A small electronics manufacturer in Illinois submitted a cyber insurance application in April 2022. They checked yes on MFA. Their CEO signed it. Their head of network security signed it. Six weeks later, ransomware hit. The carrier ran forensics and found that MFA was active on the firewall only. Every other system, including the compromised server, was unprotected. A federal court voided the policy entirely. No coverage, retroactively, for anything.
That company was International Control Services. The carrier was Travelers. The case is public record.1 And it is not an outlier.
According to 2024 data from the National Association of Insurance Commissioners, nearly 28,555 cyber claims were closed without payment, compared to 9,941 that were paid. That’s roughly a 3-to-1 unpaid-to-paid ratio.2 For excess cyber policies specifically, unpaid claims outnumber paid by more than 20 to 1. At-Bay’s 2026 InsurSec Report puts average claim severity across all incidents at $221,000, an all-time high, with ransomware averaging $508,000 per event.3 Coalition’s data shows that for businesses under $25 million in revenue, the average claim cost is around $100,000. That number jumped 56% year over year.4
Premiums fell roughly 7% in 2024 while claim volume rose 40% in the same period. That math does not hold, and carriers know it. Premium increases are forecast over the next 12 months as claim volume catches up with pricing. The underwriting window is tightening.
Travelers did not frame the ICS situation as an honest mistake. The complaint used pointed language: “misrepresentations, omissions, concealment of facts, and incorrect statements” that “materially affected the acceptance of the risk.” That is the language carriers reach for when they want a policy voided.
When an underwriter asks, “Do you have MFA enabled for all administrative access?” they mean every path to a privileged or admin account, internal and external, no exceptions. Domain admin consoles. Server administration over RDP, SSH, or local console. Email administration (Office 365 and Google Workspace admin consoles). Cloud management portals (AWS, Azure, GCP). Identity provider consoles (Okta, Entra ID). Any line-of-business application where someone holds elevated access. Every privileged account.
“We have MFA” does not satisfy that question. ICS had MFA at the firewall edge, but not on the admin paths behind it. The moment an attacker landed inside the perimeter, through phishing, a compromised endpoint, or a vendor account, every admin function was reachable without another challenge. The application asks about every admin path, not just the one at the edge. Forensics after a breach is thorough, and carriers have a financial incentive to look carefully.
Beyond MFA, most carriers now require endpoint detection and response tools deployed across all endpoints, including servers, not just workstations. Immutable, isolated backups separated from the production network, with documented restore tests. Incident documentation: logs, configurations, and communications preserved during and after an event. Industry sources consistently identify inadequate documentation as a significant factor in claim denials. Underwriters need evidence that controls were in place, not just a policy document stating they should be.
When you sign a cyber insurance application, you are making a legal representation. Not an estimate. Not a best-effort description. A representation that, if found to be material and false, gives the carrier grounds to rescind the policy entirely. Not just deny the specific claim. Void coverage retroactively.
ICS did not contest the case. They consented to the judgment rescinding their policy. Whether the application was answered with knowing falsehood, careless negligence, or genuine operational blindness was never adjudicated. It did not need to be. Insurance law permits rescission whether the misrepresentation was intentional or unintentional. Materiality is the legal hinge, not intent. Underwriters and forensic investigators compare your attestation to what they find in the logs. The label on how you got there does not change the result.
Signing the application is the moment your operational reality becomes a legal fact. If the reality does not match the signature, you carry that exposure until the next renewal. You will not know it until you file.
Three things worth doing before your next renewal date.
Run an admin access audit, not a policy check. Do not ask your IT team, “Do we have MFA?” Ask them to walk you through every path to an admin or privileged account, internal and external, and show you how MFA is enforced at each one. Document the results. That documentation is evidence, and you would want it before a carrier requests it.
Test your backup restore. “We have backups” is not the same as “we can restore from backups.” Ransomware actors specifically target backup systems, and if your backup storage lives on the same network segment as production, it is not isolated in any way an underwriter would recognize. Ask your IT provider for a documented restore test. Not a screenshot. A test with a written result.
Read the last application you submitted, line by line. Pull it from wherever it lives. Read each “yes” answer. Ask whether that control is still in place, still fully deployed, and whether you could demonstrate it under forensic examination. If anything has drifted since you signed, disclose it proactively at renewal. Misrepresentation is treated as fraud even when unintentional, and the standard is not what you meant when you answered. It’s what the investigation finds afterward.
Cyber insurance is still worth carrying. A policy that actually pays is worth significantly more than one that looks complete on paper. The renewal application is not an administrative checklist to move through quickly. It is a legal representation and, effectively, a control audit. The carriers are treating it that way. The question is whether you are.
What does your last application say? And when was the last time someone verified that it is still accurate?
- Travelers v. International Control Services, Inc., Insurance Journal, July 2022 and Lockton analysis. https://www.insurancejournal.com/news/national/2022/07/12/675516.htm | https://global.lockton.com/us/en/news-insights/travelers-v-ics-underscores-need-to-respond-carefully-to-cyber-insurance ↩
- NAIC 2025 Cybersecurity Insurance Report, via KY3 News investigation, February 2026. https://www.ky3.com/2026/02/11/your-side-cyber-insurance-claims-denied-an-alarming-rate-report-shows/ | Primary report: NAIC 2025 Cybersecurity Insurance Report (PDF), content.naic.org ↩
- At-Bay InsurSec 2026 Report, via Help Net Security, April 2026. https://www.helpnetsecurity.com/2026/04/23/cyber-insurance-claims-report/ ↩
- Coalition Cyber Insurance Claims data. https://www.coalitioninc.com/topics/cyber-insurance-claims ↩