The Alarm Was On. The Claim Still Failed
Picture a house with a proper alarm system: beams in every passage, a paid-up policy in a drawer. Everything says this is covered. Then someone gets in anyway, and the claim comes back declined, not because the alarm failed, but because an armed-response add-on had quietly lapsed eight months earlier. The alarm worked. The insurance didn’t. Nobody lied. The cover had simply stopped matching the house.
That’s the exact shape of what’s happening to cyber insurance right now, and most businesses haven’t clocked it.
The policy isn’t the policy you think you have
A cyber insurance application used to be a form: tick-boxes, a signature, a premium. Not anymore. It’s now a technical audit, run once at application and again, in far more detail, the moment you claim.
The case that put the industry on notice: Travelers Property Casualty Co. of America v. International Control Services (2022). ICS told Travelers it ran MFA across its systems; in reality, only the firewall was covered. A ransomware attack came in through the unprotected gap the application said didn’t exist. Travelers asked the court to rescind the policy entirely, and won, not because the attack was unusual, but because a form filled in months earlier no longer matched the network.

Nothing here needs a villian
It only needs time. MFA gets configured properly at onboarding; a new server goes live 18 months later and nobody enforces the same policy on it. The renewal gets rubber-stamped. The certificate stays on the wall while the real network quietly drifts away from the one the policy describes.
The South African layer
Under POPIA Section 22, you must notify the Information Regulator and affected individuals as soon as reasonably possible after a compromise, regardless of what your insurer decides. Local insurers are now asking for the same evidence of cyber hygiene as international carriers, and the market is starting to split: real controls get you priced cover; everything else is a premium paid for protection that may not be there.
To be fair to the insurers
Not every denial is bad faith. A policy that pays out regardless of basic hygiene subsidises poor security for everyone else, and most claims still get paid. Cyber cover remains genuinely useful for legal costs, forensics and business interruption. The fix isn’t distrusting insurance. It’s treating the renewal questionnaire as more than paperwork.
What to do about it
Pull your policy wording now, not at renewal. Check it against what’s actually running today, and treat MFA as all-or-nothing, including the systems it’s easy to forget: the back-office file server, the old VPN box, the service account nobody remembers creating. Keep the evidence as you go, because the businesses that get paid are the ones who can prove the state of their environment on the day it mattered, not just describe it.
The house in that story didn’t lie to its insurer. The alarm genuinely worked. What it didn’t have, eight months on, was a policy that still matched the house. Close that gap before you need the payout, not after.
Candice Landsberg
First Technology Western Cape