Money
The regulator nobody voted for
No parliament required mid-sized companies to enforce a second factor on email. An underwriting questionnaire did it in about three years.
Last reviewed August 31, 2026
- The questionnaire is the regulation. Effective, and accountable to nobody.
- Cheaper and stricter at once. Competition sets price; loss experience sets terms.
- Your answers are continuing warranties. Not a snapshot taken at purchase.
- Attribution finally matters here. The war exclusion is where a government statement bites.
Answer as the insured
5 controls and 15 answers. What comes back is not a score — it is the next question, which is always some version of the same one. These are the questions the market asks, not advice about your own policy.
On the form
What comes back
Multi-factor authentication
Is multi-factor authentication enforced on email for all users?
The single question most likely to decide whether a policy is written at all. Compromised credentials were the way in for most of the ransomware claims that erased the market's underwriting profit, and this is the control that addresses them at the point of entry.
Yes, on every account, no exceptions.
Underwriter: Can you export the enforcement policy and a list of exempted accounts?
The export is the answer, not the yes. Almost every organisation that says every account has a handful of exceptions — a shared mailbox, a service account, the chief executive's phone — and the list is where the conversation actually starts.
Yes for staff, but a few service accounts are excluded.
Underwriter: Which of those can read mail, and are any reachable from the internet?
Usually survivable, sometimes with a sub-limit. The exclusions that matter are the ones that can be used from outside, and an exempted account that reaches email from anywhere is the gap that the questionnaire exists to find.
Not yet — it is on the roadmap.
Underwriter: None. This one is usually binary.
Declined, or quoted at a price meant to be refused. This is the clearest case of an insurer behaving as a regulator: no law required mid-sized companies to enforce a second factor, and the underwriting questionnaire did it in about three years.
Remote access
Is any remote desktop service reachable from the internet?
The most cited entry point in ransomware claims. It is asked directly because it is cheap to verify from outside and because the answer is very often wrong — not dishonest, wrong.
No, nothing is exposed.
Underwriter: Would you like us to check before you sign that?
The scan is routine and it disagrees more often than anybody expects. An exposure created for a supplier three years ago, on a machine nobody owns any more, is the standard finding and is not a failure of honesty.
Only through the VPN.
Underwriter: Does the VPN require a second factor, and is the appliance patched?
The answer moves the question rather than settling it. An unpatched edge appliance is the other half of this category, and a VPN protected by a password alone is the same exposure with a longer route.
Yes, for a supplier who needs it.
Underwriter: From which addresses, and with what second factor?
Coverage is possible and the terms will name it. Expect a condition requiring the exposure to be closed or restricted within a stated period, which converts an underwriting note into a contractual obligation.
Backups
Are backups tested, and are they reachable from the production network?
Two questions in one, and the second is the one that costs money. Backups that an attacker can reach with the credentials they already stole are not backups; they are a second copy of the problem.
Tested quarterly, and stored offline.
Underwriter: What was the date of the last full restore, and how long did it take?
A date and a duration are evidence; a policy document is not. The duration matters as much as the date, because a restore that works but takes eleven days is a business interruption claim either way.
They run nightly and we have restored single files.
Underwriter: Has anybody ever restored the whole thing?
Restoring one file proves the tape is readable. It does not prove the estate can be rebuilt, and the difference between those two facts is where most of the disappointment in this subject lives.
They run to a share on the same network.
Underwriter: What stops the same stolen credentials reaching them?
Nothing does, which is why this is asked. Expect either a requirement to move them or a ransomware sub-limit, and the sub-limit is the version that surprises people at claim time.
Incident response
Do you have an incident response plan, and when was it last exercised?
The second half is the whole question. Plans are universal; rehearsals are not, and an unrehearsed plan reliably fails at the same three points — who decides, who speaks, and who has the phone numbers.
Yes, and we ran a tabletop four months ago.
Underwriter: Who was in the room, and what did it change afterwards?
