The Box You Checked on the Application Is Now the Center of the Claim

Three of the biggest breaches reported this week had nothing in common except the thing that caused them. 

The Pentagon's Defense Manpower Data Center lost records on roughly 2.76 million living people — Social Security numbers, dates of birth, contact and occupational data — over an intrusion that ran from October 2025 into mid-July 2026. The files were unencrypted. 

France's tax authority exposed data on as many as 678,000 taxpayers. Attackers logged in with employee passwords harvested by infostealer malware, through portals that had no multi-factor authentication, and went undetected for about seven weeks. 

And Proofpoint documented a Microsoft 365 password-spraying campaign that hit 5,714 accounts across 28 organizations. Seven were compromised. Every one of them was a "functional" account — a shared mailbox, a service login, the scanner account nobody owns — and every one of them lacked MFA. They fell within minutes. 

Different victims, different continents, same failure: an authentication control that was either missing or quietly not applied to the accounts that mattered. 

Why a property adjuster is writing about this 

Because the control that failed in those breaches is the same control your carrier will ask about if you file a cyber claim — and the question will not be whether you bought MFA. It will be whether MFA was actually enforced, on that account, on the day of the loss. 

That is a documentation question. It is the same kind of question that decides a water loss or a fire claim: not what the policy says in the abstract, but what the file can prove about the condition of the risk at the moment it failed. 

The market has moved in that direction fast. Industry reporting this year puts the average global ransomware claim at roughly $713,000, up from about $374,000 the year before. Claims that size get underwriting-grade scrutiny. Insurers are going back to the application, the attestation, the controls questionnaire — and asking the insured to prove the answers were true in practice, not just at signing. 

Most cyber applications ask some version of do you require multi-factor authentication for remote access and administrative accounts? Most insureds answer yes in good faith. Then the breach happens through a service account, a legacy mail protocol, or a contractor login that was exempted during a migration two years ago and never brought back in. 

Nobody lied. The box was still checked. And the carrier now has an argument. 

The second lever: what the endorsement actually limits 

The other place cyber recoveries shrink is the sub-limit page. 

In CiCi Enterprises v. HSB Specialty Insurance, a federal court in the Northern District of Texas refused to let the carrier cap a cyber-extortion loss at a $250,000 ransomware sub-limit. The reason was not sympathy. It was drafting: the endorsement never clearly stated which coverage it was limiting. The ambiguity went against the insurer, and the larger policy limit stayed in play. 

That is a reminder, not a rule. But it is worth internalizing that a number printed on an endorsement is a contract term like any other — and if it does not plainly say what it applies to, it is arguable. 

Why it matters for policyholders 

Cyber is the newest line on most commercial property schedules, and it is the one where the gap between what you bought and what you can collect is widest. Two things drive that gap, and both are addressable before anything happens: 

Keep an evidence file for your controls, not just a policy for your risk. Screenshots of MFA enforcement settings. Conditional-access policy exports. The date each exception was opened and the date it was closed. A quarterly list of service and shared accounts and their authentication status. This takes an hour a quarter and it is the only thing that answers a post-breach controls challenge, because it cannot be reconstructed after the fact. 

Re-read your application the way an adjuster would. Pull the signed questionnaire and go line by line. For every "yes," ask who would prove it and with what. Where the real answer is "yes, except for these four accounts," say so now — in writing, to your broker. A disclosed exception is an underwriting conversation. An undisclosed one is a claim defense. 

Know what your endorsements limit. Find every sub-limit that touches cyber — extortion, business interruption, forensics, notification — and confirm in plain language which coverage each one caps. If you cannot tell from the wording, that is not your failure to understand it. That is a drafting problem, and it cuts your way. 

Patch the things actually being exploited. This week's list: an Apple CoreGraphics zero-day (CVE-2026-86950, fixed in iOS/iPadOS 26.7.1), a critical Fortinet FortiMail flaw, and unpatched Citrix NetScaler remote-code-execution bugs at network edges. Meanwhile Warlock ransomware is hitting water utilities, telecoms and universities through Microsoft SharePoint flaws. Carriers read the same advisories you do, and "known exploited, unpatched" is a bad fact in a claim file. 

The lesson 

A cyber policy is sold on what it covers. It is paid on what you can prove about how you were running the week it happened. 

CISA opened Cybersecurity Awareness Month this year with a critical-infrastructure campaign and a set of toolkits aimed at smaller organizations. Use the month for the unglamorous version: confirm MFA is on every account including the ones nobody owns, export the proof, and file it where you can find it in a hurry. 

The record that supports a cyber claim gets built before the breach, or it does not get built at all. 

Incidents and figures summarized from public cybersecurity and insurance reporting. Court outcomes are specific to their facts. Nothing here is legal advice or a coverage opinion on any particular policy. 

Next
Next

Policy Review: Digit Parametric Insurance Policy