A Columbus business owner calls their insurer after a ransomware incident, expecting the policy they've paid premiums on for years to cover the loss. Instead, they get a reservation-of-rights letter, then a denial. The reason usually isn't fraud. It's that the security controls the business attested to having during underwriting — multi-factor authentication, tested backups, endpoint detection — either weren't fully in place or couldn't be proven after the fact.
This is happening more often, and it's not really an insurance story. It's an IT story that insurance companies are now forcing businesses to confront earlier than they otherwise would.
The Market Changed After the Ransomware Surge
A few years ago, cyber liability applications were short — a page or two, mostly self-attestation, and premiums were relatively low. After a wave of costly ransomware payouts across the industry, insurers tightened underwriting significantly. Applications now run 10-20 pages, ask pointed technical questions, and increasingly require supporting documentation rather than a simple yes or no.
The result: coverage is available, but it's conditional. Insurers aren't just pricing risk anymore — they're requiring businesses to actively reduce it before they'll take it on, and they're reserving the right to walk away from a claim if what was represented on the application doesn't match reality.
Why this matters
Your cyber insurance application is a legal document. If you check "yes" for multi-factor authentication and it's only enabled for half your accounts, or you check "yes" for tested backups and no one has actually tested a restore, that gap can be grounds for a denied or rescinded claim — regardless of intent.
What Insurers Are Actually Asking For Now
Requirements vary by carrier and policy size, but the same handful of controls show up on nearly every serious application. If your last renewal application asked about these, it's not a formality — it's the baseline for coverage:
| Control | What "Yes" Actually Requires |
|---|---|
| Multi-factor authentication | MFA enforced on email, remote access, and admin accounts — not just offered as an option |
| Endpoint detection & response | Active monitoring on all endpoints, not legacy antivirus alone |
| Backup testing | Documented, regularly tested restores — not just confirmation that backups run |
| Patch management | A defined cadence for critical patches, with records showing it happens |
| Security awareness training | Recurring training with completion records, not a one-time onboarding video |
| Incident response plan | A written plan naming who does what in the first 24 hours of an incident |
Notice the pattern: every one of these requires documentation, not just the control itself. A business that has MFA enabled but can't produce evidence of it is in nearly the same position as a business that doesn't have MFA at all when a claim is being reviewed.
The Businesses With the Most to Lose
This applies to every industry, but it bites hardest where a breach involves regulated or sensitive data — healthcare practices handling protected health information, childcare and education providers holding records on minors, financial and professional services firms with client financial data. In those cases, a denied cyber claim doesn't just mean an uncovered ransom or recovery cost. It stacks on top of separate regulatory exposure — HIPAA penalties, state breach notification laws, client and family trust — that a lapsed policy was supposed to help absorb.
The businesses most exposed to a claim denial are usually the ones who most need the payout — because they're also the ones facing regulatory and reputational fallout on top of the breach itself.
How to Get Ahead of Renewal — Instead of Finding Out During a Claim
The good news is that none of this requires guessing. Before your next renewal application lands in your inbox, it's worth working through it deliberately rather than reactively:
- Pull your current policy application and treat every "yes" as a claim you'll need to prove, not just a checkbox.
- Request a documented backup restore test — not a status check, an actual recovery, with the results recorded.
- Confirm MFA coverage percentage across email, VPN, admin accounts, and any cloud platforms — not just whether it's "enabled" somewhere.
- Ask for training completion records going back 12 months, not just confirmation that a program exists.
- Get your incident response plan in writing if it currently lives only in someone's head.
Most businesses find at least one gap between what they assumed was true and what they can actually document. That gap is far cheaper to close in a normal week than to discover during a breach investigation.
The Bottom Line
Cyber insurance is still worth having — a denied claim is a worse outcome than no claim to file, but it's not the same as no coverage. The shift in underwriting standards is, in a strange way, a useful forcing function: the controls insurers now require are the same ones that meaningfully reduce your odds of a serious incident in the first place. Getting your environment to the point where you'd pass a real audit of your application protects you whether or not you ever file a claim.