Most security spending at funded companies does not start with fear. It starts with a gate. An outside party blocks money until you prove a control exists. The customer blocks the deal until you show a SOC 2 report. The acquirer blocks the valuation until diligence clears. The insurer blocks the policy until you attest to your controls.
Of those three gates, the insurer has become the strictest and the most expensive to fail.
Cyber insurance stopped being a checkbox. Carriers now underwrite like auditors. They ask yes-or-no questions, demand proof, and rescind coverage when the proof does not hold.
The Gate Moved From Price to Proof
For years, buyers shopped cyber insurance on price. That window closed. After heavy ransomware losses, carriers rebuilt their questionnaires around a small set of controls and started enforcing them at the claim stage.
Of cyber insurance applications get denied on first submission, according to Marsh McLennan, with missing MFA and inadequate endpoint protection the top two reasons.
The single most cited gap is multi-factor authentication. Coalition's claims data found that 82% of denied claims involved organizations without MFA fully implemented. Endpoint detection and response, immutable backups, and a tested incident response plan round out the list of controls that carriers name directly as refusal criteria.
The questionnaire does not ask whether you have a control. It asks whether you can prove it. The gap between those two questions is where coverage dies.
The Premium Math Is Real Money
Insurability is not binary. The same control evidence that clears the gate also moves the premium, and the swing is large enough to show up on a P&L and in a board deck.
S&P Global Ratings forecast a 15 to 20% cyber premium increase for 2026 after two years of falling rates, driven by rising claim severity and a sharp jump in ransomware and credential theft. Against that rising baseline, documented controls cut the other way.
Lower or stabilized premiums for organizations with fully documented MFA, EDR on all endpoints, a tested incident response plan, immutable backups with restore testing, and a documented patch program, compared to peers without those controls.
The market is pushing premiums up 15 to 20% while well-controlled buyers hold flat or pay materially less. That spread is not a rounding error. It is a recurring annual cost that compounds across the hold period.
The Financial Levers, Ranked by Underwriting Impact
| Control | Why It Matters |
|---|---|
| MFA, fully documented | Top denial driver. Must be enforced everywhere it is claimed, including remote access, email, and admin paths. |
| EDR or MDR on all endpoints | Second most common refusal reason. Detection coverage gaps read as uninsurable exposure. |
| Tested incident response plan | Evidence of testing, not just a document. Reduces claim severity, which carriers price in. |
| Immutable, isolated backups | With documented restore testing. Determines whether a ransomware loss is recoverable or total. |
| Documented patch program | Closes the open-entry-point exposure underwriters scan for externally. |
The Lapse That Voids the Claim
Passing the gate is not the finish line. The expensive failure is the control that gets checked on the application and then lapses, because the bill comes due after the breach, when the loss is already on the books.
In Travelers v. International Control Services, Travelers issued a one-million-dollar cyber policy to an Illinois electronics manufacturer after the company attested that it required MFA for administrative and privileged access. Ransomware attackers reached a server that did not have MFA. Travelers sued to rescind the policy, and in August 2022 the parties stipulated to rescission. No coverage for the loss, no duty to defend.
The legal standard makes this worse than it looks. Under the majority rule in U.S. courts, an insurer can rescind a policy for a material misrepresentation in the application whether the misstatement was intentional, negligent, or an honest mistake. Intent is not required. The Ninth Circuit reaffirmed that principle in Hughes v. First National Insurance in 2024.
Insurance transfers the cost of a breach. It does not prevent one. A control checked on the form and left to lapse converts paper compliance into false comfort, and a seven-figure uninsured loss.
What This Means for Leadership and Investors
For an operating leader, the insurability gate sets a clear priority order. The cheapest dollars saved are on premium, through documented controls. The most expensive dollars lost are on a rescinded claim, through an undocumented lapse.
For an investor, insurability is a diligence signal that cuts straight to enterprise value. A portfolio company with a real, evidenced control program is cheaper to insure, faster to clear at exit, and far less likely to absorb an uninsured loss during the hold. The right diligence question is not whether the portfolio company holds a policy. It is whether that policy would actually pay. The same evidenced controls also clear the SOC 2 gate that blocks enterprise deals.
Where the spend should land, in order of financial impact
Close and document MFA Everywhere it is claimed. The top denial driver and the lowest-cost control to fix.
Put EDR or MDR on every endpoint With reporting you can export. The second most common refusal reason.
Test the incident response plan And keep the proof. A document is not evidence.
Make backups immutable And prove you can restore them.
Treat the attestation as a living control Re-verify before every renewal and after every infrastructure change.
One Provider. Named Accountability at Every Level.
Mid-market organizations face the same board scrutiny as enterprises. They face it with smaller teams, tighter budgets, and without the luxury of a full-time CISO.
Aetos One was built for that reality. Our Bastion module keeps MFA, EDR, and backup controls live and evidenced between renewals. Our Guardian module assigns a named fractional CISO who owns the attestation as a continuous obligation, not an annual form.
Named fractional CISO. Owns the attestation as a living control, not a once-a-year signature.
AI-driven security operations. MFA enforcement, EDR coverage, and exportable evidence underwriters ask for.
Continuous compliance automation, with documentation ready before every renewal.
If your board is asking whether your policy would actually pay, schedule a 30-minute conversation.