top of page
Search

Is Your Written Information Security Plan Enough? How Your Cybersecurity Insurance Company Is Deceiving You For Profit.

  • Writer: Robert Marshall
    Robert Marshall
  • Nov 23, 2025
  • 5 min read

By Robert Marshall

Most business owners believe cyber insurance works like auto or health insurance: pay your premium, experience a loss, file a claim, and receive support.

Cyber insurance does not work that way.

Cyber insurance companies often approve policies even when businesses are not meeting industry cybersecurity standards. Later, when a breach occurs, they conduct a forensic investigation, identify gaps, and deny the claim—while keeping every premium paid.

This is not speculative. It is reflected in real legal cases.



Real Small Business Case: Travelers vs. International Control Services (ICS)

In 2021, International Control Services, Inc. (ICS)—a electronics manufacturer in Decatur, Illinois—was hit by a ransomware attack. ICS held a cyber liability policy with Travelers Property Casualty and asserted during underwriting that:

  • Multi-Factor Authentication (MFA) was enforced

  • Security systems were actively monitored

  • Required preventative controls were maintained

Following the incident, Travelers initiated a forensic audit and determined that:

  • MFA was only active on the firewall, not on servers or internal user accounts

  • Backups existed, but no successful restore testing had been documented

  • Data encryption had been declared, but was not technically enforced

Travelers denied the claim and moved to fully rescind the policy, despite ICS having paid approximately $27,000 in premiums over three years. The policy carried a $1 million coverage limit, which ICS would have sought to access.

Because ICS had attested to cybersecurity safeguards that were not fully implemented, the insurer alleged misrepresentation and avoided coverage. The exact financial damage was not disclosed in court records, but industry commentary and case analysis indicate that recovery costs likely fell into the high six-figure range.

This was not a large enterprise. It was a 25-person manufacturing company. Following the incident and insurance denial, six positions were eliminated as part of post-incident restructuring. Had ICS not been acquired shortly afterward, the business would likely have been forced to close.



The Problem: False Confidence in Underwriting Approval

Many organizations believe that once their policy is underwritten and their Written Information Security Plan (WISP) is submitted, they are covered.

This is incorrect.

During underwriting, insurance companies frequently rely on self-attested information. They typically do not perform in-depth technical verification. The result is that a policy will be approved based on stated, not proven, security controls.

The approval activates billing—not protection. Actual protection is only evaluated after a breach.



What Happens When You File a Claim

Following a cyber incident, the insurer initiates a post-incident audit. Their objective is to determine whether your organization truly upheld the standards you declared during underwriting.

If your cybersecurity posture does not match your documented policies or application responses, the insurer has grounds to deny the claim.

They do not need to prove that your organization lacked all controls—they only need to prove that your controls fell short of the standard you declared and that is expected for “best effort” compliance.



Additional Case Example: Cottage Health System

In 2013, Cottage Health System suffered a breach exposing 32,500 patient records due to data being stored on an unencrypted publicly accessible system. Columbia Casualty Company (CNA), their insurer, argued that Cottage Health had failed to maintain minimum required security practices as stated in their WISP and application.

In total, Cottage Health faced more than $6 million in direct penalties and settlement exposure, including:

  • $4.1 million class-action settlement

  • $2 million fine from the California Attorney General’s Office for failure to secure patient data

Their insurer (Columbia Casualty/CNA) argued that Cottage failed to maintain the security controls described in their WISP and moved to deny coverage entirely based on that failure.

Had Cottage Health not had independent reserves and regulatory relationships, the organization would likely have faced operational shutdown or forced merger.



What “Best Effort” Means

In cyber insurance terms, “best effort” does not refer to general intent. It means that the organization maintains and can produce evidence of adherence to recognized cybersecurity standards.

For coverage to be defensible, organizations must enforce and document the following:

  • Multi-Factor Authentication (MFA) across all accounts, servers, and remote access points.

  • Data encryption in transit and at rest, including for servers, backups, and cloud services.

