Back to Enforcement
Cyber Insurance · 8 cases · 2015–2025

$40M+ in Claims Denied or Disputed

40-44% of all cyber insurance claims were denied in 2024. The leading cause: companies could not prove their security controls were actually in place at the time of breach. No cryptographic proof of MFA means no payout.

Featured Cases

City of Hamilton, Ontario

April 2025

$18.3M

Ransomware attack crippled 80% of Hamilton's network, impacting business licensing, property-tax processing, transit systems. Insurer denied the $18.3M claim — MFA was not fully implemented at time of breach. Taxpayers now on the hook for full $18.3M, of which $14M spent on external response experts.

Source: CBC News

Travelers v. ICS

July 2022

$1M

ICS suffered ransomware attack. During investigation, Travelers discovered ICS stated on insurance application it used MFA for administrative access. In reality, ICS only used MFA for its firewall, not its servers — precisely where the breach originated. Court voided the entire $1M policy.

Source: Insurance Journal

Columbia Casualty v. Cottage Health

2015

$4.125M

Over 30,000 patient medical records exposed publicly online. Insurer paid $4.125M settlement then sued to void the policy. Alleged Cottage Health misrepresented that it replaced factory default settings, maintained security patches, and exercised due diligence. Policy contained 'Minimum Required Practices' exclusion.

Source: Inside Privacy

ACE v. Congruity / Trustwave

September 2025

$500K

Landmark subrogation case. After paying $500K claim, insurer sued the cybersecurity vendors. Cloud provider allegedly failed to implement MFA. Trustwave misclassified a detected security event as 'moderate' instead of critical, delaying response by five days. Attackers encrypted systems before escalation.

Source: Insurance Journal

SS&C Technologies v. AIG

2019-2020

$5.9M

Hackers sent spoofed emails impersonating SS&C client, tricking employees into wiring $5.9M. SS&C had failed to follow own internal policy requiring four-person authorization. AIG denied claim. Court ruled against AIG — but only because criminal act exclusion applied to insured's own acts, not third-party hackers.

Source: CyberScoop

What went wrong in every case

The same proof gap appears across every cyber insurance dispute: companies cannot cryptographically prove their security posture at the time of breach.

  • MFA misrepresentation voids policies — not in place where the breach actually happened
  • Security attestations on applications are unverifiable — no way to prove controls existed
  • Incident timelines disputed — misclassified alerts, delayed response, no tamper-proof timestamps
  • Insurers now suing cybersecurity vendors after paying claims
  • 40-44% claim denial rate in 2024 — "what was in place at breach time?" is unanswerable

How tamper-proof evidence changes the equation

Cryptographic audit trails make it mathematically impossible to alter or destroy records without detection.

Security Controls Are Cryptographically Attested

MFA status, patch levels, and security configurations get continuous cryptographic receipts. When an insurer asks 'was MFA active at breach time?' — the answer is a mathematical proof, not a checkbox on an application form.

Incident Timelines Are Immutable

Every security event, alert, and response action is timestamped with cryptographic proof. Trustwave's misclassification and Hamilton's delayed disclosure become provable facts, not disputed narratives.

Vendors Can Prove Their Obligations

Cybersecurity vendors facing subrogation lawsuits can demonstrate they fulfilled their contractual obligations with cryptographic evidence — not just logs that could have been altered after the incident.

Ready to make your audit trail tamper-proof?

Create your free account and start protecting your data with cryptographic evidence that can't be altered or destroyed.