
Cyber insurance has no dominant standard form, and important coverage differences can be found in the application, policy definitions, exclusions, sublimits and reporting requirements.
A cyber insurance application signed by International Control Services Inc.’s CEO and the employee responsible for the company’s network and information security represented that the company used multifactor authentication for administrative or privileged access.
That representation proved costly.
In 2022, International Control Services suffered a ransomware attack and submitted a claim under its $1 million Travelers cyber policy. During its investigation, Travelers determined that the company “only used MFA to protect its firewall, and did not use MFA to protect any other digital assets,” according to its subsequent lawsuit — including the server targeted in the ransomware attack.
Six weeks after the attack, Travelers sued in federal court seeking rescission of the policy based on alleged material misrepresentations in the application. Within weeks, International Control Services agreed to rescission, and the court entered an order declaring the policy void from its inception.
For producers accustomed to property and general liability coverage, the case illustrates one of the important differences in cyber insurance: representations about an insured’s cybersecurity controls can become coverage issues after a loss, when forensic investigators can compare the application answers with the security measures actually operating on the insured’s network.
That is only one of the coverage issues producers need to consider. Cyber insurance remains heavily dependent on individual carrier forms, applications and endorsements. Producers who want the underlying vocabulary first can start with our companion primer, ten cyber terms every producer should know. Here are ten areas deserving particular attention.
1. There Is No Dominant Standard Cyber Form
Cyber insurance does not have a dominant standardized form comparable to the ISO forms familiar to producers in many traditional commercial lines.
ISO publishes cyber forms, but many insurers use proprietary cyber wordings. Terms, definitions, exclusions and coverage grants can therefore vary significantly between insurers and sometimes between renewals with the same insurer.
Proprietary wording also should not be confused with surplus-lines coverage. An admitted insurer may use its own proprietary cyber form, subject to applicable filing and regulatory requirements, while surplus-lines insurers have greater freedom of rate and form.
The practical point for producers is the same in either market: prior experience with another insurer’s cyber policy is not a substitute for reviewing the wording actually being offered to the client.
2. The Application Is Not Just a Questionnaire
The International Control Services case demonstrates why cyber applications require particular attention.
Cyber insurers routinely ask applicants about specific security measures, including MFA, endpoint detection and response, backups, patching practices and protections for privileged or administrative access.
Those are not questions that should be answered based on assumptions about the insured’s network.
After a significant cyber loss, forensic investigators may be able to determine which controls were operating, where they were deployed and when they were active. That creates the possibility of directly comparing the insured’s application representations against the network environment that existed before the attack.
The International Control Services application had an additional safeguard: it was signed not only by the CEO but also by the employee responsible for network and information security. Nevertheless, Travelers alleged after its investigation that the company’s MFA deployment did not correspond with the representation in the application.
The International Control Services dispute arose outside Massachusetts, and Massachusetts law would frame the question somewhat differently — though not necessarily in the insured’s favor. Under longstanding Massachusetts law, a misrepresentation in an insurance application does not void a policy unless it was made with intent to deceive or it increased the risk of loss. Producers should not read that as a safe harbor. When the misrepresented item is a core control such as MFA, an insurer can be expected to argue that its absence increased the risk of loss as a matter of law, because the carrier relied on the representation in underwriting the risk. Whether a given misstatement meets that standard is fact-specific, but an insured whose application answers do not match its network should not assume the Massachusetts statute will preserve coverage.
The lesson for producers is straightforward. Technical application questions should be verified by the people who actually administer the client’s systems before the application is signed and coverage is bound.
3. Security Controls May Have to Be Maintained Throughout the Policy Period
Getting the application right at inception may not end the issue.
Some cyber forms contain provisions requiring insureds to maintain security controls represented during underwriting. A control that existed when the application was completed but later was disabled, bypassed, or allowed to lapse can therefore present a separate coverage issue.
That possibility becomes particularly important when an insured changes its IT environment during the policy period. A cloud migration, new remote-access arrangement, additional server or other infrastructure change can alter the security environment the insurer originally underwrote.
Producers should determine whether the policy contains a failure-to-maintain provision or other language tying coverage to the continued operation of specified security controls. Clients also should understand that changes to their systems during the policy period can have insurance consequences.
4. Late Notice Can Mean No Coverage
Timing matters differently under claims-made coverage.
Cyber third-party liability coverage is commonly written on a claims-made or claims-made-and-reported basis. When the policy requires a claim to be made or reported within a specified period, an insured should not assume that a late report can be excused simply because the insurer suffered no prejudice.
Massachusetts does not apply the occurrence-policy notice-prejudice rule to extend the reporting requirement of a claims-made policy. Prejudice to the insurer is irrelevant when the insured fails to satisfy the reporting requirement necessary for claims-made coverage.
First-party cyber coverages can have their own discovery and reporting requirements. Forensic investigation also may reveal that an intrusion began well before the insured discovered it, potentially raising separate prior-knowledge or policy-period issues.
Producers should identify the applicable reporting requirements and encourage insureds to report potentially covered claims and circumstances promptly and in accordance with the policy.
5. Social Engineering May Have Its Own Sublimit
A fraudulent wire transfer does not necessarily have access to the policy’s full cyber or computer-fraud limit.
Business-email-compromise schemes frequently involve a criminal impersonating an executive, vendor or other trusted party and persuading an employee to voluntarily transfer funds. Cyber and crime policies may treat those losses differently from losses caused by direct unauthorized access to a computer system.
Coverage for social engineering may be provided through a separate insuring agreement or endorsement carrying its own sublimit. Some forms also impose verification requirements before funds are transferred.
