Cyber insurance can provide valuable financial, legal and technical support after a cyberattack—but simply having a policy does not guarantee that your claim will get paid out
If your actual cybersecurity practices don’t match what was represented on your application, you risk delaying the claim, triggering a difficult negotiation, or, in the worst case scenarios getting a denial of coverage.
This is why your cyber insurance renewal should never be treated as a form you automatically approve and return. In this article, we’ll address what small business owners need to do to ensure the cybersecurity insurance they have and the practices they have in place will actually cover them in the event of a breach or issue.
How To Ensure You’re Covered
Cyberinsurance applications have become much more detailed in the last few years. In addition to basic information about your company, they often ask whether you have a comprehensive list of cybersecurity tools:
- Multi-factor authentication (MFA)
- Endpoint and email security
- Employee phishing training
- Protected backups
- A regular patching process
- An incident-response plan
- Funds-transfer controls
- Device encryption
- Unsupported software
These are technical questions—and even a well-meaning business owner or office administrator could answer them honestly and still provide incorrect information.
However, cyber insurance applications are legally binding representations of your company’s security controls. If you state that MFA protects your backups, for example, but an investigation finds that it was never enabled, the carrier may have grounds to challenge your claim. This is the last situation you want to navigate while recovering from an attack.
3 Reasons Cyber Insurance Claims Run Into Problems
Most claim issues fall into three categories: misrepresentation, coverage gaps and exclusions.
1. Misrepresentation
Misrepresentation occurs when the controls described on the application do not match what is actually in place. This is most often caused by someone completing the form without enough technical input rather than deliberately providing false information.
2. Coverage Gaps
Coverage gaps arise when the policy does not reflect how the business operates. Your risks may differ depending on whether you use cloud-based systems or on-site servers, where your backups are stored, and how much you rely on third-party vendors.
3. Exclusions
Exclusions identify incidents the policy will not cover. Pay close attention to exclusions involving social engineering, funds-transfer fraud, and third-party business interruption.
Unfortunately, these are not unusual scenarios. An attacker may compromise an employee’s email account, impersonate your company and send customers fraudulent payment instructions. Customers believe they have paid you, but the money goes to the attacker. If funds-transfer fraud is excluded, the policy may offer far less protection than expected.
What Your Insurance Provider Should Do
A good cyber insurance provider should do more than email you an application. Look for a broker or agent who asks questions about your systems, vendors, backups, financial controls and security practices. They should help ensure your answers are accurate and clearly explain how policy exclusions affect your protection.
The more effort a provider makes to understand your business, the better equipped they will be to identify potential gaps.
Your Takeaway: Don’t Auto-Approve Your Renewal Without Ensuring You’re Doing What You Say You’re Doing
Your technology environment might have changed considerably in just one year. If you’ve replaced software, adopted a new vendor, moved systems to the cloud or given additional employees access to sensitive data, it’s time to review your security posture. The best way to do that?
Before you submit your renewal, schedule a brief review with your IT or cybersecurity provider and confirm that every listed control is active, and that your insurance application reflects your current systems.
At Atlantic Data Systems, we can help you review the technical portions of your cyber insurance application, document your existing controls and identify gaps that may affect your coverage. We can also help develop incident-response and funds-transfer policies.
The short conversation before renewal is worth the significant time, money and frustration you’ll save if you ever need to file a claim—and we’re happy to help you. Reach out to us today to ensure your cyber security insurance will actually cover you in case of a cyber emergency!