---
title: "Misrepresentation: when an application answer stops being accurate"
url: https://insuranceposture.com/glossary/misrepresentation
category: "Glossary, consequence terms"
term: "Misrepresentation"
updated: 2026-08-24
---

# Misrepresentation: when an application answer stops being accurate

URL: https://insuranceposture.com/glossary/misrepresentation
Section: Glossary, consequence terms
Term: Misrepresentation

Almost no misrepresentation on a cyber application is a lie. It is an answer that was true of the intent, true of the policy document, and not true of the environment.

SecValley research team. Reviewed 2026-08-24.

SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. This page explains vocabulary; it is not legal advice, not insurance advice, and not a coverage determination, no attorney-client relationship arises from reading it, and the answer in any real matter turns on your own policy wording and the law of your state.

## Definition

A misrepresentation is an inaccurate statement of fact made on an insurance application. On a cyber application it usually takes the form of a control described as in place that was not in place, or not in place everywhere the answer implied.

The carrier relies on what the form says when it decides to offer coverage and on what terms, so an answer that is not accurate is not a formality. On a cyber application a misrepresentation rarely looks like deceit. It looks like a yes to "is MFA enforced on all remote access" from someone who knew about the Conditional Access policy and not about the eleven accounts excluded from it during a migration two years earlier.

The legal consequence does not depend on intent. It depends on whether the statement was inaccurate and whether it was [material](/glossary/materiality) to the underwriting decision, and on the policy wording and the governing state law. An honest mistake and a deliberate overstatement can lead to the same remedy, which is the part most applicants find surprising.

## How it works in a cyber policy

Three features of a cyber policy turn an inaccurate answer into a coverage problem.

First, the application is usually incorporated into the policy by reference, so the answers are not marketing material that stopped mattering at binding. They are part of the contract. Many cyber forms say this in a clause the signer attests to, and [that attestation clause is itself a question on most applications](/questions/governance-and-workforce/applicant-attest-statements-application-true-complete-accurate-form-basis).

Second, the answers set the price and the terms. A carrier that quoted on the strength of enterprise-wide MFA, immutable backups, and full EDR coverage priced a different risk from the one it would have priced without them. That gap is what the word material is measuring.

Third, the controls the form asks about are exactly the controls a forensic investigation enumerates. A ransomware claim produces an incident report that states which account was compromised, whether it required a second factor, whether the endpoint ran EDR, and whether the backups were reachable from the compromised credential. The claim file therefore contains the audit of your application whether or not anyone set out to audit it.

## What these two disputes actually show

Two US disputes dominate the citations here, and neither settled the question. In Columbia Casualty Co. v. Cottage Health System the insurer alleged that yes answers on an incorporated self assessment were false, and the court dismissed the suit on a procedural ground without ever ruling on them. In Travelers Property Casualty Co. of America v. International Control Services, Inc. the policy was rescinded over a multi-factor authentication answer by stipulation of the parties, not by a decision on the merits. Neither is precedent that an inaccurate answer voids cyber cover, and the statements above about what each side alleged are drawn from pleadings rather than findings.

The full record of both matters, with sources, is set out on the [rescission page](/glossary/rescission).

## Not legal advice

SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. This page explains vocabulary; it is not legal advice, not insurance advice, and not a coverage determination, no attorney-client relationship arises from reading it, and the answer in any real matter turns on your own policy wording and the law of your state. Statements on this page about what a party did, knew, or intended are allegations drawn from court filings and contemporaneous reporting, not findings of fact; neither matter was decided on the merits. If a live application, renewal, or claim depends on any of this, take advice from a licensed broker and qualified coverage counsel. Last reviewed 2026-08-24.

## What this means for the answer you are about to sign

The practical exposure is not the exotic case where somebody lied. It is the ordinary case where the answer was assembled from memory, from a policy document, or from the person who most recently touched the system, at a moment when nobody had a current reading of the environment.

Two habits shrink the exposure to almost nothing, and neither requires a better security posture.

The first is to answer from state rather than from intent. A Conditional Access policy named "Require MFA for all users" is a statement of intent. A dated coverage report showing 412 of 412 enabled accounts in scope is a statement of state. Only the second one survives a claim investigation.

The second is to answer no in writing rather than yes in hope. An accurate no, presented with a named owner, a compensating control, and a remediation date, is an underwriting negotiation the broker can run. Carriers see partial coverage constantly and price it. What they cannot price, and what creates the [rescission](/glossary/rescission) argument later, is a yes that the incident report contradicts.

## Where the evidence for that answer lives

Most of the answers a carrier would later contest are settled by configuration you can read today, not by judgment. Multi-factor coverage, EDR deployment percentage, backup immutability, log retention, and privileged account counts are all enumerable from Microsoft 365, Entra ID, and Azure. The question library on this site works through them one at a time, showing where each answer lives and what a defensible yes requires.

