SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. This page explains vocabulary; it is not legal advice, not insurance advice, and not a coverage determination, no attorney-client relationship arises from reading it, and the answer in any real matter turns on your own policy wording and the law of your state.
Definition
Cancellation ends a policy going forward. Rescission goes further and treats it as void from inception, unwound as though it had never been issued. The carrier generally returns the premium. Everything the policy would have covered disappears with it, which is why rescission is the most severe outcome available in an application dispute and the reason it is pursued relatively rarely.
In cyber the ground is almost always a material misrepresentation on the application. The carrier argues that it would not have issued the policy, or would not have issued it on those terms, had the answer been accurate.
How it works in a cyber policy
A carrier seeking rescission is generally required to show three things, and the details vary by state.
The statement was inaccurate. This is the easiest element on a cyber form, because control state is enumerable after the fact from logs and configuration.
The statement was material, meaning it would have changed the underwriting decision. Carriers evidence this with their own underwriting guidelines and with the referral rules that route a submission differently when an answer flips. A control that is a condition of quoting in the market, such as MFA on remote access, carries a strong materiality argument almost automatically.
The carrier relied on it. The incorporation clause on the application, which the signer attests to, is what supplies this element in most cyber policies.
Several states then add their own gloss. Some require the misstatement to have been knowing or fraudulent before a policy can be rescinded; some restrict the remedy where the carrier had the means to discover the truth and did not look. There is no contestability period here: that is a life and health concept and US commercial cyber forms do not carry one. The nearest equivalents are negotiated rather than statutory, in the form of a severability of application clause, which confines the consequences of an inaccurate answer to the person who knew it was inaccurate rather than imputing it to every insured, or a non-rescindable endorsement, which removes the remedy altogether. Both are worth asking a broker about; neither appears by default. This is why a general statement about what happens is worth less than a specific one about your own wording and governing law.
What these two disputes actually show
Two US disputes are cited constantly in this area, and both are cited more confidently than the record supports. It is worth being precise about what each one actually decided, because the difference changes how much weight the answer on your form carries.
Columbia Casualty Co. v. Cottage Health System. Columbia Casualty, a CNA unit, had issued a NetProtect360 policy to a Southern California hospital group that, according to the complaint and contemporaneous reporting, experienced a 2013 exposure of roughly 32,500 patient records. After funding a $4.125 million class settlement, Columbia sued to recover what it said it had spent. Its theory rested on the application. Columbia's complaint alleged that the policy incorporated a Risk Control Self Assessment in which Cottage had answered yes to a series of security questions, and that those answers were false. Cottage did not concede the allegations, and the court never ruled on them. According to Columbia's complaint, the policy also carried a Minimum Required Practices exclusion barring loss arising out of "[a]ny failure of an Insured to continuously implement the procedures and risk controls identified in the Insured's application."
The court never reached whether the answers were false. On 17 July 2015 it dismissed the case without prejudice because the policy required the parties to work through an alternative dispute resolution clause, non-binding mediation or arbitration, before either could sue, and Columbia had not. That requirement was itself a condition precedent, and the carrier's own suit was dismissed on one, without prejudice. Columbia refiled in May 2016; that action did not produce a published merits ruling on the application answers either.
Travelers Property Casualty Co. of America v. International Control Services, Inc.. Travelers alleged that the insured, an Illinois electronics manufacturer, had suffered a ransomware incident on a server that was not protected by multi-factor authentication. Those allegations were never tested; the case ended by stipulation before any finding of fact. Travelers alleged that the submission, which included a signed standalone MFA self-attestation of the kind now standard in the market, had represented enterprise-wide MFA when in practice MFA protected only the firewall, and it sought rescission on the ground that the misstatement materially affected its acceptance of the risk. In August 2022 the parties stipulated to judgment: the policy was declared null and void from its inception, no coverage was available to anyone under it, and the case ended.
That outcome is often described as a court holding that a wrong MFA answer voids a policy. It is not. It is a policyholder agreeing not to contest rescission. What the record does show is that a carrier was willing to spend litigation money to unwind a policy over one application answer, and that the policyholder chose to stipulate rather than litigate. The stipulation records no reason, and no admission should be inferred from it.
