SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. This page explains vocabulary; it is not legal advice, not insurance advice, and not a coverage determination, no attorney-client relationship arises from reading it, and the answer in any real matter turns on your own policy wording and the law of your state.
Definition
The decision that has to have moved can be any of several: whether to write the risk at all, at what price, at what limit, with what retention, or with what conditions attached. Materiality is the hinge. An inaccurate answer that fails the test is generally of no effect, and an inaccurate answer that passes it is what supports rescission or a denial.
In many US states the test is framed objectively: not whether this underwriter was in fact swayed, but whether a reasonable insurer would have been. A number of jurisdictions measure the effect on this carrier instead, so the governing law matters. Carriers evidence it with their own underwriting guidelines, their referral rules, and testimony about what the submission would have triggered had the answer been the other way.
How it works in a cyber policy
Cyber is unusual in how easy materiality is to demonstrate, for a reason that has nothing to do with law.
Since the ransomware losses of 2020 and 2021, a handful of controls became conditions of quoting across most of the US market rather than rating factors. Multi-factor authentication on email and remote access is the clearest example: an application answering no to it is often declined outright or routed to a different market. When a control is a gate rather than a dial, the materiality argument makes itself. The carrier does not have to reconstruct a pricing model, only show that a no would have stopped the submission.
The ordering below is an editorial assessment of how easily a carrier could establish materiality, drawn from how US cyber submissions are commonly underwritten. It is not an underwriting rule, no carrier has reviewed it, and no policy turns on it.
- Prior claims, incidents, and known circumstances. Loss history is the strongest single predictor of future loss, and the no known loss or prior knowledge statement is the answer a carrier reaches for first.
- Revenue, record counts, and business activity. Revenue is the rating base, so a misstatement is material as arithmetic. A misstated activity, such as providing IT services to third parties, holding protected health information, or handling card data, is an appetite question that can move the submission to a different market entirely.
- Multi-factor authentication coverage on email, remote access, and privileged accounts.
- Backup immutability, segregation, and restore testing, which drive ransomware pricing more than any other technical block.
- Externally observable exposure: internet-facing remote desktop, end-of-life systems, unpatched known-exploited vulnerabilities. Carriers scan for these before quoting, so proving the answer was wrong costs them nothing.
- Endpoint detection coverage and whether it is monitored.
- Funds transfer and social engineering controls. The sublimits attached to these covers are small enough that a carrier will often contest rather than settle.
- Policy documents, training cadence, and process questions, where an inaccuracy is real but rarely decisive on its own.
That ordering is a useful way to triage an application. The answers at the top deserve a dated reading of the environment. The ones at the bottom deserve care and honesty but not an audit.
What these two disputes actually show
Neither of the two US matters cited most often produced a ruling on materiality. In Travelers Property Casualty Co. of America v. International Control Services, Inc. the carrier pleaded that an inaccurate enterprise-wide multi-factor authentication answer materially affected its acceptance of the risk, and the parties stipulated to rescission before any court weighed the point. In Columbia Casualty Co. v. Cottage Health System the materiality of the self assessment answers was never reached at all.
Carrier practice, rather than case law, is what makes materiality predictable on the controls listed above. The full record of both matters is on the rescission page.
SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. This page explains vocabulary; it is not legal advice, not insurance advice, and not a coverage determination, no attorney-client relationship arises from reading it, and the answer in any real matter turns on your own policy wording and the law of your state. Statements on this page about what a party did, knew, or intended are allegations drawn from court filings and contemporaneous reporting, not findings of fact; neither matter was decided on the merits. If a live application, renewal, or claim depends on any of this, take advice from a licensed broker and qualified coverage counsel. Last reviewed 2026-08-24.
What this means for the answer you are about to sign
What actually happens if you answer a cyber insurance application incorrectly?
In the ordinary case, nothing. Most inaccuracies are immaterial, no loss ever lands on them, and no one ever looks. That is the honest base rate and it is worth saying plainly.
In the case that matters, a loss lands on the control the answer overstated. The forensic report the carrier funds describes that control, the adjuster reads it against the application, and the carrier now has a materiality argument on one of the items at the top of the list above. The outcome then depends on the policy wording and the governing state law, and it ranges from nothing, through a negotiated reduction, to a denial or an attempt at rescission.
The gap between those two cases is narrower than it looks, and it is closed at signing time rather than at claim time. Read the environment for the answers at the top of the list. Where the reading disagrees with the answer you were about to give, change the answer and let the broker carry the gap into the negotiation with a remediation date attached. An accurate no is not a misrepresentation.
Where the evidence for that answer lives
The top of the materiality list is almost entirely readable from a live environment: MFA coverage as a ratio rather than a policy name, EDR deployment percentage, backup immutability and last successful restore test, log retention, and privileged account inventory. The question library works through each one.
Frequently asked
What happens if you answer a cyber insurance application incorrectly?
In most cases nothing, because most inaccuracies are immaterial and no loss ever lands on them. The consequence appears when the inaccuracy is material, meaning an accurate answer would have changed the underwriting decision, and a loss arises on that control. The carrier can then argue for rescission of the policy, denial of the claim, or a reduced settlement, and whether it succeeds depends on the policy wording and the law of the governing state.
What makes an application answer material?
That an accurate version would have changed whether the carrier wrote the risk or the terms it wrote it on. In cyber, controls that are conditions of quoting, such as MFA on remote access, are material almost automatically, because a no would have stopped or rerouted the submission.
Who decides whether an answer was material?
The carrier asserts it, and if the matter is litigated a court decides, in many states on an objective standard of what a reasonable insurer would have done. Carriers support the assertion with their underwriting guidelines and referral rules.
Is a small overstatement material?
It depends on which side of a threshold it falls. Saying EDR covers 100 percent of endpoints when it covers 97 is unlikely to be decisive on its own. Saying MFA is enforced on all remote access when a single excluded account was the entry point is a different matter, because that is the control the loss ran through.
Does materiality apply to the ransomware supplemental too?
Yes, and often more sharply, since the supplemental concentrates on exactly the controls that ransomware losses turn on.
Sources
Every statement about a court case on this page is drawn from the documents and reporting below. Links open on the publisher's own site.
- Columbia Casualty Co. v. Cottage Health System, complaint filed 7 May 2015 (copy via Internet Archive; docket available on PACER and CourtListener) Internet Archive
- Cyber insurer seeks to void data breach coverage because of purported misstatements in policy application (16 June 2016) Covington, Inside Privacy
- Travelers, policyholder agree to void current cyber policy (30 August 2022) Insurance Journal
- Travelers v. ICS underscores need to respond carefully to cyber insurance application questions (15 September 2022) Lockton
Full captions: Columbia Casualty Co. v. Cottage Health System, No. 2:15-cv-03432-DDP-AGR (C.D. Cal., filed 7 May 2015, dismissed without prejudice 17 July 2015), refiled as No. 2:16-cv-03759 (C.D. Cal.); Travelers Property Casualty Co. of America v. International Control Services, Inc., No. 2:22-cv-02145 (C.D. Ill., stipulated judgment August 2022). Dockets are available on PACER and CourtListener.
Sources are cited only for the facts attributed to them. The publishers listed are unaffiliated with Insurance Posture and SecValley, have not reviewed or endorsed this page, and their inclusion implies no relationship.
Related terms
Answer from the environment, not from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer, so the answers on the form match a dated reading of the environment before anyone signs.
Assess your posture