$40M+ in Claims Denied or Disputed
40-44% of all cyber insurance claims were denied in 2024. The leading cause: companies could not prove their security controls were actually in place at the time of breach. No cryptographic proof of MFA means no payout.
Featured Cases
City of Hamilton, Ontario
April 2025
Ransomware attack crippled 80% of Hamilton's network, impacting business licensing, property-tax processing, transit systems. Insurer denied the $18.3M claim — MFA was not fully implemented at time of breach. Taxpayers now on the hook for full $18.3M, of which $14M spent on external response experts.
Source: CBC NewsTravelers v. ICS
July 2022
ICS suffered ransomware attack. During investigation, Travelers discovered ICS stated on insurance application it used MFA for administrative access. In reality, ICS only used MFA for its firewall, not its servers — precisely where the breach originated. Court voided the entire $1M policy.
Source: Insurance JournalColumbia Casualty v. Cottage Health
2015
Over 30,000 patient medical records exposed publicly online. Insurer paid $4.125M settlement then sued to void the policy. Alleged Cottage Health misrepresented that it replaced factory default settings, maintained security patches, and exercised due diligence. Policy contained 'Minimum Required Practices' exclusion.
Source: Inside PrivacyACE v. Congruity / Trustwave
September 2025
Landmark subrogation case. After paying $500K claim, insurer sued the cybersecurity vendors. Cloud provider allegedly failed to implement MFA. Trustwave misclassified a detected security event as 'moderate' instead of critical, delaying response by five days. Attackers encrypted systems before escalation.
Source: Insurance JournalSS&C Technologies v. AIG
2019-2020
Hackers sent spoofed emails impersonating SS&C client, tricking employees into wiring $5.9M. SS&C had failed to follow own internal policy requiring four-person authorization. AIG denied claim. Court ruled against AIG — but only because criminal act exclusion applied to insured's own acts, not third-party hackers.
Source: CyberScoopWhat went wrong in every case
The same proof gap appears across every cyber insurance dispute: companies cannot cryptographically prove their security posture at the time of breach.
- MFA misrepresentation voids policies — not in place where the breach actually happened
- Security attestations on applications are unverifiable — no way to prove controls existed
- Incident timelines disputed — misclassified alerts, delayed response, no tamper-proof timestamps
- Insurers now suing cybersecurity vendors after paying claims
- 40-44% claim denial rate in 2024 — "what was in place at breach time?" is unanswerable
How tamper-proof evidence changes the equation
Cryptographic audit trails make it mathematically impossible to alter or destroy records without detection.
Security Controls Are Cryptographically Attested
MFA status, patch levels, and security configurations get continuous cryptographic receipts. When an insurer asks 'was MFA active at breach time?' — the answer is a mathematical proof, not a checkbox on an application form.
Incident Timelines Are Immutable
Every security event, alert, and response action is timestamped with cryptographic proof. Trustwave's misclassification and Hamilton's delayed disclosure become provable facts, not disputed narratives.
Vendors Can Prove Their Obligations
Cybersecurity vendors facing subrogation lawsuits can demonstrate they fulfilled their contractual obligations with cryptographic evidence — not just logs that could have been altered after the incident.
Ready to make your audit trail tamper-proof?
Create your free account and start protecting your data with cryptographic evidence that can't be altered or destroyed.