Cyber insurance gets sold like a seatbelt. Buy the policy, and if something terrible happens, the insurer writes a check. Most of the time that is roughly how it works. The claims that go badly rarely go badly because the insurer is villainous. They go badly because of something the business did, or failed to do, months earlier, usually while filling out a form or letting a control quietly lapse.
Two notes first. This is general information, not legal or insurance advice. Policy language varies enormously between carriers and even between renewals with the same carrier, so have your broker and an attorney confirm what applies to your business. Second, none of this is meant to scare anybody off buying coverage. Cyber insurance is worth having. It is just worth having correctly, and the difference is mostly paperwork and follow through.
What the Claims Data Actually Shows
It helps to know what these claims look like before worrying about how they get denied. In its 2026 Cyber Claims Report, covering full year 2025 claims across its book of business, the cyber insurer Coalition reported that business email compromise and funds transfer fraud together “accounted for the majority (58%) of cyber incidents,” with funds transfer fraud alone making up 27 percent of all claims. Coalition also reported average global claims severity of $116,000 in that period, ransomware claims averaging $269,000, initial ransom demands up 47 percent year over year, and a record 86 percent of businesses refusing to pay.
Notice what is missing: dramatic nation state intrusions. The typical claim is somebody in accounting wiring money to a fraudulent account after a convincing email. That matters, because the controls insurers ask about on the application are aimed squarely at those ordinary events. For wider context on how incidents ripple through supply chains, our piece on what the Stryker cyberattack tells us about the threats facing every business is a good companion.
Reason One: The Application Was Not Accurate
This is the big one, and there is a well known example. In July 2022, Travelers filed a federal complaint against a policyholder, International Control Services, alleging “material misrepresentations in connection with its application for a Travelers cyber insurance policy” regarding multifactor authentication. As the broker Lockton summarized the case, Travelers sought “rescission and declaratory relief,” and the matter ended the following month when the policyholder agreed to let the court enter a judgment rescinding the policy. Rescission does not reduce a payout. It unwinds the policy as if it never existed.
Lockton’s guidance to policyholders is one sentence long and worth taping to a wall: organizations should “accurately convey the current status of their controls in response to relevant questions in policy applications.” In practice, the failure is rarely a lie. It is a busy owner forwarding the application to whoever has time, that person answering “yes, we have MFA” because email has it, and nobody checking whether the remote access tools, the VPN, or the administrative accounts have it too. Treat the application as a technical document. Have the person who administers the systems answer it, in writing, and keep their answers.
Reason Two: The Control Lapsed After Binding
A policy is bound in March based on a snapshot of your environment. In August, a vendor needs access and someone creates an exception. In October, an integration breaks and multifactor authentication gets turned off for a service account “temporarily.” In January, that is where the intruder walks in. The application was accurate when signed. The environment was not accurate when it mattered.
Fixing this is a process problem, not a technology problem. Keep a short list of every control you attested to on the application. Review it quarterly against reality. Log every exception with a name, a reason, and an expiration date, and actually close them out. If a control has to come down for a business reason, tell your broker before renewal rather than discovering the gap during a claim. If you are still deciding what your authentication should look like, our comparison of YubiKey versus passkeys versus MFA walks through the practical differences.
Reason Three: You Told Them Late
Cyber policies carry notice conditions, and they are not decorative. The wording differs by carrier, so read yours before you need it and keep the reporting instructions somewhere findable offline. The Federal Trade Commission, in its small business guidance on cyber insurance, suggests confirming your provider will “offer a breach hotline that’s available every day of the year at all times.” That advice exists because these events start at 2 a.m. on holidays, and the expectation runs both ways: they answer immediately, and you call immediately.
The realistic failure mode is not defiance. It is a team spending four days trying to fix the problem quietly, hoping it turns out to be nothing, and reporting only once it clearly is not. By then decisions have been made, evidence overwritten, money spent. Write the phone number on the incident response plan. Print the plan. Nobody can read a plan stored on the file server that just got encrypted.
Reason Four: The Wrong People Did the Response Work
This one surprises people most. It is common for a cyber policy to require the insurer to approve the professionals who respond, and to consent before certain response costs are incurred. Coverage counsel routinely advise clients to look for those provisions at purchase rather than at claim time, and where possible to negotiate them, for example so that consent cannot be unreasonably withheld for costs that are reasonable. Check your own policy for the exact wording, because it varies.
So the forensic firm you called at midnight because you trust them may not be a covered expense. Handle it in advance: ask your broker for the carrier’s approved vendor list, and if you have a relationship with a specific firm or attorney, request they be added before you need them. Vendors matter after the fact too. Reporting on a 2025 federal case in which an insurer sued two cybersecurity vendors to recover money it had paid its own insured, the law firm Hunton Andrews Kurth observed that “cyber insurers are frequently request[ing] vendor contracts from their insureds following a cyber incident so that the insurer can evaluate potential subrogation rights.” Your vendor contracts will be read closely.
Exclusions Worth Reading Before You Need Them
Nobody enjoys this part. Do it once, with your broker, in an hour.
- The retroactive date and prior acts. If an intrusion began before your coverage started but was discovered after, ask specifically how the policy treats it. Coverage for undiscovered prior breaches is something you request, not something you assume.
- Contractual liability wording. If your customer agreements include confidentiality obligations, ask whether a broad breach of contract exclusion would swallow the claims most likely to come at you.
- Duty to defend. The FTC recommends checking whether the insurer will “defend you in a lawsuit or regulatory investigation,” and to look for that specific wording. Reimbursement and defense are not the same product.
- How it stacks with your other policies. The FTC also suggests confirming whether coverage applies “in excess of any other applicable insurance you have,” which determines who pays first when a crime policy and a cyber policy both arguably respond.
The Bottom Line
Denied claims are usually self inflicted, and every cause is preventable with unglamorous work: answer the application with your administrator in the room, keep a living list of the controls you promised, review it quarterly, report fast, and know which vendors your carrier will pay for before the bad day. Do those five things and you are ahead of most businesses your size. Once more: this is general information, not legal or insurance advice, and every policy differs. Have a lawyer or your broker review your coverage and confirm what applies to you.
We regularly help clients answer cyber insurance applications accurately, document the controls a carrier will ask about, and keep them in place between renewals so there are no surprises at claim time. If you would like a second set of eyes before your next renewal, Contact us today.
Sources:
- Lockton, Travelers v. ICS underscores need to respond carefully to cyber insurance application questions
- Hunton Andrews Kurth, Policyholder Plot Twist: Cyber Insurer Sues Policyholder’s Cyber Pros
- Federal Trade Commission, Cyber Insurance guidance for small business
- Coalition, 2026 Cyber Claims Report announcement

Comments are closed