## Related questions

- [Does the Applicant attest that all statements in the application are true, complete, and accurate and form the basis of the policy (misrepresentation voids coverage)?](https://insuranceposture.com/questions/governance-and-workforce/applicant-attest-statements-application-true-complete-accurate-form-basis)
- [Is multi-factor authentication enforced on all email access?](https://insuranceposture.com/questions/multi-factor-authentication/multi-factor-authentication-enforced-email-access)
- [What percentage of endpoints have EDR deployed?](https://insuranceposture.com/questions/endpoint-and-patching/percentage-endpoints-edr-deployed)
- [Are backups kept offline (disconnected) or immutable / air-gapped?](https://insuranceposture.com/questions/backup-and-recovery/backups-kept-offline-immutable-air-gapped)

## Frequently asked

### What is misrepresentation on a cyber insurance application?

A misrepresentation is an inaccurate statement of fact on an insurance application that the carrier relied on when it decided to offer coverage and on what terms. On a cyber application it is usually a control described as in place that was not in place everywhere the answer implied, rather than a deliberate falsehood. Its legal effect turns on materiality rather than on intent, and on the policy wording and the law of the governing state.

### Does it count as a misrepresentation if the mistake was honest?

It can. Materiality, not intent, is the usual test in the US, though some states and some policy wordings require the carrier to show the statement was knowingly false or fraudulent. Intent matters more to how aggressively a carrier pursues the point than to whether the point exists.

### Who is responsible for the accuracy of the answers?

The applicant organisation is. An officer or authorised signer attests on its behalf, which is not the same as taking personal responsibility for every underlying fact, and the IT administrator who supplied those facts is not the one signing. That gap between the person with the knowledge and the person with the signature is where most inaccurate answers are created, which is why the answers are worth reading against the environment before anyone signs.

### Can a control that was true at signing and drifted later be a misrepresentation?

Generally not, because a statement is ordinarily measured as of when it was made, but this depends on the policy wording and the governing state law. Two things complicate it. Most US cyber applications carry a change-in-condition clause requiring the applicant to report any material change between signing and inception, and that gap is commonly three to six weeks. Separately, drift after inception can breach an ongoing condition or a minimum practices requirement, which is a coverage argument rather than a misrepresentation argument. On any specific policy this is a question for coverage counsel.

### Is the ransomware supplemental treated the same way?

Yes. A supplemental is part of the same submission and its answers are relied on the same way. It matters more in practice because it concentrates on the controls that ransomware losses actually turn on.

## Sources

- Internet Archive: [Columbia Casualty Co. v. Cottage Health System, complaint filed 7 May 2015 (copy via Internet Archive; docket available on PACER and CourtListener)](https://archive.org/details/031121143231)
- Covington, Inside Privacy: [Cyber insurer seeks to void data breach coverage because of purported misstatements in policy application (16 June 2016)](https://www.insideprivacy.com/data-security/cybersecurity/cyber-insurer-seeks-to-void-data-breach-coverage-because-of-purported-misstatements-in-policy-application/)
- Insurance Journal: [Travelers, policyholder agree to void current cyber policy (30 August 2022)](https://www.insurancejournal.com/news/national/2022/08/30/682564.htm)
- Lockton: [Travelers v. ICS underscores need to respond carefully to cyber insurance application questions (15 September 2022)](https://global.lockton.com/us/en/news-insights/travelers-v-ics-underscores-need-to-respond-carefully-to-cyber-insurance)

Full captions: Columbia Casualty Co. v. Cottage Health System, No. 2:15-cv-03432-DDP-AGR (C.D. Cal., filed 7 May 2015, dismissed without prejudice 17 July 2015), refiled as No. 2:16-cv-03759 (C.D. Cal.); Travelers Property Casualty Co. of America v. International Control Services, Inc., No. 2:22-cv-02145 (C.D. Ill., stipulated judgment August 2022). Dockets are available on PACER and CourtListener.

Sources are cited only for the facts attributed to them. The publishers listed are unaffiliated with Insurance Posture and SecValley, have not reviewed or endorsed this page, and their inclusion implies no relationship.

## Related terms

- [Materiality](https://insuranceposture.com/glossary/materiality)
- [Rescission](https://insuranceposture.com/glossary/rescission)
- [Warranty (versus representation)](https://insuranceposture.com/glossary/warranty)
- [Claim denial](https://insuranceposture.com/glossary/claim-denial)

---

Insurance Posture by SecValley. https://insuranceposture.com
The question library is written in our own wording to reflect the control topics that recur across US cyber application and ransomware supplemental forms. No carrier form is republished.
SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. Nothing here is insurance advice, legal advice, or a coverage determination, and no attorney-client relationship arises from reading it. Statements about what a party to a cited case did, knew, or intended are allegations drawn from court filings and contemporaneous reporting, not findings of fact.
Your organization's authorized signer remains responsible for the accuracy of any application. Consult a licensed broker and qualified counsel before binding.
