Insurers Are Raising the Bar, and Claims Are Getting Harder to Collect
For years, the standard advice around cyber insurance was simple: buy a policy, file a claim if something happens, get paid. That relationship is changing. According to reporting in Infosecurity Magazine’s year-end look at the cyber insurance market, 56% of CISOs said their organization had a cyber insurance payout denied over the past year, a statistic attributed to Marie Wilcox, VP at security vendor Binalyze and a board director at the Chartered Institute of Information Security (CIISec).
The reasons behind those denials are telling. The article reports that rejections increasingly come down to firms lacking “evidence to prove that they had mitigated risks” and being unable to “produce a full timeline of a breach” when a claim is filed. In other words, insurers aren’t just asking whether you had a policy in place. They’re asking whether you can document, after the fact, exactly what your security controls were doing and precisely how the incident unfolded.
Ryan Rubin, EMEA cyber practice lead at risk consultancy Ankura, put the underwriting shift in blunt terms: “Companies will find themselves having to increasingly demonstrate higher levels of cyber controls maturity before being offered insurance.” He also noted that insurers are growing more cautious in general, “given continued large claims relating to ransomware and business interruption costs,” making them “more hesitant to offer wide coverage.” Wilcox added that the outlook for the year ahead “looks far more challenging” for the people responsible for security programs, with underwriting criteria tightening and compliance expectations rising alongside it.
The article also points to the cost of getting this wrong. It cites Jaguar Land Rover’s August 2025 cyberattack, which had no active cyber insurance policy in place at the time and which the piece estimates cost the UK economy roughly £1.9 billion. By contrast, Marks & Spencer’s April 2025 incident was covered, with a claim reported around £100 million. Having a policy and having a policy that actually pays out turned out to be two very different things.
Why This Matters If You’re Not a Big Company
It’s tempting to read this as an enterprise problem — big companies, big claims, big consultants weighing in. But the underlying shift applies with more force, not less, to smaller businesses. Large organizations generally have security teams, incident response retainers, and the internal logging infrastructure to reconstruct a breach timeline on demand. Most small and mid-size businesses don’t have any of that by default, which means exactly the kind of documentation insurers now expect — proof that controls were in place and working, plus a clear record of what happened — is often the first thing missing when a claim gets filed.
The market dynamics work against smaller businesses too. When insurers pull back on “wide coverage” and raise the bar on controls maturity industry-wide, that bar doesn’t get set separately for a 20-person company versus a 2,000-person one. It gets set once, and smaller businesses either meet it with the same rigor or find themselves in the growing group getting a denial, a higher premium, or a non-renewal notice at the worst possible time — right after an incident, when there’s no runway left to fix the gap.
What Businesses Should Do Instead
The practical takeaway isn’t just “have security tools.” It’s “have security tools that produce a record you can hand to an insurer, and know where that record lives before you ever need it.” That means MFA enforced across email, remote access, and admin accounts, not just checked as a box on a renewal questionnaire. It means endpoint detection and response (EDR) that’s actually logging and alerting, not sitting unmonitored. And it means backups that are tested, offline or immutable, and verified to restore, since “we had backups” and “we can prove our backups worked” are very different claims to make to an insurer after the fact.
Just as important: treat your cyber insurance application and renewal process as a real audit, not paperwork. If you can’t currently answer “what does our breach timeline documentation look like” or “can we prove our MFA coverage is complete,” that’s the gap to close before a renewal, not after a claim gets denied.
Security Checklist for Your Business
Enforce MFA everywhere, not selectively. Email, remote access, and admin accounts all need it, and you should be able to prove coverage is complete when asked.
Deploy EDR with active monitoring. A security tool that isn’t generating logs and alerts someone reviews doesn’t help you document an incident later.
Test your backups, not just schedule them. Offline or immutable backups that have been verified to actually restore are what insurers and your own recovery plan both need.
Keep incident documentation insurer-ready. Know in advance how you’d reconstruct a breach timeline, since that evidence gap is a leading reason claims get denied.
Insurers aren’t just asking whether you bought a policy anymore — they’re asking whether you can prove your controls actually work, and that’s a harder bar to clear without help. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: Soft Market, Hard Choices: The State of Cyber Insurance.