  • Ongoing patch management and vulnerability remediation.

  • Active Endpoint Detection and Response (EDR/XDR) monitoring.

  • Regularly documented backup restoration testing.

  • Zero Trust or properly segmented network design and access control systems.

  • Audit logs retained and reviewable.

  • Routine WISP reviews aligned with changes in the environment and technology.

If an organization documents controls in a WISP or application that are not fully implemented and verifiable, those records become evidence against them during a claim review.



The Difference When Practice Matches Policy

For comparison, in National Ink & Stitch, LLC v. State Auto Property & Casualty Insurance Co., a Maryland-based embroidery and apparel business suffered ransomware damage and sought $310,000 in recovery costs. The insurer initially rejected coverage under a “property damage” technicality, but the U.S. District Court ultimately ruled the insurer was responsible for paying the full rebuild cost of the company's damaged IT systems.

The key difference? The company’s environment and declared security posture matched closely enough for the court to accept coverage. This demonstrates that cyber liability insurance can pay — but only when systems and documentation are in alignment.



How Accurate Tech Service Addresses This Risk

At Accurate Tech Service, we go beyond helping businesses complete insurance documentation. Our approach ensures that clients are not only insured—but also insurable.

Our process includes:

  1. Reviewing your current WISP and insurance declarations.

  2. Performing a cybersecurity audit aligned with how insurers conduct post-breach investigations.

  3. Identifying gaps between declared policies and actual system configurations.

  4. Implementing the required cybersecurity controls.

  5. Providing documentation and evidence to support claim compliance.

  6. Establishing ongoing validation procedures.

The goal is to build an IT environment that can withstand not only cyber threats but also claims audits. This ensures that if a breach occurs, you are not attempting to justify compliance—you are able to prove it.



A written security plan is not sufficient if it does not reflect your actual cybersecurity posture.

Your policy approval does not guarantee coverage.

If your systems do not meet the standards your policy assumes, you are not protected—you are only paying for the appearance of protection.We've now seen SMBs lose:

  • $250k–$1M+ in unrecoverable costs (ICS, Illinois)

  • $6M+ in civil and regulatory liability (Cottage Health, California)

  • $310k in system rebuild expenses (National Ink & Stitch, Maryland — paid only because controls aligned)

These were not Fortune 500 failures. All three companies operate with fewer than 50 internal technical staff and would be considered "medium risk" under standard insurance profiling.

If this happened to them, it can happen to you.

Schedule a cybersecurity and insurance alignment assessment with Accurate Tech Service. We will evaluate your WISP against your current infrastructure and help build an evidence-backed cybersecurity posture that supports your insurance claim—not undermines it.



Sources & Case References

  1. Travelers Property Casualty Co. of America v. International Control Services, Inc. U.S. District Court, Central District of Illinois, Case 2:21-cv-02130. https://www.insurancejournal.com/news/national/2022/07/12/675516.htm https://www.reedsmith.com/en/perspectives/2022/07/insurance-applications-under-scrutiny-lessons-from-travelers-v-ics

  2. Columbia Casualty Company v. Cottage Health System U.S. District Court, Central District of California, Case 2:15-cv-03432. https://www.hipaajournal.com/no-insurance-cover-for-cottage-health-hipaa-breach-6778/ https://www.ciab.com/resources/columbia-casualty-v-cottage-health-system-shows-importance-of-reading-your-cyber-policy/

  3. National Ink & Stitch, LLC v. State Auto Property & Casualty Insurance Co. U.S. District Court, District of Maryland, Case 1:18-cv-00214. https://www.cyberscoop.com/cyber-insurance-court-st

  4. ate-auto/ https://cyethack.com/cyber-insurance-ransomware-settlement-supported/

  5. “Cyber Insurers Clamp Down on Self-Attested Controls” DarkReading, September 2022. https://www.darkreading.com/cyber-risk/cyber-insurers-clamp-down-on-clients-self-attestation-of-security-controls


Comments


bottom of page