The Policy That Won’t Pay: Cyber Insurance and the Small Print That Decides Everything
The Sekhmet Scribe | Team Sekhmet
THE CLAIM WAS DENIED IN WRITING. IT TOOK NINE WEEKS.
The breach was real. The losses were real. The policy was live and the premium was paid. And the insurer still said no — not because the attack wasn’t covered, but because a control the business had declared on its application form turned out not to be switched on everywhere it claimed.
Nobody lied. Somebody answered a question in good faith about a system they hadn’t checked in eighteen months.
This edition of The Sekhmet Scribe is about cyber insurance: what it actually buys you, why claims fail, and why the underwriting form has quietly become one of the most consequential security documents in your business.
Protect • Empower • Evolve
WHAT’S HOT 🔥
Underwriting Is the New Audit
Cyber insurance used to be easy to buy. A short form, a modest premium, a policy in the drawer. That market is gone. Insurers have absorbed enough ransomware losses to know precisely which controls change their odds, and they now ask about them by name: MFA on remote access and privileged accounts, tested and segregated backups, endpoint detection and response, patching cadence, email filtering, privileged access management.
Those questions are not a formality. They function as warranties. Answer them optimistically and you haven’t bought protection, you’ve bought a dispute.
There is an upside, and it’s a real one. The underwriting questionnaire is now a free security assessment, funded by the people betting money on your survival. It tells you exactly which controls they think matter most.
WHAT’S HOT 🔥
The Cover Is Narrower Than the Risk
Even a valid, paying policy does not make you whole.
Business interruption cover frequently carries a waiting period longer than the outage most firms actually suffer. Reputational damage, lost customers and management time are rarely recoverable. Systemic-event and state-actor exclusions have tightened considerably. And for regulated businesses, an insurer’s cheque does nothing to settle the regulator’s view.
Insurance transfers a slice of financial loss. It does not transfer operational disruption, contractual failure, or the conversation with your largest client. Those stay exactly where they were.
WHAT’S NOT ❄️
Buying cover without reading the exclusions. Completing the proposal form from memory rather than from evidence. Letting finance answer technical questions unaided. Assuming MFA is “on” because it was rolled out once, two years ago, to most people. Discovering your incident response obligations — panel breach counsel, notification windows, insurer consent before you engage anyone — at 2am on the night it matters.
A policy you cannot claim on is not a control. It’s a subscription.
THE SEKHMET STANCE
Cyber insurance is a legitimate and valuable part of a resilience strategy. It is not a substitute for one.
At Sekhmet we treat the underwriting questionnaire as a technical document rather than an administrative one. We evidence the controls, close the gaps before the form is signed, and make sure the answers you give are answers you can still prove eighteen months later when someone is looking for a reason not to pay. For our private equity clients we do it consistently across the portfolio, because one weak declaration can move renewal terms for everyone.
The lioness does not hunt on the assumption the herd will be there. She checks.
Don’t buy the policy and hope. Earn it, evidence it, and know exactly what it will and won’t do.
Protect • Empower • Evolve
Team Sekhmet