A cyber insurance application gives you two boxes, yes and no. Most control questions have three honest answers: verified, where a query read the setting and returned a value on a date; attested, where a person asserts it and nothing read anything; and unreadable, where the check ran and could not conclude. The form has no box for the third state, so it gets rounded into yes. That rounding, not weak security, is what turns a good faith answer into a material misrepresentation.

Nobody sets out to lie on an application. Someone answers yes to MFA because MFA is on, and nobody checks which accounts fall outside the policy. The binary does not record what was known, it records what was believed, and belief is what gets read back after a loss. That mechanism, including a policy rescinded from inception over one sentence about MFA, is in why cyber insurance claims get denied.

The Three States

Verified. A named query ran against the live environment and returned a value that decides the answer: Conditional Access scope with the count of excluded principals, standing Global Administrator assignments, backup lock state and who can write to it. The answer carries the value and the date it was read.

Attested. A person asserts it, in writing, with a name and a date. Training completion, vendor terms, whether the incident response plan was actually exercised. Legitimate, and no scanner will ever produce it. It just has to be labelled, so nobody later mistakes memory for measurement.

Unreadable. The check ran and could not conclude: a missing permission, a licence tier that does not expose the data, a resource outside the connected scope. Here the rule is absolute. An unreadable check is never rendered as a pass, because a silent failure painted green looks exactly like a real answer and produces a false one.

Answer state What stands behind it What it survives
Verified A query, a value, a date Forensic reconstruction after a loss
Attested A named person and a signature date Good faith review, if the assertion holds
Unreadable Nothing yet Nothing. It is work, not an answer

Why Unreadable Is the Useful One

Flagging a question unreadable looks worse on the form and behaves better at claim time. It converts an unknown into a scoped, dated known that a broker can carry into the submission and an underwriter can respond to, by subjectivity, by warranty, or by price.

The asymmetry is the whole point. Rescission arguments run on the accuracy of what was represented, not on the existence of a weakness everyone could see on the paper. A question you flagged is a question the carrier had the chance to price. A question you rounded to yes is one only your forensic firm will ever read.

Before You Sign

Take the real question set, not a generic checklist. Sort every question by whether any API in your estate can decide it, which is a one-time exercise. Run the read-only scan and record the value and the date beside each verifiable answer; where each answer lives across Microsoft 365, Entra ID, and Azure is already mapped. Label the rest attested, with an owner. What is left unreadable is the pre-bind work list, and it is usually permissions rather than security.

Two boundaries keep this honest. A configuration read proves state on a date, not that a control operated all period, so repeated readings matter more than one clean one. And the controls that decide a ransomware claim sit inside the tenant, out of reach of any outside-in rating, as set out in the five controls an underwriter cannot see.

This three-state model is how SecValley is built rather than a position we recommend. Our scans read Microsoft 365, Entra ID, and Azure read-only, and any check that cannot be read is reported as unanswered, never as passed. Insurance Posture runs on the same scans and marks every carrier question verified, attested, or unreadable instead of forcing a binary, with the question library published at insuranceposture.com/questions so the mapping can be checked rather than taken on trust.

SecValley is a security scanning and compliance platform, not an insurance broker, agent, or carrier. Nothing here is insurance, legal, or coverage advice. Policy wording and underwriting practice vary by carrier, policy, and state. Talk to your broker and your counsel.

Frequently Asked Questions

Is answering unreadable worse than answering no?

They are different statements. No is a claim about the environment, that the control is absent. Unreadable is a claim about the evidence, that nothing could decide the question at the time of asking. The accurate answer is the one you can still defend when it is read back.

Can everything on a cyber insurance application be verified automatically?

No, and a platform claiming otherwise is describing something else. Identity, privilege, logging, and backup configuration is largely queryable. Training, contracts, and whether a tabletop happened stay attestations.

Does a verified answer stay true after binding?

Not on its own. An exclusion added in month three does not announce itself, and the answer signed in month zero is what the carrier reads. The useful unit is the drift between two dated readings, which is the difference covered in security posture vs insurance posture.