What Happened
In March 2022, International Control Services (ICS), an electronics manufacturer in Decatur, Illinois, applied for cyber insurance through Travelers. The application asked a now-standard question: did the company use multifactor authentication to control access to its systems? ICS’s CEO and its security officer signed off on an application stating that MFA was in place for administrative and remote access across the network. Travelers issued the policy effective April 4, 2022.
Six weeks later, in May 2022, ICS was hit with a ransomware attack. It wasn’t the company’s first: hackers had already gotten in once before, in December 2020, using compromised administrator credentials. ICS had told Travelers its security had improved since then. But when Travelers investigated the new claim, it found that MFA was only enabled on the company’s firewall — not on the remote access, admin accounts, and other systems the application had said it protected.
Travelers didn’t just deny the claim. In July 2022, it filed suit in the U.S. District Court for the Central District of Illinois, seeking to rescind the entire policy on the grounds that ICS had materially misrepresented its security controls when applying for coverage. Travelers argued that accurate answers about MFA would have changed whether it accepted the risk at all, let alone at the terms it offered.
ICS didn’t fight it. On August 26, 2022, both sides filed a joint stipulation asking the court to declare the policy “null and void, from its inception.” The court agreed. That meant not just the ransomware claim, but any claim under that policy, past or future, had no coverage at all. Each side paid its own legal costs, and the case was dismissed with prejudice — a clean, final end to any possibility of coverage.
Why This Matters If You’re Not a Big Company
It’s tempting to read this as a story about a company that lied its way out of coverage. It’s more accurate, and more useful, to read it as a story about how casually MFA gets described on paper versus how it’s actually deployed. A lot of businesses genuinely believe they have MFA “in place” because it’s on for email or for one admin account, without anyone checking whether it covers the systems that actually matter — remote access, domain admin accounts, backups, financial software. That gap between what leadership believes and what’s actually configured is exactly what sank ICS’s coverage, and it’s a gap that exists in plenty of small and mid-size businesses that would never think of themselves as having misrepresented anything.
The other detail worth sitting with is that ICS had already been breached once, in 2020, through weak credential controls, and told its insurer it had fixed the problem. Cyber insurance applications increasingly ask about your controls in detail because insurers have learned that self-reported security posture is often wrong, not necessarily out of dishonesty, but because nobody on the business side actually verified it against what IT deployed. If your business has ever answered a cyber insurance questionnaire from memory rather than from an actual audit of your systems, you’re carrying the same exposure ICS had, regardless of your size.
What Actually Would Have Stopped This
The fix here isn’t complicated, but it does take discipline: before signing any cyber insurance application, have whoever manages your IT — internally or through an MSP — verify every security claim against what’s actually configured, system by system, not just confirm the general idea that “we have MFA.” If the application asks whether MFA protects administrative access, remote access, and email, someone needs to check each of those individually, because a yes to one doesn’t mean yes to all of them.
It’s also worth treating the insurance application itself as a security audit trigger, not just paperwork. ICS’s own history shows the value in this: the December 2020 breach was a clear signal that credential-based access needed stronger protection, and the 2022 application was the moment to actually close that gap rather than describe it as already closed. Any time your business fills out a security questionnaire, whether for insurance, a vendor, or a client, treat a “yes” answer as a commitment to verify, not a formality to get through quickly.
Security Checklist for Your Business
Audit MFA coverage by system, not by feeling. Confirm in writing which specific systems — remote access, admin accounts, email, backups, financial tools — actually require MFA today.
Never answer a security questionnaire from memory. Have your IT provider verify each claim against current configuration before anyone signs an insurance or vendor application.
Treat a past breach as an unclosed gap until proven otherwise. If you’ve had an incident, confirm the specific vulnerability was actually fixed, not just generally addressed.
Re-verify your controls before every renewal. Security postures drift as staff, vendors, and systems change; what was true last year may not be true now.
A denied claim after a ransomware attack is bad. A voided policy that erases coverage retroactively, for every claim, is worse — and it happened here because of gaps between what was claimed and what was configured, not because of anything exotic. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: Insurance Journal, “Travelers, Policyholder Agree to Void Current Cyber Policy”.



