One question decides more cyber claims than most people expect: did the insured actually do what the policy and the application said they did? It is usually asked after the loss, when the evidence is hardest to find.
Conditions and representations
A cyber policy carries two kinds of promise from the insured. Representations made in the application, such as "MFA is enforced on all remote access". And conditions in the policy itself, such as maintaining backups or patching within a stated window.
When a loss happens, the insurer is entitled to test both. If they do not hold, cover can be reduced, disputed or, in serious cases, rescinded.
This is not hypothetical
Two well known US cases show the pattern. In 2022, Travelers sought to rescind a cyber policy issued to International Control Services after a ransomware attack, arguing that MFA had been represented as in place when it was not on all systems. The parties agreed to rescission. Earlier, in Cottage Health v. Columbia Casualty, the insurer challenged a data breach claim by pointing to an exclusion for failure to maintain minimum security practices.
In both, the question was not whether there had been a breach. It was what the insured could prove about their controls beforehand.

Evidence assembled before the loss is worth far more than evidence reconstructed after it.
In plain language
The claim turns on what the insured can prove about their controls on the day of the loss. If that proof is gathered continuously, the conversation at claim time is short.
Know your risk. Prove your controls. Protect your claim.
Step | For the insured | For the insurer |
|---|---|---|
Know your risk | Quantify what could be lost and what the policy actually covers | Underwrite on measured exposure, not only attestation |
Prove your controls | Turn policy conditions into controls that are tested and evidenced | Monitor compliance through the policy term |
Protect your claim | Close gaps before a loss and keep the evidence ready | Verify conditions quickly at renewal and claim |
One evidence layer, two sides
The same evidence serves both parties. Insureds use it to reduce risk and prove insurability. Insurers use it to underwrite, monitor, renew and manage claims. Nobody has to rebuild the picture after the event.
Next step. Twenty minutes is enough to show how the evidence layer works for insureds and insurers. Book 20 minutes →
For any comments or information please reach out to info@astragar.com







