View all Managed IT services →
View all IT Services →
View all Cybersecurity services →
View all Cloud services →
Network Management & Security
Network Management Network Security

Most small businesses answer their cyber insurance application wrong, and they find out at the worst possible moment.

Not deliberately. The form arrives, it asks thirty technical questions about controls nobody in the building owns, and it gets handed around until someone fills it in. Sometimes that is the owner. Sometimes the office manager. Sometimes the insurance broker takes a run at it. In Jim O’Connell’s words, from years of watching this happen across Scottsdale and Phoenix businesses: it is a burden that gets passed around, and nobody really knows what is going on.

That matters more than it used to. Your answers are not a formality. They are representations on a legal document, and they determine whether the policy pays.

Answering these questions for clients is part of what Axio Networks does — we complete the technical sections of applications, questionnaires and renewals, then hand the form back for the line-of-business questions we have no visibility into. This is what we see go wrong.

The three answers that get small businesses in trouble

Across the applications we work on, the same three questions get answered “yes” when the honest answer is “no” or “we don’t know.”

1. Multi-factor authentication — specifically its scope. Almost nobody has a clear picture of where MFA is actually enforced. The application does not ask “do you use MFA,” it asks whether MFA is required for email, for remote network access, and for administrative accounts. Those are three different questions, and a business can genuinely have MFA while failing two of them. Our guide to how we actually deploy MFA covers getting that scope right, including the awkward cases — shared machines, service accounts and the scanner that emails.

2. Backups — specifically whether they are tested. Many businesses believe they have backups. Very few have tested a restore. The backup runs, the job reports success, and nobody discovers what is actually in it until they need it back. An untested backup is an assumption, and the application is asking about a control. Managed backup means the restore test is somebody’s job.

3. Endpoint security. There is a persistent belief that careful people do not need endpoint protection — that if nobody clicks bad links, the firewall is enough. Modern intrusions do not require anyone to click anything obviously bad, which is why carriers now ask specifically about endpoint detection rather than antivirus. As we covered in our walkthrough of how ransomware and wire fraud actually reach Arizona businesses, the current lure arrives from a genuine Dropbox or DocuSign account and passes every authentication check.

Why a wrong answer voids the policy

The mechanism has a name: rescission. If an insurer can show that a material representation on the application was untrue, it can seek to void the policy from inception — not deny one claim, but unwind the contract as though it never existed.

The case every broker now cites is Travelers Property Casualty Company of America v. International Control Services, filed in the Central District of Illinois in July 2022. Travelers sought rescission of a $1 million cyber policy on the grounds that the insured had attested it required MFA for employee and third-party access to email, remote network connections and endpoints, when in fact MFA was deployed only on the firewall. The parties agreed to void the policy that August.

Read that failure mode carefully, because it is not exotic. It is the MFA scope question, answered optimistically by somebody who believed they had MFA. That is the single most common wrong answer we see.

The practical consequence: a business that answers the application honestly and gets a smaller policy at a higher premium is in a far better position than one that answers well and discovers at claim time that the coverage was never enforceable.

Carriers stopped taking your word for it

The most significant change in this market over the past two years is not price. It is verification.

Applications used to work on trust. You signed the questionnaire, sent it back, and the policy issued. Carriers have since worked out that a great many of those questionnaires described protections that did not exist. So they now verify — external scanning, evidence requests, and in some cases a genuine security review before a policy is approved or renewed.

We have been through that review process on the application side, and we welcome it. A fresh set of eyes examining a client’s posture either confirms the work is right or finds something worth fixing. Both outcomes are useful, and it is the same exercise as a security assessment done on your own terms rather than a carrier’s. It also means the gap between what a business claims and what it can prove has become expensive to maintain.

What the policy actually pays for

Cyber policies split into two halves, and small businesses routinely misjudge which half they need.

First-party coverage pays for your own losses: incident response and forensics, data restoration, business interruption while you are down, extortion payments and negotiation, and breach notification costs. This is the half that responds when you are the victim.

Third-party liability pays when someone else’s data was in your care: privacy liability, regulatory defence and penalties, and the legal costs of defending claims. For a title agency holding buyer financial information, or a medical practice holding patient records, this is not optional.

The one that matters most for real estate, title and escrow is usually neither of those by default. Fraudulent wire transfer losses — where an employee was deceived into sending money to an attacker — typically fall under a social engineering or funds transfer fraud endorsement. That is frequently a rider rather than core coverage, and it usually carries its own sublimit well below the policy’s headline figure. A $1 million policy can carry a $100,000 social engineering sublimit, and the wire that went out was for $340,000.

The FBI’s Internet Crime Complaint Center recorded $3.04 billion in business email compromise losses across 24,768 complaints in 2025, plus $275.1 million in real estate fraud specifically. That is the loss event most likely to hit a Valley title office, and it is the one most likely to sit outside the coverage the business thinks it bought.

Reviewing this is a standing item for our clients. As part of our quarterly check-ins we go through the policy annually with the client and their insurance agent, so the coverage and the limits actually match the business. What the right answer is varies genuinely by client — but it should be a decision somebody made on purpose, not a default nobody read.

What it does not cover

Four exclusions account for most of the unpleasant surprises.