An exercise that changed nothing was a presentation. The follow-up actions are the evidence that it was real, and they are what an underwriter is actually asking to see.
Yes, written last year, not exercised.
Underwriter: Does it name people, or roles that have since changed?
Usually acceptable and usually optimistic. A plan naming a role rather than a person is a plan that has never met a Sunday night, and the gap shows up in the first hour rather than in the underwriting.
We would call our provider.
Underwriter: Is that arrangement in a contract, and does it have a response time?
Sometimes accepted, and it changes who is in charge. Note that most policies require you to use the insurer's own panel of responders, so the provider you would call may not be the one who arrives.
Patching
How quickly are critical vulnerabilities on internet-facing systems fixed?
Asked in days because days are auditable. It is also the question most likely to be answered with a policy target rather than a measurement, and the two are rarely the same number.
Within a week, and we can show the ticket history.
Underwriter: What is your slowest one still open, and why?
The outlier is the interesting number. Every estate has one that has been open for a year for a reason somebody can explain, and being able to explain it is worth more than the average.
Our policy says thirty days.
Underwriter: That is the policy. What is the measurement?
The gap between the two is normal and it belongs on the form. Declaring a target you do not hit is the kind of inaccuracy that gets quoted back during a claim, when the wording will be read far more carefully than it was written.
When we notice them.
Underwriter: Who notices, and how?
Coverage will carry conditions, and they will be specific. This is also the honest answer for a great many small organisations, and saying it is safer than declaring a process that does not exist.
Notice what never happens: nobody asks whether you are secure. Every question resolves into whether you can produce something — an export, a date, a ticket history, a list of exceptions. That is not laziness on the underwriter's part. It is the only thing that can be priced, and it is the reason this process changed behaviour where a decade of advice did not.
How did an insurer become the regulator?
For most of the last decade cyber cover was sold the way small commercial lines usually are: a short proposal form, a modest premium, few questions and less verification. The product was profitable because losses were rare, and the questions on the form were closer to marketing than to underwriting.
Ransomware ended that arrangement between 2019 and 2022. Losses arrived at a frequency and a severity that nobody had priced, and they wiped out the underwriting profit of the class. The interesting part is what did not happen next: the market did not withdraw. It stayed, raised prices, and — decisively — started asking questions it intended to check.
The effect on behaviour was extraordinary and almost entirely undiscussed as a security story. A mid-sized manufacturer that had ignored a decade of advice about multi-factor authentication implemented it in six weeks, because the renewal depended on it. Backups were moved off the production network for the same reason. Remote desktop was closed because a form asked, and somebody checked.
Whether that is a good way to run public policy is a separate question from whether it worked. It worked. It also means the security baseline of a large part of the economy is now set by a group of underwriters, reinsurers and brokers who never stood for election, publish no rationale, and can change the requirements at renewal without notice or appeal.
Why is it cheaper and stricter at the same time?
The market in 2026 sends two signals that contradict each other. Rates fell around 5% in the first quarter and the large brokers describe conditions as buyer-friendly. Meanwhile analysts project premium rises of 15 to 20% over the following year, and the underwriting requirements keep tightening.
Both are true because they are produced by different mechanisms. Price is set by competition for the business that carriers want, and there is a great deal of capital chasing it. Terms are set by loss experience, and the loss experience is still the one that removed the profit from the class. So the same insurer will quote you keenly and refuse to quote at all if the second factor is missing.
The practical consequence is that the premium has stopped being a useful signal of how risky anybody thinks you are. An organisation can conclude from a cheap renewal that its posture is fine, when the cheap renewal reflects market capacity and the real assessment lives in the conditions attached to it — which is the part nobody reads.
It also means the direction of travel is unstable in a way that matters for planning. Soft markets in this class have historically ended abruptly, and the organisation that let a control lapse because the renewal was easy is the one that discovers the change at the least convenient moment.
