Cyber Insurance Exclusions That Decide Claims
Coalition put average global cyber claim severity at $116,000 for 2025, well under most policy limits. That means cyber insurance exclusions and sublimits, not the limit, decide what you collect.

Coalition found 64% of closed cyber claims in 2025 resolved with no out-of-pocket cost. Most claims pay. Here is what separates the ones that do not, and the five habits that close the gap.
Cyber insurance claims get denied for reasons that are usually decided long before the incident. The common ones are a mismatch between the application and the environment, a loss type that falls outside the coverage bought, a late notice, and a condition in the policy that was never operationalized. All four are addressable in advance.
I am Amelia S. Gagne, CEO of Kief Studio. This page is about the failure modes and what closes them. Its companions are what a cyber insurance renewal application asks now and cyber insurance exclusions that decide claims.
Worth stating the base rate first, because the topic attracts alarming numbers of uncertain origin. Coalition's 2026 Cyber Claims Report, covering more than 100,000 policyholders, found 64% of closed claims in 2025 resolved with no out-of-pocket cost to the policyholder. Most claims pay. The interesting question is what distinguishes the ones that do not.
This distinction is the most useful thing to understand, and it is rarely explained to buyers.
A denial says this loss is not covered under the policy. The policy still exists, other losses may still be covered, and the argument is about scope.
A rescission says the policy should never have been issued, because the application contained a material misrepresentation. A rescinded policy is treated as void from inception. There is no coverage for anything, and the premium comes back.
The second outcome is the one worth designing against, because it removes the whole program rather than one claim.
Less than it is often credited with, and it is still the clearest illustration available.
In July 2022, Travelers filed suit in the Central District of Illinois seeking rescission of a $1 million cyber policy issued to International Control Services, an Illinois electronics manufacturer that had suffered a ransomware attack. Travelers alleged the company had represented that multi-factor authentication was in use, and that its investigation found MFA protecting only the firewall rather than the server that was attacked.
The case never reached a ruling on the merits. The parties jointly stipulated to rescission, and on August 30, 2022 the court entered an order declaring the policy void from inception, with the matter dismissed with prejudice.
Because it resolved by stipulation, it carries no precedential weight. It is cautionary rather than binding. What makes it instructive is the fact pattern: the gap was not the absence of a control but the scope of one. MFA existed. It did not cover the path that was used.
The application had also been signed by both the CEO and the employee responsible for network security, which is a reminder that review by more senior people is not the same as review against evidence.
Because controls are described in binary language and deployed in partial states.
An honest person asked "do you use MFA" who has rolled it out to staff email will answer yes. The answer is true about the organization and incomplete about the attack surface. Remote access, administrative consoles, service accounts, and legacy systems each get adopted on their own schedule, and the leftover is rarely inventoried.
The fix is unglamorous: answer the question at the level of the asset rather than the organization, and keep the exclusions list from your own identity policy where you can find it. That list is the honest answer.
It is also the list that matters operationally, not just contractually. Machine and service identities are the usual survivors of an MFA rollout, which is why non-human identity is worth treating as its own category.
These are the procedural conditions, and they cause avoidable problems in the first forty-eight hours of an incident, which is exactly when nobody is reading the policy.
Most cyber policies require prompt notice and give the insurer a say in which forensics firm, breach counsel, and negotiator are engaged. Retaining your own vendors first, before notifying, can put those costs outside coverage even when the underlying loss is covered.
The practical control is a single page in your incident plan listing the carrier's notification number, the policy number, the panel vendor list, and the name of the person authorized to make the call. Coalition's data shows funds transfer fraud recoveries averaging $202,000 per incident, with $21.8 million clawed back in 2025, and recovery in those cases is strongly time-dependent. Speed on notification is not paperwork discipline, it is money.
That page belongs in the same plan described in what happens when you get hacked and business continuity is architecture.
This is the most common ordinary outcome, and it is not really a denial in the adversarial sense. The policy paid what it was written to pay.
Funds transfer fraud against a social engineering sublimit is the standard example. The claim is covered and the recovery is capped, which surprises people who read the policy limit and stopped there. The remedy is the scenario exercise in the exclusions piece, run before binding.
Five things, in rough order of effort to value.
None of this requires a security team. It requires a file and a calendar, which is the same argument as writing a cybersecurity policy without a security team.
Underwriting has moved toward verifying what buyers claim, which sounds like an added burden and mostly is not. The artifacts an insurer wants are the artifacts an operator should already have: a current asset inventory, a tested restore, a known privileged account list, and a vendor register.
Building those because a form asks is a slightly undignified reason to build them. They pay for themselves regardless, which is the argument in security architecture first.
Brian Gagne handles security architecture at Kief Studio and has for the fourteen years we have worked together. For control design, briansgagne.com is the deeper read, and JDR Security Solutions covers cloud health checks and IAM audits. How we run managed operations is at ltfi.ai.
The recurring causes are a mismatch between application answers and the deployed environment, a loss type that falls under a sublimit or exclusion rather than the full limit, late notice or use of non-panel vendors, and failure to maintain a control the policy conditioned coverage on. Most claims still pay: Coalition found 64% of 2025 closed claims resolved with no out-of-pocket cost to the policyholder.
Rescission voids the policy from inception on the basis of a material misrepresentation in the application, rather than declining a single claim. It is a broader outcome than a denial because no coverage remains for anything under that policy.
Travelers sued in 2022 seeking rescission of a $1 million cyber policy, alleging the insured represented it used multi-factor authentication when MFA protected only its firewall. The parties stipulated to rescission and the court entered judgment voiding the policy on August 30, 2022. There was no merits ruling, so the case is cautionary rather than binding precedent.
Check the policy first. Many cyber policies require the insurer's consent and specify panel vendors for forensics, breach counsel, and negotiation. Engaging your own firm before notifying the carrier can put those costs outside coverage.
Store the answers alongside the evidence supporting each one and review them quarterly, plus after any migration or major change. Controls disabled temporarily and never re-enabled are the most common source of drift between what was represented and what is running.
Coalition put average global cyber claim severity at $116,000 for 2025, well under most policy limits. That means cyber insurance exclusions and sublimits, not the limit, decide what you collect.
Marsh recorded cyber rates down 4% globally in Q2 2026, the twelfth straight quarterly decline, while underwriting evidence standards tightened. What a cyber insurance renewal application asks now, and the folder to have ready.
Cyber resilience tools cost versus breach recovery and fines is a recurring number you choose against a one-time number you do not. IBM's 2026 average breach is $4.99 million globally and $11.5 million in the US. The fine is rarely the largest line.
Work With Us
Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.
Newsletter
Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.
Subscribe