By Nate Olson, Fractional CIO & IT Director | N.O. IT Strategy LLC
The Distance Between "Yes" and "Provable"
Your cyber liability insurance renewal is coming up. You know the drill, do you have MFA, do you have EDR, do you have backups. Check, check, check, sign here, right?
Nope, that’s changing.
Cyber liability carriers are starting to ask more, not just if you have MFA, but where? You have backups, but where is the immutable copy stored and when was the last time someone tested a restore?
These harder questions are starting to pop-up because the industry is learning to be more careful.
The FBI’s Internet Crime Complaint Center reported $20.877 billion in losses from cyber-enabled crime in 2025, a 26% increase over the prior year. Business email compromise alone accounted for $3.0 billion. Ransomware reporting climbed for the third straight year, from 2,825 complaints in 2023 to 3,156 in 2024 to 3,611 in 2025, with 63 new variants identified in 2025, roughly five per month. Those ransomware loss figures are understood to run low, because plenty of victims never report the payment.
Small and mid-sized organizations are right in the crosshairs. They hold enough money to be worth taking and rarely have the staff to watch for it.
This tracks with what I’m hearing from people who work these cases. In a recent conversation I had with a PNW cybersecurity vendor who sees this daily, he described a sharp rise in organized criminal groups moving into cybercrime, and not the headline-grabbing kind. They’re taking a few hundred dollars here, a few thousand there, whatever they can reach. The amounts stay small enough that law enforcement is unlikely to pursue them individually, and the volume is where the money is.
Carriers see this from the other side. They write the check; they don’t want to be left holding the bag for a company that answered yes on paper and had gaps in practice. They’ve started asking questions specific enough to expose the difference.
Three examples, straight from the carriers applications.
The Hartford’s CyberChoice application asks whether MFA is required for all remote access, and it names cloud-hosted, on-premises, and VPN so you can’t answer for one and mean the others. Coalition doesn’t ask yes or no. It asks which services you enforce MFA on, separating remote access paths from privileged and administrative accounts. One of the available answers means partial coverage. A carrier wrote that option because partial is what they keep finding. Chubb’s Cyber ERM proposal form asks whether privileged access requires separate MFA, whether administrators hold separate standard and privileged accounts, and then asks you to detail your exceptions in writing.
The Hartford’s application requires a senior officer to sign as the company’s authorized representative, declaring the statements true and complete, and the application becomes the basis of the contract if a policy is issued. That officer most likely didn’t gather the answers themselves. They either came from IT, their MSP, another vendor, and they usually describe what was purchased or configured at some point rather than what’s running this morning.
Your books are kept by one party, audited by another and nobody finds that insulting. It’s just how you get reliable numbers when it counts. IT rarely works that way. The vendor who built the environment or manages it, is usually the same one confirming they have it configured correctly, and that confirmation is what ends up on the application a senior officer signs. An independent assessment lands one of two ways. Either it confirms your MSP has you where you need to be, or it surfaces gaps, and we work with your MSP to close them. Either of which is worth knowing before you sign an attestation.
Travelers sued International Control Services after a ransomware incident, alleging the company represented that it used MFA for privileged access when MFA in fact protected only the firewall. The parties agreed to rescind the policy and void it from inception. No coverage, past or future.
Nobody in that story had to lie. Somebody answered a scoped question as though it were a simple one.
I work for the business, not the carrier. But when the answers on that application are accurate, both sides come out ahead. The carrier prices the risk it’s actually taking. The business gets coverage that holds up, and independent documentation of where its security posture actually stands.
A cyber insurance readiness review produces a documented current state, the evidence behind each answer, the exceptions written down instead of glossed over, and a prioritized plan to close them. Leadership walks into the renewal with a defensible position and a roadmap.
One boundary worth stating. I don’t interpret coverage, negotiate with underwriters, or predict whether a claim gets paid. That’s the broker’s work and the carrier’s decision. I establish whether the technical answers your leadership team is being handed can actually be supported.
The goal isn’t turning every answer into a yes. It’s making sure leadership knows which answers are yes, which are partial, which are planned, and what evidence stands behind each one.
If you want to know if your cyber security posture answers would survive, reach out.
Sources
FBI Internet Crime Complaint Center, 2025 Internet Crime Report
https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
Total reported losses, BEC losses, ransomware complaint counts, new variant count.
FBI Internet Crime Complaint Center, 2024 Internet Crime Report
https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
Prior-year ransomware complaint figures.
The Hartford, CyberChoice Underwriting Application, Form CB 00 H027 03 0824
MFA scoping language, senior officer signature and declaration.
Coalition, Cyber Insurance Application
https://help.coalitioninc.com/hc/en-us/articles/24799477261851-Cyber-Insurance-Application
Per-service MFA enforcement questions.
Chubb, Cyber Enterprise Risk Management Standard Proposal Form
Privileged access MFA, separate administrator accounts, written exceptions.
Travelers Property Casualty Company of America v. International Control Services, Inc., U.S. District Court for the Central District of Illinois, No. 1:22-cv-01145
