Cyber insurance claims are denied when there’s a gap between what your insurance application states and what security controls are actually implemented in your environment, regardless of intent. This gap creates a material misrepresentation that gives insurers grounds to rescind coverage, and recovery costs entirely out of pocket. The Hamilton, Ontario case demonstrates how even partial implementation of required controls like multi-factor authentication can void coverage despite honest efforts.
In Hamilton, Ontario, a city of about 570,000 people, a 2024 ransomware attack took down roughly 80 percent of the municipal network, and the recovery ultimately cost the city about CAD $18.3 million out of its own operating budget, more than the attackers had originally demanded. As Global News reported, the claim was complicated by the fact that multi-factor authentication had not been fully deployed across every department despite being a known policy requirement since 2022. That is the cyber insurance denial business owners are learning about too late.
That was Hamilton, Ontario. February 2024. And it is not a one-off.
Cyber insurance used to sell to business owners as a safety net. In 2026, cyber insurance denial has become the more relevant conversation, because the policy is now a conditional promise that lives or dies on what you can prove. Fitch Ratings reports that cyber insurance claim volumes surged nearly 60 percent in 2024, and carriers responded by tightening exactly what they will pay for and what they require you to have in place.2 Coalition, one of the largest cyber underwriters in the market, found that 82 percent of denied claims in its 2024 book involved organizations without properly implemented MFA across their environment.3
The application form is now the security audit. And the payout, if a claim ever gets filed, is entirely contingent on whether the answers you gave match what the forensic team finds after the attack.
The Denial That Cost Hamilton $18.3 Million
Hamilton’s story is worth understanding in detail, because it is a preview of what many businesses are about to learn the hard way.
In February 2024, ransomware attackers disabled roughly 80 percent of Hamilton’s network. Business licensing, property tax, transit planning, finance, and procurement systems went dark for weeks. The attackers demanded a ransom of roughly $18.5 million in exchange for a decryption tool. The city did not pay. Hamilton contained the incident within two days and kept critical services running throughout.
Recovery cost real money. External experts alone consumed more than $14 million of the total $18.3 million recovery bill. The city carried cyber insurance and expected the policy to bear the cost. When the forensic review completed, the insurer denied the claim.1 The reason was not that Hamilton had never deployed MFA. It was that MFA had not been rolled out across every department. Staff had known about the policy requirement since 2022. The rollout had reached only a few departments. That gap voided coverage.
Notice what happened here. Hamilton did not lie on the application. Hamilton had a plan and a timeline and was working the plan. The insurer did not care about the timeline. The policy language was specific. The controls were required in full. Anything less was outside coverage.
The Case That Changed the Rules
The legal precedent that gave insurers this leverage was set in 2022, in a case called Travelers v. International Control Services.
International Control Services, an electronics manufacturing company in Decatur, Illinois, applied for a cyber policy in April 2022. The application, signed by the CEO and a person responsible for the company’s network and information security, stated that ICS used MFA to protect administrative and privileged access. Travelers underwrote and issued the policy on that basis.4
A month later, ICS was hit with ransomware. When Travelers investigated, the forensic team found that MFA was in use on the firewall, and nowhere else. It was not protecting the server that got hit. It was not protecting the accounts the attackers used. The application said one thing. The environment showed another.
Travelers went to federal court and asked to have the policy declared null and void. In August 2022, the case was dismissed with judgment entered in favor of Travelers, and ICS agreed to allow the court to rescind the policy.
That ruling matters far beyond one Illinois manufacturer. Under the majority rule across U.S. jurisdictions, an insurer can rescind a policy based on a material misrepresentation regardless of whether the false statement was intentional, negligent, or an honest mistake. Intent is not part of the test. What matters is whether the statement was false and whether it was material to the decision to insure.5 Every cyber insurance application question the business owner signs is now, functionally, a legal representation.
What Your Application Actually Asks Now
Cyber policy applications in 2026 look nothing like they did five years ago. Insurers now demand attestation across a specific set of controls, and they demand evidence of deployment. Not a checkbox on the form. Evidence.
The controls that show up on most major carrier questionnaires now include the following:
- Phishing-resistant multi-factor authentication on every account with access to email, VPN, remote desktop, cloud admin, banking, and business applications. Authenticator apps, FIDO2 hardware keys like YubiKey or Feitian, or passkeys. Not SMS. Not one-time codes that can be relayed through an attacker’s proxy.
- Endpoint Detection and Response on every endpoint and every server, monitored 24/7 by an internal SOC or a Managed Detection and Response provider. CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, or equivalent. Having EDR installed is no longer sufficient. Carriers want to see that alerts are being acted on around the clock, which is what MDR services from providers like Huntress, Blackpoint, or Arctic Wolf actually deliver.
