Cyber insurance is not the safety net it used to be. Coverage that once relied on a signed application is now conditional on specific controls being in place at the time of an incident. Firms are discovering, only after a breach, that the answers on the form and the environment behind them did not match.
That mismatch is where claims fail. Insurers now check the detail, and the detail is where partial implementations show up.
Why the rules have changed
This shift has been building for a few years. Claim volumes climbed sharply through 2023 and 2024, ransomware losses pushed several carriers into the red, and the industry walked away from the honor system it used to run on. Underwriters now come with detailed technical questionnaires that require documented evidence, and adjusters compare the answers on the application to what was in the environment when the incident happened. Marsh McLennan’s analysis of cyber controls has quantified how much specific hygiene practices reduce breach likelihood, and insurers are underwriting off that data, and self-attestation on the application form no longer carries the weight it did. When a claim gets denied post-breach, the reason is usually specific. A control the applicant said was in place was not, and the missing piece is often where the intrusion happened.
For law firms, accounting practices, and other regulated businesses across the DMV, the underwriting standards behind coverage are unlikely to loosen again. Here are five hygiene areas where the denials most often show up.
1. MFA everywhere, not just email
Multi-factor authentication moved from best practice to policy condition around 2022, and by 2024 it appeared on almost every application questionnaire. Insurers now require more than just a yes-or-no response. Post-breach investigators check whether MFA was in place on email, on VPN, on remote desktop, on cloud admin consoles, and on privileged accounts, and a single unprotected login path is enough to deny. Verizon’s Data Breach Investigations Report has for years found stolen credentials to be one of the top initial access vectors, which is why carriers keep tightening what qualifies as MFA coverage across email, VPN, remote desktop, cloud admin consoles, and privileged accounts.
If someone mapped every login route into your firm’s systems this afternoon, could you name the ones without MFA in front of them?
2. Patch cadence
Insurers now ask how quickly critical patches move from vendor release into production, especially on anything internet-facing. Marsh’s data links a seven-day patch window on high-severity vulnerabilities to a measurable drop in incident probability, and that window has become an underwriting benchmark. Firms that treat it as a stretch goal often struggle to produce the timestamps a claims adjuster will ask for later.
When the last critical patch was released, how long did it take to reach every server and every laptop?
3. Backups you can prove work
Every firm has backups. Few can produce the results of a recent restore test. Insurers know the difference, because ransomware groups target backups directly, and CISA’s #StopRansomware guidance has for years told organizations to maintain offline, encrypted backups and to regularly test the availability and integrity of those backups in a disaster recovery scenario. Underwriters now ask when the last full restore test happened, and adjusters ask to see the log.
When was the last time someone at your firm did a full restore, timed it, and wrote down what worked and what did not?
4. Endpoint detection
Traditional antivirus has largely dropped out of underwriting requirements at the mid-market level. Endpoint detection and response, which watches for suspicious behavior across the fleet, catching activity that signature-based tools miss, is what most carriers expect to see deployed across the entire fleet. Where it is missing from a subset of endpoints, or where the deployment covers office machines but not the laptops used outside the office, that is often where the intrusion happens.
If a laptop belonging to someone at your firm was compromised outside of working hours, would anyone know before the next business day?
5. A documented IT policy
Insurers ask to see the written document itself. They want to see the file that sets out who has access to what, how new starters are onboarded and leavers offboarded, how incidents get reported and to whom, and how often the environment is reviewed. Firms without one increasingly find that a claim gets challenged even when the underlying security held up, because the paperwork the policy required simply did not exist.
If your broker asked for your written IT policy on a call tomorrow, would there be a document to send, or would it need to be pieced together first?
The question that matters
These questions are diagnostic in intent. Asking them is what closes the distance between what a policy assumes and what a firm can prove. That distance has grown as carriers moved further toward evidence-based underwriting, and it is likely to keep growing.
The next piece in this series will cover the practical side of these questions and what firms can do to close them. Until then, a thorough look at what is running across the firm’s environment is often the fastest way to find out.
If a claim landed on your desk tomorrow, and an adjuster began asking the questions above, would your policy pay out?



