Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Policy Rescissions Are Rising: What Changed in Cyber ApplicationsSecurity Controls
5 min readFor Cyber Insurance Buyers & Brokers

Policy Rescissions Are Rising: What Changed in Cyber Applications

The New Reality of Cyber Insurance

Cyber insurers are now conducting forensic investigations after claims to verify the security controls you stated in your application. This isn't just about risk management; it's about operational reality, as shown by documented policy rescissions.

In 2022, International Control Services faced a ransomware attack and filed a claim under its $1 million Travelers cyber policy. The issue wasn't a dispute over policy language. Instead, Travelers sued for rescission due to misrepresentation in the application. Within six weeks, the insured agreed to void the policy from inception. The application claimed the use of multifactor authentication (MFA) for administrative access, but Travelers found that MFA was only used for firewall protection, not for other digital assets, including the compromised server.

This case highlights a fundamental shift. Forensic investigators now compare your application answers with the actual security environment before an attack. Your statements about endpoint detection, backup configurations, and access controls are not just formalities. They are contractual statements that insurers will verify with precision after a loss.

Key Findings

Application signatures carry technical liability. The International Control Services application was signed by both the CEO and the employee responsible for network security. That dual signature didn't prevent rescission when the actual network setup contradicted the application. Your IT administrator's understanding of deployed controls must match what the application states, not what leadership assumes is in place.

Security controls must persist throughout the policy period. Some cyber forms require you to maintain the controls you represented during underwriting. If a control was in place at inception but later disabled or altered, it creates a coverage issue. Changes like migrating to cloud infrastructure or adding servers can alter the security environment the insurer underwrote. Your policy may not automatically adjust.

Forensic timelines can pre-date your discovery. An investigation may show that unauthorized access began months before you detected it. This affects coverage under retroactive date provisions and prior-knowledge clauses. The date you discovered the attack isn't what determines coverage; it's when the attacker first accessed your network.

Cyber forms vary significantly between carriers. Unlike property coverage, cyber insurance lacks a standardized form. Many insurers use proprietary forms with different definitions, exclusions, and coverage grants. Your experience with one carrier's policy isn't transferable to another's without detailed review.

Internal sublimits fragment your declared limit. The policy limit on your declarations page isn't the available limit for every coverage. Cyber policies often have separate sublimits for social engineering, cyber extortion, digital asset restoration, regulatory defense, and business interruption. A $5 million policy might only provide $250,000 for a business email compromise loss if social engineering has its own sublimit.

What This Means for Your Team

Your underwriting questionnaire is now a technical audit document that will be forensically verified if you file a significant claim. This changes how you should approach application completion, policy maintenance, and incident response planning.

First, understand that your insurer's forensic investigators have tools to reconstruct your security posture at the time of an attack. They can determine which controls were active, where they were deployed, and when they were configured. If your application states you use MFA for administrative access but your domain controllers weren't protected, the forensic report will document that gap.

Second, recognize that changes to your IT environment during the policy period can void coverage even if your original application was accurate. A migration that temporarily disables backup replication, a new VPN that bypasses your MFA requirement, or a cloud tenant that doesn't enforce the same access controls as your on-premises systems can all create misalignment between your policy representations and your actual security state.

Third, accept that late claim reporting under claims-made coverage is not excusable based on lack of insurer prejudice. The notice-prejudice rule that applies to occurrence-based property policies does not extend the reporting requirements of claims-made cyber coverage. If your policy requires claims to be reported within the policy period or within a specified extension period, missing that deadline means no coverage regardless of whether the insurer was harmed by the delay.

Action Items by Priority

Immediate (before your next renewal):

Assign a specific IT administrator to verify every technical control question in your underwriting questionnaire. Don't allow executives to answer questions about MFA deployment, EDR coverage, backup frequency, or patch management based on policy documents or assumptions. The person who actually administers these systems must confirm what is operationally deployed before anyone signs the application.

Within 30 days:

Document your current security control deployment with sufficient detail to defend against a future forensic comparison. Create a snapshot showing where MFA is required, which systems have EDR agents, how backups are configured, and what your privileged access management actually enforces. Retain this documentation with your policy file so you can demonstrate what existed at inception if you face a claim investigation.

Within 90 days:

Establish a change-control notification process that flags IT infrastructure changes requiring insurer notification. Your policy may contain a failure-to-maintain provision or other language tying coverage to continued operation of specified controls. If you're planning a cloud migration, deploying new remote access, or making other significant infrastructure changes, determine whether your policy requires advance notice or whether the changes create a material change in risk that must be reported.

Before your next application:

Review your policy for retroactive dates, prior-knowledge provisions, waiting periods, and internal sublimits. When moving coverage between insurers, verify continuity of retroactive dates. If you've experienced network anomalies, unexplained access attempts, or other uncertain circumstances during the prior policy period, address them explicitly in your renewal application rather than allowing them to become prior-knowledge issues if they develop into claims.

Map your actual wire transfer exposure against any social engineering sublimit. If your finance team regularly processes six-figure wire transfers but your cyber policy provides only $100,000 for social engineering losses, you have a coverage gap that requires either a higher sublimit or a separate crime policy review.

Conclusion

Your cyber insurance application is more than a formality; it's a binding document that can impact your coverage. Ensure your team is prepared to accurately represent your security controls and maintain them throughout the policy period. By doing so, you can protect your organization from the financial fallout of a cyber incident and avoid the risk of policy rescission.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like