Why do cyber insurance claims get denied?

Two documented patterns stand out. In a 2022 US case, an application said MFA was in place across the company, and both sides agreed to void the policy. In Hamilton, Ontario, CBC reported the city's insurer would not cover part of its claims because MFA was missing in many departments. Read your policy's conditions and make every yes true.
Is there a list of reasons?
Not a reliable one. You'll see numbers online for how many cyber claims get denied, and we haven't found one that traces back to an insurer or a regulator, so we don't repeat any of them. What we can point to are two cases with a public record behind them, and they went wrong in two places.
The first is the application: something the business said that turned out not to be true. The second is the policy itself: something about security that the policy cared about, and that wasn't in place when the attack came. Both cases turned on MFA. The checklist covers every other item.
What went wrong in the 2022 US case?
The application. In 2022, a US insurer went to court against its customer, saying the customer's application had stated that MFA was in place across the company. It never reached a ruling: both sides agreed to void the policy, and the court entered an order saying it was void. What happens if you answer the application wrong goes through it in more detail.
Applications commonly spell out the link between your answers and your policy: by accepting the insurance, you confirm the facts on the application are true, and those facts form the basis of the policy.
What happened in Hamilton?
This one was about the policy, not the form. CBC reported that the City of Hamilton's insurer would not cover part of the city's claims after its cyberattack, because MFA was missing in many city departments.
A city isn't a small business, and its policy won't look like yours. The thing it turned on, though, is one most forms ask about, starting with MFA on email.
Who decides whether a claim is paid?
The insurer, under the policy you hold. Nobody else can tell you ahead of time how a claim will go, and that includes us. What you control is whether the answers you gave are true and whether you've met what your policy asks of you.
What to do next
- Find the conditions and exclusions in your policy and look for anything about MFA, backups or updates.
- Make every yes on your application true, and keep dated proof. How to save proof shows what to keep for each item.
- If an answer you've already given isn't true, tell your broker.
Common questions
Is it true that most cyber insurance claims get denied?
We haven't found a trustworthy source for any denial rate, so we can't say. Be wary of a percentage that doesn't name where it came from.
If I answer yes to everything, will my claim be paid?
Not because of the form alone. Only the insurer decides, based on the policy and what happened. True answers take one possible problem off the table.
Who signs the application, and does that matter?
It does, because the signature is what makes the answers a promise. Who should sign the application covers it.