The clause that turns on a government statement
Insurance has always excluded acts of war, for a reason that predates computers: war is not a diversifiable risk, and a market that covered it would be underwriting a loss it could not survive. Applying that logic to intrusions was harder, and from 2023 the London market required its syndicates to carry an exclusion for state-backed attacks.
The wordings that followed do not turn on whether a state was involved, which would be unarguable in most cases, but on scale: whether an attack had a major detrimental impact on the functioning of a state, its essential services or its security. That is a threshold nobody can assess from inside a victim organisation, and it converts a claim into an argument about geopolitics.
Which lands somewhere uncomfortable. Public attribution of an attack to a government changes very little about what a defender does that week — the same systems are rebuilt, the same regulator is notified, the same customers are told. It changes the insurance position, and it is made by intelligence services whose reasoning is not published and whose timing has nothing to do with your renewal.
The reasonable response is unglamorous: read the exclusion before the incident, establish what evidence would be needed to argue on either side of the threshold, and know which of your systems would plausibly be described as an essential service. Doing that in the first week of a crisis, with lawyers on both sides, is the expensive version.
A small subject that decided a lot
174 entries here touch insurance, liability or the cost of an incident. 123 name insurance directly, 19 discuss premiums or price, and 52 concern liability or claims.
The solid portion is the share naming insurance directly: about 77% across the first half of the period and roughly 61% across the second. Coverage peaks in 2015 with 34. The subject stayed small throughout, and that is the interesting part: across the same decade the underwriting questionnaire became the most effective security requirement most organisations of moderate size had ever encountered, and almost nobody wrote about it as a security story. The earliest piece here naming it, Cybersecurity insurance becoming a must have, treats it as a financial product rather than a control.
The reason for the blind spot is structural. Security writing is organised around threats and products, and an insurance form is neither. It arrives through the finance department, it is discussed with a broker, and by the time it changes what a technology team does it looks like a budget decision rather than a security one.
What actually voids a claim?
The common belief is that claims are refused on technicalities buried in the wording. The more frequent reality is simpler and more uncomfortable: the organisation stopped doing something it said it did.
The answers on a proposal form behave like continuing warranties rather than a photograph taken on the day. Enforcing a second factor everywhere in January and granting three exceptions in July is not a lie told at purchase; it is a change in the risk that was never notified, and it is the commonest route to an argument at claim time.
Two others come up repeatedly. Vulnerabilities that were known internally before binding and not disclosed, which converts an ordinary backlog into a non-disclosure. And sub-limits, particularly on ransomware, which are not a refusal at all — the policy pays exactly what it said it would, and the number is a fraction of the headline figure everybody remembered.
The defence against all three is administrative rather than technical. Keep the completed questionnaire. Re-read it when anything material changes. Tell the broker when it does, in writing, and keep that too. It is dull work that nobody is thanked for, and it is worth more at the moment of a claim than any control on the form.
The part that is worth more than the money
For a small organisation the payout is rarely the most valuable thing in the policy. The panel is. A company of forty people that has never handled a serious incident gains, at three in the morning, access to breach counsel, forensic responders and a negotiator it could not have found, retained or afforded on its own.
That access comes with a condition people rarely notice until it applies: most policies require the insurer's own panel to be used. The consultancy you trust, the one that knows your network, may not be an approved firm — which settles in advance who is in the room during the first hour — and engaging them anyway can prejudice the claim. It is a question worth asking before signing rather than during the first hour of an incident.
The panel arrangement also quietly shapes what gets done. Responders paid by an insurer optimise for the insurer's interests, which are mostly aligned with yours and not identical: containing cost, establishing what is covered, and producing a defensible record. Restoring the business quickly is a shared goal; understanding precisely how it happened sometimes is not.
None of that is an argument against buying. It is an argument for knowing who will arrive, who instructs them, and who reads their report first — three questions with clear answers in the contract, and vague ones in most people's expectations.
What can insurance not transfer?
A policy moves money. It does not move consequences, and the distance between those two things is where most disappointment with this product originates.
