepancy matters because the two numbers answer different questions. The 21% to 27% range specifically measures claims denied or partially denied due to a policy exclusion, missing MFA, unpatched systems, or a nation-state attribution exemption. The higher “40%+” figures circulating widely often include claims that closed without payment for reasons unrelated to denial for cause, falling below a deductible, being withdrawn, or resolving through a different coverage line entirely. Both figures are technically accurate depending on definition, but conflating them creates a misleading picture: it’s not that nearly half of all legitimate claims get rejected outright, it’s that roughly a quarter face a real denial specifically because a declared control wasn’t actually maintained. The practical takeaway is the same regardless of which number you find first: the single largest lever you control is keeping the controls you attested to genuinely current, not just current on the day you applied.
The five most common reasons claims get denied
Five reasons account for most denials: missing or unenforced MFA, particularly on privileged accounts, unpatched systems that predate the incident, undocumented or unverifiable security controls, policy exclusions like ransomware sublimits or nation-state attribution, and pre-existing vulnerabilities not disclosed at underwriting.
Missing MFA dominates this list specifically: 82% of denied claims trace back to the absence of MFA on critical systems. This single control gap causes more denials than every other reason combined, which is exactly why insurers have hardened MFA requirements faster than any other control category in recent renewal cycles. If you maintain only one control perfectly, MFA enforcement without exception is the one with the highest financial consequence if it slips.
Can your coverage be cancelled after the fact?
Yes, and it happens through a legal process called rescission, which voids a policy entirely, treating it as if it never existed, if the insurer proves a material misrepresentation on the application. Courts in the majority of US jurisdictions allow this regardless of whether the misrepresentation was intentional, negligent, or an honest mistake.
A real case shows exactly how this plays out. Travelers sued International Control Services six weeks after a ransomware attack, seeking rescission based on misrepresentations about MFA deployment in the insurance application. Within weeks, ICS agreed to rescission, and the court declared the policy void from inception, meaning zero coverage for the entire incident. The application had been co-signed by two people, including the company’s own head of network security, and courts treat that co-signature as fully informed attestation, closing off the “we didn’t realize what was actually deployed” defense entirely. The 9th Circuit reaffirmed the broader principle in Hughes v. First National Insurance in March 2024: a material misrepresentation, even an honest mistake, entitles the insurer to rescind the policy from day one. The lesson isn’t paranoia, it’s precision: before signing any cyber insurance application, verify every security claim against what’s genuinely deployed, ideally with someone technical enough to catch the gap between what a dashboard shows and what’s actually enforced everywhere it needs to be.
Two real gaps that trip up otherwise well-secured firms
The most common gap that trips up genuinely security-conscious businesses is MFA enabled on email but never extended to VPN or remote desktop access, and EDR deployed on workstations but missing from servers, both technically true statements that still constitute a material misrepresentation if the application asked about coverage broadly.
This pattern deserves real attention because it doesn’t come from negligence, it comes from an honest but incomplete understanding of scope. A business genuinely believes it has “MFA everywhere” because it’s enforced on the systems the IT team interacts with daily, email and the primary login portal, without realizing the VPN gateway or a legacy remote desktop connection was configured years ago and never revisited. Underwriting applications ask broad questions, “is MFA enforced across your environment,” and a technically defensible “mostly yes” answer can become the exact material misrepresentation that voids coverage after an incident traces back to that one unprotected VPN entry point. The second common gap follows the same logic with EDR: a business deploys EDR across every workstation during a security refresh, checks the box confidently, and never extends the same coverage to backend servers, which often sit outside the standard endpoint rollout and get overlooked precisely because they’re not user-facing. Before your next renewal, audit both gaps specifically: pull a full asset inventory and confirm MFA and EDR coverage against every entry point and every server, not just the systems your team touches daily.
Why remote access is now central to your premium, not just your security
Remote access has become one of the single biggest underwriting factors because it’s where the most damaging real-world gaps concentrate. 45% of new claims filed in Q1 2025 originated from VPN setups that lacked MFA protection, making unprotected remote access the single most common root cause behind recent claims.
