You Have Cyber Insurance. But Are You Actually Insured?

Liked this post? Share with others!

You pay the premium. You have the policy. 

So surely, if something goes wrong, you’re covered?

Not necessarily.

This is something many businesses don’t think about until they’re trying to make a claim.

Your cyber insurance policy may assume that certain security controls are already in place.

MFA. Backups. Endpoint protection. Access controls. Patching. Monitoring.

You may have been asked about them when you took out the policy, or the application form could state that they assume it is already in place. 

Here’s the uncomfortable question: Can you prove they were actually in place when the attack happened?

“We have MFA” isn’t enough

Imagine your business gets compromised. The attacker uses a stolen password to access a user’s account.

You tell your insurer: “We have MFA.”

They ask:

  • Which accounts were protected.
  • Was MFA enabled for everyone?
  • Were there exceptions?
  • Were privileged accounts protected?
  • Was it actually enforced?
  • Can you demonstrate it?

The same applies to your other controls.

“We have backups.”

Great. Can you demonstrate that they’re protected from ransomware and that you can actually restore the business?

“We have antivirus.”

Is it deployed everywhere? Is it working? Is anyone monitoring it?

“We have 24/7 security.”

What exactly is being monitored?

These aren’t theoretical questions. They are questions businesses should be asking before they have an incident.

The NCSC advises organisations to keep the security information provided to insurers accurate and up to date, warning that claiming security controls are in place when they aren’t can affect whether a claim is paid.

Cyber insurance isn’t cyber security

This is the distinction that matters. Insurance helps transfer financial risk but it doesn’t stop an attacker getting your password. It will not monitor your Microsoft 365 account. It doesn’t detect someone quietly moving through your network. It doesn’t protect your data and it doesn’t make you secure because you’ve paid the premium.

Insurance is the safety net. Cyber resilience is what stops you falling through the floor.

Security needs to be more than a tick box, this is why at J2 we talk about cyber resilience across five areas:

Users. Email. Data. Machines. Internet.

Because an attacker doesn’t care what security products you bought. They look for the weak link that gets them in. 

  • A compromised user.
  • A phishing email.
  • A stolen credential.
  • An exposed system.
  • A vulnerable machine.
  • Access to valuable data.

Once something gets through, you need to be able to see it, understand it and respond.

That’s cyber resilience, it is not about simply having security tools.

Don’t discover the gap when you make the claim

The worst time to discover your MFA wasn’t protecting everyone is after an account has been compromised. The worst time to discover your backup doesn’t work is after ransomware and the worst time to discover that nobody was monitoring your environment is after an attacker has been inside for months.

The worst time to find out what your cyber insurance policy expects from you is when you’re making a claim.

  • Check your controls.
  • Check your policy.
  • Check your evidence.

We are here to make sure your cyber resilience actually matches the security you’re telling your insurer you have.

Because having cyber insurance doesn’t mean you’re secure.

Cyber insurance is a part of the digital risk mitigation strategy. The security is still your responsibility.

author avatar
John Mc Loughlin Director
John Mc Loughlin is a cybersecurity and digital resilience specialist with experience in email security, phishing mitigation, and data protection strategies. He works with organisations to reduce digital risk and improve operational resilience.

Request Consultant