The costs it handles well are the ones with invoices: investigators, lawyers, notification, monitoring, the negotiator, the rebuild. The costs it handles badly are the ones that arrive as absences — the customer who does not renew, the tender that is not won, the eighteen months in which the technology team ships nothing because it is remediating. Those are larger for most organisations and they are nearly impossible to underwrite.
Nor does a policy transfer obligations. Regulatory duties, contractual commitments to customers and the responsibility to notify people whose data was taken all remain exactly where they were. An insurer may fund the work, and the accountability does not move an inch.
Which suggests the sane framing. Insurance is a treatment for the tail — the event that would otherwise end the organisation — and a poor substitute for anything else. Bought for the tail it is excellent value. Bought as an alternative to the controls on the questionnaire, it is an expensive way of finding out what the exclusions say.
If you never buy a policy, read the form anyway
There is a use for all of this that costs nothing and requires no broker. The questionnaire is, accidentally, the best short list of controls that anybody has published — not because underwriters are wiser than security teams, but because they are the only people who lose money by being wrong about which controls matter.
Everything on it earned its place by appearing in claims. Multi-factor on email, exposed remote access, backups an intruder can reach, an unrehearsed plan, an unmeasured patching interval: that is not a framework assembled by committee, it is a list of the ways organisations of ordinary size actually lose. A team with no intention of insuring anything can work through it and be measurably better off.
It is also a usefully short list, which is its real advantage over the frameworks it competes with. Nobody has ever completed a control catalogue of several hundred items; a great many people have completed a proposal form, because it fits on a few pages and somebody was waiting for it. There is a lesson in that for anybody writing security guidance, and it has nothing to do with the contents: the document that gets finished is the one with a deadline and a person on the other end of it, and no amount of rigour compensates for lacking both. Security guidance is almost never written with either, which explains rather a lot about how much of it goes unread by the people it was drafted for, and rather a lot about why a proposal form outperforms it.
Common questions
What does cyber insurance actually cover?
Typically the costs of responding — investigators, lawyers, notification, credit monitoring — plus business interruption and, in many policies, extortion payments. What it rarely covers well is the thing people assume: the long-term loss of customers, contracts and reputation, which is where most of the real damage sits.
Why did insurers start demanding security controls?
Because ransomware losses between 2019 and 2022 wiped out the market's underwriting profit. The response was not to leave, it was to underwrite properly, and the questionnaire became a set of conditions rather than a formality.
Is multi-factor authentication really mandatory?
For email, in practice yes. Many carriers treat it as binary: it is in place, or the risk is declined or heavily sub-limited. No legislature required this of mid-sized companies, and the insurance market achieved it in roughly three years.
Are prices going up or down?
Both, depending on who you ask, which is genuinely unusual. Rates fell around 5% in the first quarter of 2026 and brokers described conditions as buyer-friendly, while analysts projected rises of 15 to 20% over the following year. Price and scrutiny are moving in opposite directions.
How can it be cheaper and stricter at once?
Because competition sets the price and loss experience sets the terms. Capital entering the market pushes rates down while the same underwriters, having been burned, keep tightening what they will write at any price. The premium stopped being a reliable signal of how risky anybody thinks you are.
What is the war exclusion?
A clause excluding losses from state-backed attacks. Lloyd's required its market to carry one from 2023, and later wordings turn on whether an attack had a major detrimental impact on a state's essential services or security — which makes the argument about <a href="/topics/nation-state/">geopolitics</a> rather than about your network.
Could a government statement void my cover?
It can turn a covered loss into a dispute, which in practice is the same problem with a longer timescale. This is the one place where public attribution changes something concrete for an ordinary victim, and it is decided by people who will never see your logs.
What most commonly voids a claim?
Not maintaining a control you attested to. The questionnaire is not a snapshot taken at purchase; the answers behave like continuing warranties, so an exception added in month seven can matter more than anything that was true in month one.
Should a small organisation buy it?
