Ransomware ready? Take the 3-minute assessment

What Cyber Insurance Underwriters Actually Test For

BLUF: Insurance renewal and security effectiveness are two different questions, asked by two different parties, with two different incentives. A clean underwriting review protects the institution’s balance sheet if a claim is filed. It says very little about whether the institution would actually withstand an attacker. Leaders who treat one as evidence of the other are exposed twice over: once to the attack they never tested for, and again to a claims dispute if the coverage they believed they had turns out to rest on attestations that weren’t accurate.

The Assumption Worth Checking

A renewal comes back clean. Premium holds steady or drops. The underwriting survey clears without a follow-up call. It is a natural moment for a security leader to exhale and read the outcome as validation: the program passed inspection.

That read is understandable and it is also a mistake. An underwriter is not evaluating whether your organization would survive contact with a motivated attacker. An underwriter is pricing the likelihood and cost of a claim across a portfolio of similar companies, using a set of proxies that are fast to collect, consistent to score, and defensible in an actuarial model. Those proxies correlate with risk. They are not the same thing as risk.

Conflating a clean renewal with a validated security posture is where institutions get exposed, and it is worth separating the two questions cleanly before going further: what does an underwriter actually look at, and what does that leave uncovered.

What Underwriters are Actually Evaluating

Cyber insurance applications have converged on a fairly standard set of controls over the past several renewal cycles: enforced multi-factor authentication, particularly on remote access, email, and privileged accounts; endpoint detection and response coverage; backup architecture, with specific attention to whether backups are immutable and segmented from the production network; privileged access management; a documented incident response plan; and security awareness training on a defined cadence.

Most of what reaches the underwriter is self-attested: a named officer, often the CISO, signs an application affirming these controls are in place. Verification at the point of underwriting is typically limited to external scanning, what an internet-facing footprint reveals about patching, exposed services, and known vulnerabilities. That scan tells an underwriter something real, but it only sees what faces the internet. It cannot see whether MFA enforcement has gaps internally, whether EDR alerts are actually triaged, or whether the incident response plan has ever been tested against a realistic scenario.

The underwriter is building a defensible, portfolio-scale estimate of loss probability. That estimate is priced against actuarial data across an industry vertical and a company size band, not against your specific architecture, your specific vendor relationships, or the specific way an attacker would actually move through your environment once inside.

That scrutiny is not easing. The National Association of Insurance Commissioners reported that US cyber claims rose nearly 40 percent in 2024, to almost 50,000, even as direct written premium fell for the first time since the agency began tracking the market in 2015. Insurers absorbing more claims against a flatter premium base lean harder on the control checklist, not softer.

Presence is not the Same Question as Effectiveness

This is the technical gap that matters most, and it is the same gap offensive security work exists to close. A checklist captures whether a control exists. It does not capture whether the control holds up under the conditions an actual attacker creates.

MFA can be enforced on the systems an application asks about and still leave a path open through a service account, a vendor integration, or an authentication fallback outside the questionnaire’s scope. EDR can be deployed across every endpoint and still be misconfigured, unmonitored after hours, or tuned in a way that misses the specific technique an attacker uses to get past it. A written incident response plan can sit as a document nobody has walked through, meaning the first real test happens during an actual incident, against a live adversary.

None of this means underwriting surveys are worthless, only that they answer a narrower question than leadership tends to assume. Whether a control is present is a reasonable proxy for loss probability at the scale an insurer operates. Whether that control would actually stop or meaningfully slow a specific, motivated attacker is a different question entirely, and it is the one offensive testing, red team engagements, and adversary emulation are built to answer. A penetration test interacts with your controls the way an attacker would. An underwriting questionnaire interacts with them the way an actuary would. Both are legitimate. They are not interchangeable, and only one tells you whether you would actually hold.

Two Parties, Two Incentives, No Conflict of Intent

None of this is a criticism of insurers. They are solving a real problem at genuine scale: pricing risk consistently across thousands of policyholders, fast enough to issue coverage on a reasonable timeline and defensible enough to survive regulatory and reinsurance scrutiny. A control checklist, verified by attestation and a light external scan, is a rational instrument for that job.

An institution’s security program is solving a different problem: whether it can withstand a targeted, adaptive adversary actively looking for the gap between what the questionnaire asked and what actually protects the environment. That adversary does not care what your application said. It cares what is actually true in production, today.

Both instruments do their job correctly. The failure happens when an institution uses the output of one to answer the question posed by the other.

The Sharper Risk Hiding Underneath the False Confidence

The cost of this confusion is not only strategic. It can be contractual, and two cases, one very recent, make the stakes concrete in two different ways.

In July 2025, the City of Hamilton, Ontario disclosed that its cyber insurer had denied the claim tied to a February 2024 ransomware attack that disabled roughly 80 percent of the city’s network. The denial did not turn on whether the attack happened or whether ransomware was covered. It came down to one control: MFA had not been fully implemented at the time of the breach, and the policy specifically excluded coverage for losses where the absence of MFA was the root cause. The recovery bill came to $18.3 million CAD, and taxpayers are covering it directly. Hamilton did not misrepresent anything on an application; the gap was between the control the policy required and the control actually running in production the day the attacker got in.

A related but distinct mechanism produced a similar outcome for International Control Services, an Illinois electronics manufacturer, in 2022. ICS’s application represented MFA was deployed across the organization’s digital assets. After a ransomware attack, the insurer’s investigation found MFA had only been implemented on the firewall, not the server that was actually compromised. The insurer moved to rescind the policy for material misrepresentation, and the parties stipulated to void it from inception, leaving ICS with no coverage at all.

Two different legal mechanisms, the same underlying failure. Hamilton lost coverage because a required control had lapsed by the time of loss. ICS lost coverage because a required control was never accurately represented in the first place. Both institutions learned the same thing at the worst possible moment: the gap between what was attested and what was actually deployed does not surface until a claim forces the comparison.

What This Means for Your Organization

Verifying what is actually deployed, not what is documented as deployed, before the next renewal cycle is not a compliance exercise. It is the difference between coverage that holds and coverage that evaporates at the exact moment it is tested.

A few actions worth taking before your next renewal:

A clean renewal is worth having. It is not a substitute for knowing, with evidence rather than attestation, what would actually happen the day an attacker shows up.

References

Final CTA Section
GET STARTED

Ready to Strengthen Your Defenses?

Whether you need to test your security posture, respond to an active incident, or prepare your team for the worst: we’re ready to help.

📍 Based in Atlanta | Serving Nationwide

Discover more from Satine Technologies

Subscribe now to keep reading and get access to the full archive.

Continue reading