Insurance posture management is the practice of continuously checking that the security answers you gave your cyber insurance carrier are still true in your live environment. It turns the application from a form you sign once a year into a set of claims your scans verify every week.
Most GRC programs track frameworks, risks and audits. Very few track the one document that decides whether a breach is covered: the insurance application. That gap has a price, and in the last few years we've watched organizations pay it in full.
The $18.3 million lesson from Hamilton
In February 2024, ransomware hit the City of Hamilton, Ontario. Recovery cost CAD $18.3 million. The insurer refused about CAD $5 million of it because multi-factor authentication had not been fully implemented, and called the missing MFA the "root cause" of the breach.
The part that should make every risk owner wince: a city councillor said "the city had full knowledge we were not compliant" in 2023. Taxpayers covered the bill.
Hamilton is not an outlier. In 2022, Travelers rescinded the cyber policy of International Control Services (ICS) after a ransomware attack. The application said ICS used MFA for privileged access; the investigation found it on the firewall and nothing else. On August 26, 2022, a court entered judgment voiding the policy. Not a denied claim: a policy that legally never existed.
We covered why cyber insurance claims get denied before. This post is about the fix.
Why this is a GRC problem, not a broker problem
A law firm alert published on September 29, 2026 put the trend in one line: carriers now "condition both the binding of coverage and the honoring of claims on specific, verifiable security controls, documented operational procedures, and ongoing compliance throughout the policy period."
With your GRC hat on, that's a control requirement whose auditor only shows up after the worst day of your year. It has three properties your risk register usually ignores:
- It's a representation, not a goal. "We require MFA for all remote access" is a factual statement your CEO signed. Aspirational answers are the most dangerous kind.
- It drifts. The answer was true in March. Then someone excluded a service account from Conditional Access for a migration and never put it back.
- Nobody owns it. Finance renews the policy, the broker fills the form, IT runs the controls. The three rarely compare notes.
So treat the application like any other control set: assign an owner, measure it, and keep dated evidence. For the longer version, see security posture vs insurance posture.
Key definitions
- Insurance posture: how closely your actual security configuration matches what you told your carrier on the application and policy documents.
- Representation: a factual statement on the application ("MFA is enforced for all admins") that the carrier relies on to price and bind coverage.
- Material misrepresentation: a false representation the carrier would have weighed in deciding to issue the policy. It can support a denial or a rescission.
- Rescission: the carrier treats the policy as void from the start, so there's no coverage for any claim in that term.
- Drift: the gap that opens when a control that was true at signing stops being true later.
How SecValley Insurance Posture Management works
We built Insurance Posture into SecValley, the Security Evidence Platform, because we kept seeing the same failure: a "yes" on the form and a "partly" in the tenant. Here's the flow:
- Upload your documents. Add your cyber policy or application form. The analyzer reads it and extracts your answers, and you confirm the policy details (carrier, limit, retention, expiry).
- Sort the questions. Every answer lands in a bucket: matched and scanner-verifiable, not scanner-verifiable (organizational practices you confirm manually), or missing from your form. Answers where a mistake can void coverage are flagged as High materiality, so you review those first.
- Let scans verify. Each technical answer is checked against the latest completed Scan of the matching Connection, across your cloud, identity and SaaS environments (Microsoft 365, Entra ID, Azure, AWS and more).
- Read the verdict. Each answer shows whether your scan contradicts it ("Contradicts your scan"), backs it up, or shows you're actually stronger than you said ("Better than you told your carrier"). Anything a Scanner can't see stays marked as not scanner-verifiable rather than being quietly counted as a pass.
- Brief your broker. At renewal, generate a broker discussion brief that drafts notes on where your evidence is strong, where scans contradict your answers, and what changed since the application.
Two design choices matter most. A passing result older than 45 days stops counting as verified, so stale evidence can't hide drift. And every Connection of the same kind must be scanned before an answer counts: ICS had MFA on one asset, and a check of only that asset would have said "yes."
What to do this week
Pull your cyber application. For every question on MFA, backups, EDR and privileged access, write down who can prove it today, with what evidence, from what date. "Nobody" or "a screenshot from last year" marks your highest-risk control. For what carriers ask, see cyber insurance security requirements.
FAQ
What is insurance posture management?
It's the continuous comparison of your cyber insurance application answers against your real security configuration, so a gap shows up before a claim instead of during one.
Can a carrier deny a claim if a control was only partly in place?
Yes, it has happened. Hamilton's insurer refused about CAD $5 million in claims because MFA was not fully implemented at the time of the attack.
What is the difference between a claim denial and a rescission?
A denial refuses one claim. A rescission voids the whole policy from the start, as in Travelers v. ICS, so nothing in that policy term is covered.
Which answers can SecValley verify automatically?
Technical answers that map to configuration checks in any connected cloud, identity or SaaS environment, such as Microsoft 365, Entra ID, Azure or AWS. Organizational practices, like training cadence, are marked not scanner-verifiable and confirmed manually.
How often is an answer re-checked?
Every completed Scan of the matching Connection updates the verdict. A passing result older than 45 days no longer counts as verified.
Does SecValley tell me whether I'm covered?
No. Coverage decisions are made solely by your carrier.
Disclaimer: SecValley Insurance Posture output is informational only and is not legal or insurance advice. Coverage decisions are made solely by your carrier. Talk to your licensed broker and counsel about your policy.