Your Cyber Insurance Application Is an Audit You Already Signed
Somewhere in your files is a cyber insurance application. Someone in the practice filled it out, probably in an afternoon, probably from memory, possibly with a broker reading the questions aloud over the phone. There were maybe forty questions about multi-factor authentication and backups and how quickly you patch. Somebody answered them, somebody signed, the policy arrived, and nobody has looked at that form since.
That form is the most consequential security document most small practices have ever produced, and almost nobody treats it as one. It is not a survey and it is not marketing. The policy was issued in reliance on it, and an answer that turns out to be wrong can unwind the whole thing on the day you need it. Here is what those questions are really asking.
Overview
A cyber insurance application is a security questionnaire with legal weight attached. The carrier is not curious about your environment for its own sake. It is pricing a risk, and it is doing so on the strength of what you told it, because it has no other way to know. That is why the policy contains language stating it was issued in reliance on the representations in the application, and why a material misstatement in that application can give the carrier grounds to rescind rather than merely to argue about the claim.
Rescission is a harsher outcome than denial, and the difference is worth understanding before you need it. A denied claim means the carrier says this particular loss is not covered. A rescinded policy is treated as though it never existed. Premiums come back, coverage does not, and every loss under it goes with the policy. That is the remedy at issue when an application answer turns out to be inaccurate.
In California, the governing provisions are not obscure. Insurance Code section 331 deals with concealment and section 359 with representations that are false in a material point. Neither one is built around intent. That is the part practices find hardest to accept, and it is the reason the honest answer to a question you are not sure about is to go and look rather than to answer from a reasonable belief formed three years ago.
The Challenge
The first difficulty is that the questions use terms of art and the answers get given in ordinary English. An application asks whether multi-factor authentication is required for all remote access to the network, and the person filling it in thinks about the portal she logs into every morning, which does have it, and answers yes. She is not lying. She is answering a narrower question than the one printed on the page, and the gap between those two questions is where the trouble lives. The word doing the damage is almost always all.
The second is that the person signing usually cannot see the systems. In a nine-person practice the form lands with the owner or the office manager, because it arrived with the renewal paperwork and that is who handles renewals. Neither of them can open a console and check whether the backup actually ran last night, or whether the old file server is still reachable from outside the building. So the answers come from memory, or from a general sense of what the IT company has probably taken care of, and the signature goes on the bottom.
The third is drift. Even an application that was perfectly accurate on the day it was signed describes a building that has since been renovated. A vendor got remote access in March. Somebody left in May and the account is still there. A workstation came out of a closet in June because the front desk needed a second screen. None of those is dramatic on its own, and the aggregate is an environment that no longer matches the document the coverage rests on.
The fourth is that nobody owns the form. It is not the IT provider's document, because the practice signs it. It is not really the broker's, because the broker is relaying questions rather than verifying answers. And it is not treated as the practice manager's, because it looks like paperwork rather than like a security control. So it belongs to no one, and unowned documents do not get checked.
Why It Matters
Four reasons this is worth a morning:
The case everyone cites is real, and most descriptions of it are wrong. In 2022 Travelers sought rescission of a cyber policy issued to International Control Services, an Illinois manufacturer, after a ransomware attack. Travelers alleged the application had represented multi-factor authentication more broadly than it was actually deployed, and that the affected server was not protected by it. The case is worth knowing precisely, because a great deal of what has been written about it is not: it was not litigated to a verdict, and no court weighed the evidence and sided with the carrier. Within weeks the parties stipulated, and in August 2022 the court entered an order rescinding the policy and declaring it void from inception. The reason to get that right is that the actual story is more instructive than the myth. The insured did not lose an argument. It looked at the exposure and agreed to hand the policy back.
Intent is not the shield people assume it is. The most common reaction to all of this is that nobody lied, so nobody is at risk. That is not how the doctrine works in most of the country, California included. A representation can be materially false without anyone intending it, and the remedy attaches to the inaccuracy rather than to the state of mind behind it. Which means the ordinary, well meaning, slightly rushed answer is exactly the kind that causes the problem.
The questionnaire is a free gap analysis, and it is already on your desk. Every question on that form is there because carriers have paid claims arising from its absence. Read as a list rather than as paperwork, it is one of the better plain-language security checklists a small practice will ever encounter, assembled by an industry with money at stake in getting it right. Most practices never read it that way, because it arrives dressed as administration.
A practice under HIPAA has to be able to answer these questions anyway. Nearly every item on a cyber application maps to something the Security Rule already expects: an inventory, a risk analysis, access control, training, contingency planning. If the application is hard to answer, that difficulty is not an insurance problem. It is the same finding the rule would produce, arriving through a different door, and it is the same list our piece on the proposed Security Rule update walks through.
What Organizations Should Watch For
- Any question containing the word all. All remote access, all privileged accounts, all endpoints, all email. These are the questions that get answered about the main case and asked about the whole estate. The old server nobody uses, the vendor login, the owner's laptop, and the account that predates the current system are all inside the word all.
- A signature from someone who could not have verified the answers. If the person who signed cannot say where each answer came from, the practice has attested to a set of facts it did not check. That is the single most common shape of this problem and it is invisible until it is expensive.
- Backup questions answered from the existence of backups. The form usually asks about frequency, about offline or immutable copies, and about whether restores are tested. Having backups answers none of those. Our piece on the difference between backup and recovery covers the gap between a copy existing and a copy working.