- Immutable, isolated, restore-tested backups. Ransomware crews now hunt down and delete backups before encrypting production data. Insurers want backups the attacker cannot alter, Veeam Hardened Repository, Wasabi Object Lock, Datto immutable snapshots, and they want a test date documented. Having backups is not enough. You have to be able to attest that they are isolated from production and that you have verified you can recover from them.
- Email authentication at enforcement. SPF, DKIM, and DMARC configured across every legitimate sending source, with the DMARC policy set to reject impersonation rather than monitor it.
- Documented security awareness training. Not a one-time video. A program with tracked completion and phishing simulation results the business owner can produce on request.
- Patch management with a service-level agreement covering critical vulnerabilities and end-of-life systems.
- An incident response plan on file, tested at least annually, with contact information for the insurer, breach counsel, and forensic vendors already recorded.
None of these are theoretical. Underwriters run technical audits before renewal. Businesses that fail those audits face premium increases, coverage exclusions carved into the policy, or outright non-renewal.
Where Cyber Insurance Denial Actually Starts
The dangerous space in cyber insurance is not between a business with controls and a business without them. Every cyber insurance denial documented in the last three years lives in a smaller space than that. It lives in the gap between what the application says is deployed and what is actually running in production when the incident happens.
An MSP that lists MFA on the client’s application and has enabled it on 80 percent of accounts is not protecting that client. The 20 percent is where the attacker gets in, and the 20 percent is where the claim gets denied. An EDR license that was purchased but never rolled out to every server is not protecting the client. An immutable backup solution that has never been tested is not a backup at all. It is a hope with a subscription fee.
Every application question is now, in effect, a sworn statement. Every gap between the answer and the reality is a rescission risk. This is the space where MSPs quietly fail their clients, not by giving them nothing, but by giving them 80 percent and letting them sign a form that claims 100 percent.
What Your MSP Should Be Handing You Right Now
If your MSP is doing this right, you should be able to walk into a policy renewal conversation with a specific set of documents in hand. Not a promise. Documents.
A control matrix that maps every policy application question to what is deployed in your environment, when it was verified, and where the evidence lives. Your underwriter is going to ask. Your forensic firm is going to ask. Having it ready before either one shows up changes the conversation.
A documented restore test with a date, a scope, and a result. Not “backups completed successfully.” A restore. To a real environment. With a note that says what was restored, how long it took, and who watched it happen.
An MFA coverage report, exported from your identity platform, showing which accounts have phishing-resistant MFA enforced and which do not. If any account is on the list without coverage, your MSP should tell you why before you attest that MFA is universal.
An attestation letter your MSP is willing to sign alongside your policy application. If the answer to the question is yes, your MSP should be willing to co-sign that yes. If they will not co-sign, that is information you needed before you signed the application yourself.
A cyber policy pre-review at every renewal. Your MSP should be reading the application before you fill it out. The controls the carrier is now asking about are technical questions. The person best positioned to answer them accurately is the person who deployed them.
Where This Leaves You
Cyber insurance is not going away. It is becoming a market that only pays out for businesses that can prove what they said was true. That is a different product than the one many business owners think they bought.
The businesses that get paid when a claim gets filed will be the ones whose MSPs treated every application question as a legal representation and made sure the environment matched. The businesses that get denied will be the ones who thought “we have MFA” was a full answer, and whose MSPs let them sign the form without asking the next question.
Do not wait for a cyber insurance denial letter to find out which one you are. Ask your MSP for the five documents above this week. If any of them cannot be produced, that is your open item to fix before the next renewal, not after the next attack.
Sources
1 Global News, “Ontario city facing full $18.3M cyberattack bill after insurer denies claim,” globalnews.ca, July 31, 2025.
2 Reinsurance News, “US cyber insurance market remains profitable amid slower growth in 2024: Fitch,” reinsurancene.ws, 2025.
3 Coalition, “The State of Active Insurance: 2024 Cyber Claims Report,” coalitioninc.com.
4 Insurance Journal, “Travelers Wants Out of Contract With Insured That Allegedly Misrepresented MFA Use,” insurancejournal.com, July 12, 2022.
5 Lockton, “Travelers v. ICS underscores need to respond carefully to cyber insurance application questions,” lockton.com.
About Brent Lacy: Brent Lacy has been in the IT industry since 1997. He moved into the managed services world around 2015 and was doing vCIO work before the title even existed. He writes about the operational discipline, trust-based relationships, and strategic thinking that separate MSPs built to last from those built to bill. He is the author of Rewired MSP: Mastery, Scalability and Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.