What is a Cyber Insurance Attestation?
A cyber insurance attestation is a signed statement about your security controls. If it's inaccurate, the insurer may deny the claim. How to answer defensibly.
What Underwriters Actually Ask
Cyber applications have moved from general questions to specific, verifiable ones. The current standard set:
Multi-factor authentication. Not whether MFA exists, but on which systems, for which users, using which methods. Remote access, email, privileged accounts, and remote administrative tools are asked about separately.
Endpoint detection and response. Which product, what percentage of endpoints, whether it is monitored and by whom.
Backups. Whether backups are offline or immutable, whether they are segmented from the production domain, and when the restore was last tested.
Privileged access management. How administrative accounts are controlled, whether standing privilege exists, whether there is session monitoring.
Email security. Filtering, DMARC enforcement, and whether the organization runs phishing simulations.
Patch and vulnerability management. Cadence, mean time to patch critical vulnerabilities, and whether internet-facing systems are prioritized.
Incident response. Whether a plan exists, when it was last exercised, and whether there is a retained IR provider.
End-of-life software. Presence of unsupported operating systems or applications in the environment.
Why the Answers Are Frequently Wrong
Rarely through intent. The person completing the application is usually a CFO, controller, or office manager who is not the person who knows. They ask IT, receive a summary, and transcribe it.
Common failure patterns:
Aggregate answers to specific questions. Do you have MFA? Yes — on email, for most users, with SMS fallback enabled, and not on the VPN. The application says yes.
Policy described as practice. Do you patch critical vulnerabilities within 30 days? The policy says 30 days. Actual mean time to patch is 90. The application reports the policy.
Backups counted without verification. Are backups offline or immutable? The backup product has an immutability feature. Whether it is enabled, whether the repository is domain-joined, and whether a restore has ever been tested are three separate questions the application does not ask.
Drift after submission. Answers accurate at submission become inaccurate over the policy period as configurations change and nobody revisits the application.
The Consequence
Insurers investigate claims. A material misrepresentation on the application can support rescission — treating the policy as void from inception — or denial of the specific claim. That outcome arrives at the worst possible moment: after an incident, when the organization is spending on response and expecting reimbursement.
Litigation in this area has been active. The pattern is consistent: the insurer identifies a gap between what the application said and what the environment contained, and disputes coverage on that basis.
How to Answer Defensibly
Have the technically accurate person answer, or verify. Whoever signs should not be transcribing a summary they cannot evaluate.
Evidence every answer. A configuration export, a policy screenshot, a report. If an answer cannot be evidenced, it should be qualified rather than asserted.
Qualify partial coverage explicitly. MFA on email and VPN for all users; SMS fallback enabled; not deployed on legacy ERP is a better answer than yes. Underwriters price accurately from accurate information, and the qualification is what protects the claim.
Keep the evidence file. Retain what supported each answer, dated. If coverage is later disputed, that file is the defense.
Re-verify at renewal rather than rolling forward. Environments change.
Consider independent verification. An external assessment produces evidence the insurer will find more credible than self-report, and it surfaces the gaps before the application does.
The Diligence Angle
A target's cyber insurance application is an underused diligence document. It is a signed, dated statement by management about the security controls in place. Comparing it against what an assessment actually finds is one of the fastest ways to evaluate the reliability of management's representations generally — and any material gap is both a coverage risk and a rep-and-warranty issue.
Related Reading
The Gap That Shows Up at Claim Time
The recurring pattern in coverage disputes: an application states that multi-factor authentication is deployed across remote access. The organization is then compromised through a remote access path where MFA was not in fact enforced — a legacy VPN, a service account, a third-party connection.
The insurer investigates, identifies the discrepancy, and disputes coverage. The organization discovers the gap between its attestation and its environment at the moment it needs the policy most.
The through-line across the 2025-2026 intrusion wave reinforces this. Organizations reported MFA coverage and were compromised through session token theft and helpdesk resets anyway, because the method deployed was not phishing-resistant. Whether that constitutes a misrepresentation depends on the exact question and the exact answer — which is precisely why the specificity of both matters.
is the remedy an insurer may pursue when an attestation materially misstates the controls in place — treating the policy as void from inception, after the incident has already occurred.
.png)