This matters because remote access sits at an unusual intersection: it’s often configured once during initial setup and rarely revisited, yet it represents a direct, unmonitored path into the network from outside your usual security perimeter. Insurers have responded by scrutinizing VPN and remote desktop MFA specifically and separately from general MFA questions on applications, since the data clearly shows this specific gap driving a disproportionate share of recent losses. If your VPN still accepts password-only authentication anywhere in your environment, treat that as the single highest-priority fix before your next renewal, ahead of nearly every other control on the checklist.
Does basic antivirus still count? What underwriters require
No. Legacy antivirus, which relies on matching known malware signatures, no longer satisfies cyber insurance requirements. Underwriters now require EDR, which detects behavioral anomalies like fileless malware and living-off-the-land techniques that signature-based antivirus structurally cannot catch.
| Legacy Antivirus | EDR | |
| Detection method | Known malware signatures | Behavioral analysis |
| Catches fileless attacks | No | Yes |
| Insurer acceptance | No longer sufficient | Standard requirement |
| Increasingly expected addition | N/A | 24/7 monitored response (MDR) |
The bar keeps rising even within EDR itself. Some carriers now push beyond EDR toward MDR specifically, reasoning that EDR sitting unwatched between business hours is functionally similar to having no detection at all during the window attackers most often strike. If your current setup is antivirus alone, or EDR with no one actively monitoring alerts after hours, both represent a real, current gap against 2026 underwriting standards, not a hypothetical future requirement.
A realistic path if you can’t self-audit every control alone
Start with a documented gap analysis comparing your actual deployed controls against your current policy’s stated requirements, not your memory of what was configured at initial setup. This single exercise catches the MFA and EDR scope gaps covered above before they become a denied claim.
Request a full export of your MFA enforcement policy, not a screenshot of a settings toggle, and cross-reference it against every access point: email, VPN, remote desktop, cloud consoles, and administrator accounts specifically. Do the same for EDR deployment coverage, confirming servers and any legacy systems are included, not just standard workstations. Cyber Security Solutions Ltd runs exactly this gap analysis for clients preparing for renewal or a first application, and it consistently surfaces the exact scope gaps, VPN access left out of MFA enforcement, a handful of servers missing EDR, that would otherwise only surface during a post-breach forensic review, which is the worst possible time to discover them.
Conclusion
Cyber insurance, in practice, comes down to one principle: coverage only holds if the controls you declared stay genuinely true for the life of the policy, not just on application day. Audit your MFA and EDR scope against every access point before your next renewal, since that single gap causes more denials than everything else combined. If you want help running that gap analysis before your next application or renewal, Cyber Security Solutions Ltd can walk through it with you at cybersecuritysolutionsltd.com.
FAQs
Cyber insurance is a policy covering financial losses from cyber incidents, including breach response costs, ransomware payments, business interruption, and third-party liability. Coverage depends on maintaining the specific security controls declared at application, not just purchasing the policy itself.
Often, yes. Small businesses face the same core threats as larger companies but typically have fewer resources to absorb a breach’s cost. Despite this, only 10% to 20% of SMEs carry cyber insurance, leaving most exposed to costs that can exceed $79,000 for an uninsured incident.
Typical coverage includes breach response costs like forensics and notification, ransomware payments, business interruption losses, legal liability, and regulatory fines where insurable. Coverage details vary significantly by policy, and specific exclusions, like nation-state attacks, can limit what actually gets paid.
Current requirements typically include phishing-resistant MFA, EDR on all endpoints and servers, immutable and restore-tested backups, a documented patch SLA, privileged access management, a tested incident response plan, and enforced email authentication. Most carriers now verify these with documentation, not just attestation.
The most common reason is missing or unenforced MFA, responsible for 82% of denied claims. Other frequent causes include unpatched systems, undocumented controls, policy exclusions like ransomware sublimits, and pre-existing vulnerabilities not disclosed during the underwriting application process.
Yes, through a legal process called rescission, which voids the entire policy if the insurer proves a material misrepresentation on the application. Courts generally allow this even for honest mistakes, as shown in the Travelers v. International Control Services case, which resulted in a policy voided from inception.
No. Legacy antivirus relies on known malware signatures and cannot detect fileless attacks or living-off-the-land techniques modern ransomware uses. Underwriters now require EDR at minimum, with some carriers increasingly expecting 24/7 monitored response through MDR rather than unwatched detection alone.