Anything you already knew about. Policies exclude incidents known or reasonably discoverable before the policy period began. If an intrusion started in March and you bound coverage in May, the carrier will look hard at when it should have been discovered. This is another argument for monitoring that would actually surface an intrusion — you cannot report what nobody saw.

Failure to maintain the controls you described. Many policies contain a clause excluding losses arising from a failure to maintain the security standards represented at application. This is the quiet one. You are not only asserting that MFA was enforced on the day you signed; you are undertaking to keep it that way. A policy renewed on an attestation that has since drifted out of date is exposed in exactly the same way as one that was wrong from the start.

War and state-sponsored action. Following large-scale attributed attacks, carriers have tightened these clauses considerably. Wording varies enough between carriers that it is worth reading rather than assuming.

Loss of future business. Cyber policies pay for measurable interruption during the incident. They do not compensate for the clients who quietly stop calling afterwards, which for a title agency or a brokerage is frequently the larger long-term cost.

The pattern is that exclusions cluster around what you should have known and what you said you were doing. Both are controllable, and both are why the honesty of the application matters more than its score.

What a breach actually costs in Arizona

National averages are close to useless for a twenty-person business. Arizona statute is not.

Under A.R.S. § 18-552, an Arizona business that determines a breach of unencrypted personal information has occurred must notify affected individuals within 45 days of that determination. If the breach requires notifying more than 1,000 individuals, you must also notify the Arizona Attorney General, the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies.

Civil penalties run to the lesser of $10,000 per affected individual or the total economic loss sustained, with a maximum of $500,000 for a breach or series of related breaches.

Those obligations start on determination, not on resolution. Forty-five days is not long to identify whose data was involved, produce notifications and stand up a response — which is precisely what first-party breach response coverage exists to fund. A business without it is paying for all of that out of operating cash while also trying to run.

How to be able to answer the application honestly

The goal is not a better-looking application. It is an application you could defend.

  1. Establish MFA scope precisely. Not “do we have MFA” but: is it enforced on email, on every remote access path, and on administrative accounts, for every user including the owner and any external IT.
  2. Test a restore. Actually restore something and confirm the contents. If nobody has done this in the last quarter, the honest answer to the backup question is that you do not know. See what immutable backup means on your insurance form for what carriers are now asking beyond simple backup.
  3. Confirm endpoint coverage is real and monitored. Licensed is not deployed, and deployed is not monitored. The question behind the question is whether anyone would notice a detection.
  4. Find out whether you have a social engineering endorsement, and what its sublimit is. Ask your agent directly. This is the number that matters if a wire goes out.
  5. Keep the evidence. Carriers increasingly want proof, and assembling it under renewal deadline pressure is how errors get made. Our guide to answering renewal questions walks through the specific wording carriers are using now.

A note on where we sit in this: Axio Networks is not an insurance broker and we do not sign anything for a carrier. We answer the technical questions accurately, we sign off to our clients that the controls are in place, and we only do that after verifying them internally. Coverage decisions belong with you and your agent.

Frequently asked questions

Can an insurer really void a cyber policy over an application answer?

Yes. It is called rescission, and it unwinds the policy from inception rather than denying a single claim. In Travelers v. International Control Services, the insurer sought rescission of a $1 million policy over an MFA attestation that did not match the deployment, and the parties agreed to void the policy. Materiality is the test — whether the true answer would have changed the underwriting decision.

Does cyber insurance cover a fraudulent wire transfer?

Often only if you have a social engineering or funds transfer fraud endorsement, and often only up to a sublimit that is much smaller than the headline policy limit. Because an employee authorised the transfer, this loss frequently falls outside standard first-party coverage. Confirm the endorsement and the sublimit with your agent rather than assuming.

Who should fill out the cyber insurance application?

The technical sections should be answered by whoever actually administers the systems, because those questions are about configuration, not intent. The business sections belong to the owner. Problems arise when the whole form is handed to one person who can only answer half of it accurately.

What is different about applications now versus a few years ago?

Carriers verify. Attestation alone is no longer sufficient at renewal for many carriers, and external scanning or evidence requests are common. The gap between claimed and actual controls has become expensive to maintain.

How long does an Arizona business have to report a breach?

Forty-five days from determining that a breach of unencrypted personal information occurred, under A.R.S. § 18-552. Breaches affecting more than 1,000 individuals also require notice to the Attorney General, the Arizona Department of Homeland Security and the three largest consumer reporting agencies.

Will better security lower our premium?

It affects eligibility more reliably than price. Several controls — enforced MFA, tested and immutable backups, managed endpoint detection — have moved from discount factors to prerequisites. The more useful framing is that good controls determine whether you can get meaningful coverage at all.

Sources and further reading

Talk to an IT team in Scottsdale

Most of the gaps described above are closed by controls that are already bundled with tools small businesses pay for — the work is turning them on and keeping them on.

Axio Networks is a managed IT and cybersecurity provider based in Scottsdale, Arizona. Founded in 2019, we support small and mid-sized businesses across the Phoenix metro — Scottsdale, Phoenix, Tempe, Chandler, Mesa, Gilbert and Fountain Hills — with an under-30-minute average response time.

Start with a free IT assessment, call 480-602-2946, or email [email protected].

Related: Cybersecurity services · Security assessments & audits