- Third-party and vendor access, quietly excluded from your mental picture. Applications increasingly ask whether vendors with network access are held to the same controls. Your EHR support, your imaging vendor, your billing service and your IT provider are all inside that question. Our piece on third-party vendor risk covers how those relationships accumulate without a list.
- Patch timelines given as a policy rather than as a fact. A question about how quickly critical patches are applied is asking what actually happens, not what the standard says. If nobody can produce evidence of the last month of patching, the honest answer is that you do not know, and that is a better answer than a confident number.
- The remote path, again. Questions about remote access assume you can describe every route into the environment from outside the building. Most practices cannot, for the reasons our piece on the accidental remote workforce lays out. An application is a bad place to find that out.
- Last year's answers, copied forward at renewal. Renewal is where an application stops being a snapshot and becomes a habit. If the process is that somebody confirms the previous responses, then a single error becomes a standing representation, refreshed annually without ever being examined.
Recommended Actions
- Find the application and read it as a checklist. Not the policy, the application. Print it, sit down with it, and treat every question as an item to verify. This costs a morning and is the highest yield hour on this page.
- Mark every answer you cannot personally source. Do not correct anything yet. Just separate what you know from what you assumed. The size of the second pile is the finding.
- Get the technical answers from the systems, in writing. Send the unsourced questions to whoever runs your IT, including us, and ask for answers with evidence rather than reassurance. Keep the reply. That reply is what turns a belief into a record.
- Check what the word all actually covers. Walk the multi-factor question across every route into your environment rather than the one you use daily. Where it stops helping is a separate matter, covered in our piece on why multi-factor is not the whole answer, but the application is asking a coverage question first.
- Test one restore before you answer a restore question. A single proven recovery converts the most commonly overstated answer on the form into a fact with a date attached.
- Write down where each answer came from. A one page note listing the question, the answer, the source, and the date. This is the difference between having answered and being able to show why the answer was reasonable, and it is the same evidence a risk analysis wants.
- Tell your broker if you find a gap, before renewal. This is uncomfortable and it is the correct move. A correction made in the open is a conversation about terms. A gap discovered during a claim is a conversation about rescission, and only one of those is survivable.
- Fix the small things the questionnaire found. Most of what it surfaces in a small practice is closeable in a few weeks: a shared login, an account that outlived a departure, a machine that missed the patch cycle. The form is worth more as a work list than as a form.
- Put the review on the calendar for sixty days before renewal. Not the week of. Sixty days gives you room to close a gap before you have to describe it, which is the entire difference between the two versions of this conversation. If you would rather start from a structured picture, the assessment covers most of the same ground, and translating what comes back is part of what managed IT should include.
The SecureLynx Perspective
Observe:
Ours first, since a question we will not answer about ourselves is not a fair one to put to you. SecureLynx answers the same questionnaire for its own carrier, and we answer it from consoles rather than from memory, because we are subject to exactly the doctrine described above. Our coverage is not a claim we make in a brochure either. The limits are written into our client agreement, which is published, and a certificate of insurance is available on written request. You can read what we carry before you hire us, which is the same standard this page is asking you to hold your own file to.
Adapt:
On the client side, most of what a cyber application asks about is not a document problem, it is a record problem. Who has access and since when, whether training happened and on what date, when someone left and what was closed, what is deployed and whether it is current. Those are the things a practice reconstructs from memory at renewal, badly, and they are the things the client portal keeps as dated history rather than as a current state that quietly overwrites yesterday. It is exportable and you hold the primary copy, since ours is a good faith secondary and we say so in writing. That does not fill out your form. It means that when you sit down with it, the answers exist somewhere other than in one person's memory.
Protect:
Then the limits, which we would rather state than have you discover. We are not your broker, we are not your lawyer, and nothing here is advice about your policy or your coverage. Insurance questions belong with the people who carry the licence for them, and a serious one belongs with counsel. What we can do is make the technical answers checkable instead of remembered, and tell you plainly when the honest answer to a question is that nobody currently knows. Point these questions at us first.
Common questions
We answered honestly, to the best of our knowledge. Does that protect us?
Not as much as most people expect. In California, and in most of the country, an insurer may rescind a policy for a misrepresentation that was material to the risk, and intent is generally not the deciding element. California Insurance Code section 331 addresses concealment and section 359 addresses false representations on a material point. Neither turns on whether anyone meant to mislead. That is uncomfortable, and it is also the practical reason to treat the application as a document to verify rather than a form to complete. Good faith is not the same as an accurate answer, and only one of the two is checkable later.
Who in the practice should actually be answering these questions?
Whoever can see the systems, working with whoever is signing. The common failure is that the person with the authority to sign does not have the visibility to answer, and the person with the visibility is never asked. A question about whether multi-factor authentication covers all remote access is a question about configuration, and the honest source for it is the console rather than memory. Get the answers from the systems, keep a short note of where each one came from, and have the signer review that note rather than the blank form. If an outside IT provider holds the answers, ask them in writing and keep the reply.
The environment changed after we signed. Does the old application still matter?
Yes, in two directions. The application describes the risk as of the day it was submitted, so a change afterward does not retroactively make a wrong answer right. But policies also commonly ask you to maintain the controls you represented, and some contain conditions tied to them, which means drift after binding can matter on its own terms. The practical handling is the same either way. Note what you attested to, review it when the environment changes rather than only at renewal, and tell the broker about a material change when it happens instead of discovering the gap during a claim.