For producers, the important number is therefore not simply the overall policy limit. The social-engineering limit should be reviewed against the insured’s actual wire-transfer exposure, and the insured should understand any verification procedures required by the policy.
Cyber and crime policies should also be reviewed together, as both potentially address fraudulent-transfer losses.
6. Modern War Exclusions Require a Fresh Reading
Cyberattacks have forced insurers and courts to address war exclusions originally drafted for a different type of risk.
High-profile litigation involving malware attacks raised questions about whether traditional war or warlike-action exclusions applied to non-kinetic cyberattacks. The insurance market responded with newer cyber exclusions addressing issues such as nation-state attribution and attacks causing widespread or significant effects.
The result is that producers should not assume that a familiar-looking war exclusion operates in the same way as language they have seen in other commercial policies.
The wording matters. Producers should examine how the policy addresses attribution, state-backed actors, and widespread attacks, as well as any provisions that preserve coverage when an insured is affected by collateral damage in a broader attack.
7. Retroactive Dates and Prior Knowledge Can Reach Back Before Inception
A newly issued cyber policy does not necessarily cover every cyber incident discovered during its policy period.
Claims-made coverage may include a retroactive date restricting coverage for events originating before that date. Prior-knowledge provisions can create a separate issue when specified individuals knew, before the application, of circumstances that could reasonably be expected to produce a claim.
Cyber losses make these provisions particularly significant because the date an attack is discovered can differ significantly from when the attacker first entered the network
A forensic investigation following a loss may establish that unauthorized access began months before the insured detected the intrusion.
When moving cyber coverage between insurers, producers should therefore pay particular attention to continuity of retroactive dates. Renewal and replacement applications should also carefully address known incidents, network anomalies, and any other undetermined or unexplained circumstances.
8. Business Interruption Has Its Own Coverage Traps
A cyber event that shuts down an insured’s operations does not necessarily produce business-interruption coverage from the moment the system goes offline.
Cyber business-interruption coverage commonly includes a waiting period that operates as a time-based deductible before coverage attaches. Waiting periods commonly fall in the range of six to 24 hours, although the actual period is carrier- and policy-specific.
The applicable trigger also matters. Coverage can depend upon whether the interruption resulted from a security failure, system failure or another defined event.
Dependent or contingent business-interruption coverage raises another issue: whether the policy responds when the insured’s own network remains operational but a cloud provider, technology vendor or other dependent business suffers the cyber event.
Producers should review the waiting period, applicable coverage trigger, period of restoration and any separate terms or sublimits applying to dependent business interruption before presenting the coverage to the client.
9. The Policy Limit May Not Be the Available Limit
The declarations page does not tell the entire coverage story.
Cyber policies can contain internal sublimits for individual coverages such as cyber extortion, social engineering, digital-asset restoration, regulatory matters and dependent business interruption.
Retentions and waiting periods can further affect the amount recoverable after a loss.
Another important issue is whether defense costs and other expenses are paid within the policy limit. When defense expenses erode the available limit, legal, forensic and other covered costs can reduce the amount remaining for settlements or other covered losses.
Cyber policies also may require the insured to use insurer-approved breach counsel, forensic investigators and other vendors. Incurring substantial expenses before complying with those requirements can create additional coverage disputes.
Producers should map the policy’s limits, sublimits, retentions, waiting periods and vendor requirements rather than presenting only the headline aggregate limit.
10. Producers Face Cyber Exposure on Both Sides of the Transaction
Cyber presents a dual exposure for insurance agencies.
The first arises from the placement itself. An incorrect application representation, misaligned retroactive date, inadequate social-engineering sublimit or overlooked policy restriction can lead to an E&O claim if the insured later alleges that the coverage obtained did not provide the protection expected.
Documentation therefore matters. Producers should identify important limitations, document discussions concerning coverage options and make clear that technical representations on the application need to be verified by the client’s appropriate personnel.
The second exposure belongs to the agency itself.
Massachusetts requires businesses owning or licensing personal information concerning Massachusetts residents to maintain a written information security program and appropriate safeguards under the Commonwealth’s data-security requirements. Insurance agencies and other insurance businesses handling protected personal information have their own obligations independent of the cyber coverage they place for clients. Insurance entities are themselves among the most-targeted holders of sensitive data; our ranked breakdown of what cyber losses cost insurance entities shows how quickly those losses climb.
An agency advising clients about cyber risk therefore should not overlook its own information-security practices.
Cyber Coverage Requires More Than Comparing Premiums and Limits
Cyber insurance requires producers to bridge two subjects that traditionally have been handled separately: the client’s technology environment and the language of its insurance policy.
The International Control Services case demonstrates the potential consequences when those two do not correspond. An application representation concerning MFA became central after a ransomware attack because the insurer’s investigation could compare what had been represented during underwriting with what was actually operating on the company’s network.
But the application is only the beginning.
Failure-to-maintain provisions, claims-made reporting requirements, social-engineering sublimits, war exclusions, retroactive dates, business-interruption waiting periods, defense-within-limits provisions and vendor requirements can all materially affect the coverage available after a cyber event.
For producers, that makes cyber insurance less suitable for a routine renewal process based primarily on premiums and headline limits. The application should involve personnel who understand the client’s network, while the policy itself should be reviewed for the provisions that determine when coverage applies and how much will actually be available after a loss.
The essential discipline is simple: verify the application, preserve continuity when changing insurers, identify the major sublimits and reporting requirements, and read the form being issued rather than assuming it operates like the cyber policy it replaces. For the case to make to a client still weighing whether to buy cyber coverage at all, see our talking points on why cyber coverage isn’t optional.