Often yes, and for a reason people underrate: the incident response panel. A small organisation that has never handled a serious incident gets access to lawyers and responders it could not otherwise reach at three in the morning, and that is worth more than the payout in most realistic scenarios.
What should I check before signing?
The sub-limits, the exclusions and the obligation to use the insurer's panel. Ransomware is frequently sub-limited well below the headline figure, and the panel requirement means the responders you had in mind may not be the ones who turn up.
Does having a policy make an attack more likely?
The claim is made regularly and the evidence for it is thin. What is better established is the reverse: the conditions attached to policies have raised the security baseline of a very large number of organisations that would not otherwise have moved.
Is the insurer a good regulator?
It has been an effective one, which is a different question. It answers to shareholders rather than to the public, it protects what is cheap to underwrite rather than what matters most, and it will withdraw from a class of risk with no obligation to anybody. Effective and accountable are not the same thing.
Insurance and liability in the archive
174 entries, peaking in 2015 with 34.
- 90% of IT Decision Makers Believe Organizations Compromise on Cybersecurity in Lieu of Other Goals
November 16, 2021 · channelfutures.com
- 4 ways companies can increase their cybersecurity
November 12, 2021 · techrepublic.com
- What exactly is 5G security, and why is it essential?
October 22, 2021 · securitybrief.asia
- Ransomware grows 1070%, organisations struggle to secure operations
October 6, 2021 · securitybrief.asia
- Hackers Targeted Over 75,000 Mailboxes in a Credential Phishing Campaign
September 29, 2021 · cisomag.eccouncil.org
- 5 Tips for Achieving Better Cybersecurity Risk Management
September 24, 2021 · threatpost.com
- Hardening Cyber Insurance Market Makes Cybersecurity More than a Tech Problem
September 20, 2021 · cisomag.eccouncil.org
- A CISO’s perspective on ransomware payments
September 2, 2021 · urgentcomm.com
- Cyber insurance payouts are incentivizing ransomware attacks
August 26, 2021
- Japanese insurer tokio marine discloses ransomware attack
August 23, 2021
- Avoiding identity theft personally and professionally
August 20, 2021 · murfreesboropost.com
- Ransomware attacks around the world including cyber insurance agencies
July 5, 2021
- Insurer axa hit by ransomware after dropping support for ransom payments
May 17, 2021
- Telstra service provider hit by cyber attack as hackers claim sim card information stolen
May 4, 2021
- Insurance giant CNA hit by new Phoenix CryptoLocker ransomware
March 26, 2021 · bleepingcomputer.com
- Ransomware insurance is becoming more common
January 29, 2021 · itproportal.com
- Ransomware attacks on the rise even as cyber insurers scale back
December 17, 2020 · auto.economictimes.indiatimes.com
- How do i select cyber insurance for my business
December 10, 2020
- Personal information leaked in suspected cyberattack on shirbit insurance
December 2, 2020
- Artificial Intelligence and Machine Learning helping insurance companies with cybersecurity: EY
November 11, 2020 · economictimes.indiatimes.com
- What Are The Fastest Growing Cybersecurity Skills In 2021?
November 2, 2020 · forbes.com
- Hackers claim data breach at paytm mall firm denies
August 31, 2020
- The liability plan to hold software producers accountable for cybersecurity
July 28, 2020
- With ransomware attacks increasing, cyber insurance now seen as a necessity, not a luxury
June 22, 2020 · securitymagazine.com
- 43% of Americans are Comfortable with Insurance Companies Using Artificial Intelligence
May 28, 2020
- Determining liability for security breaches isnt black and white
May 27, 2020
- The Human Brain is Both a Liability and Asset for Cybersecurity: Here’s Why
April 27, 2020
- Fake apps growing threat to personal data, says cybersecurity expert
April 22, 2020
- Demand for cyber security insurance set to rise
April 16, 2020
- Chubb cyber insurer allegedly hit by maze ransomware attack
March 27, 2020