Neither case is precedent that an inaccurate answer voids cyber coverage. Both are evidence that carriers treat application answers as the lever they reach for first when a loss lands on a control the form said was in place. Whether a rescission or denial succeeds turns on materiality, the exact policy wording, and the law of the governing state, which varies considerably. Anyone facing this in a live matter needs coverage counsel, not a web page.
SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. This page explains vocabulary; it is not legal advice, not insurance advice, and not a coverage determination, no attorney-client relationship arises from reading it, and the answer in any real matter turns on your own policy wording and the law of your state. Statements on this page about what a party did, knew, or intended are allegations drawn from court filings and contemporaneous reporting, not findings of fact; neither matter was decided on the merits. If a live application, renewal, or claim depends on any of this, take advice from a licensed broker and qualified coverage counsel. Last reviewed 2026-08-24.
What this means for the answer you are about to sign
The asymmetry is what makes rescission worth managing rather than worrying about. A carrier does not need to prove your entire security programme was misdescribed. It needs one material answer that the incident report contradicts. Meanwhile, the answer that would have avoided the whole argument was usually available to you for free at signing time, from a system you already own.
The practical hedge is a dated record. If you can show that on the day you signed, a dated reading of the environment matched the coverage you claimed, you are no longer arguing about memory. You are arguing from evidence, and a carrier that wants to rescind now has to dispute a measurement rather than an assertion. This is also why a measurement taken once at renewal is weaker than a continuous one: policies increasingly carry ongoing conditions, and control drift between renewals is invisible until somebody looks.
Where the evidence for that answer lives
The answers that most often become rescission arguments are the ones a live read settles cleanly: multi-factor coverage across email, remote access, and privileged accounts; backup immutability and restore testing; endpoint detection coverage; and the claims and circumstances questions, where accuracy is a matter of disclosure rather than configuration.
Frequently asked
What is rescission in cyber insurance?
Rescission is an insurer's remedy that treats the policy as void from inception rather than cancelled going forward, usually sought on the ground that a material misstatement appeared on the application. The premium is generally returned and coverage disappears for all claims under the policy, not only the one in dispute. Whether a rescission succeeds depends on materiality, the policy wording, and the law of the governing state.
How is rescission different from a claim denial?
A denial refuses one claim and leaves the policy standing for everything else. Rescission removes the policy itself, retroactively, so other claims under it fall away too. Carriers sometimes plead both, seeking rescission and arguing in the alternative that the claim is not covered.
Has a US court ever rescinded a cyber policy over an MFA answer?
A federal court in the Central District of Illinois entered judgment rescinding a cyber policy in the Travelers v. International Control Services matter in August 2022, but by stipulation of the parties rather than after a contested ruling. The policyholder agreed to the rescission. That is meaningfully different from a court deciding the question on the merits.
Is the premium returned?
Rescission generally involves returning the premium, since the remedy treats the contract as never having existed. Returned premium is a small figure set against an uncovered ransomware loss.
Can rescission reach a claim the carrier already paid?
That is exactly what a carrier pursuing reimbursement is trying to do. In the Cottage Health matter the insurer sued to recover the $4.125 million it said it had spent settling the underlying class action. The court dismissed that suit on a procedural ground without deciding whether the recovery was available.
Sources
Every statement about a court case on this page is drawn from the documents and reporting below. Links open on the publisher's own site.
- Columbia Casualty Co. v. Cottage Health System, complaint filed 7 May 2015 (copy via Internet Archive; docket available on PACER and CourtListener) Internet Archive
- Cyber insurer seeks to void data breach coverage because of purported misstatements in policy application (16 June 2016) Covington, Inside Privacy
- Travelers, policyholder agree to void current cyber policy (30 August 2022) Insurance Journal
- Travelers v. ICS underscores need to respond carefully to cyber insurance application questions (15 September 2022) Lockton
Full captions: Columbia Casualty Co. v. Cottage Health System, No. 2:15-cv-03432-DDP-AGR (C.D. Cal., filed 7 May 2015, dismissed without prejudice 17 July 2015), refiled as No. 2:16-cv-03759 (C.D. Cal.); Travelers Property Casualty Co. of America v. International Control Services, Inc., No. 2:22-cv-02145 (C.D. Ill., stipulated judgment August 2022). Dockets are available on PACER and CourtListener.
Sources are cited only for the facts attributed to them. The publishers listed are unaffiliated with Insurance Posture and SecValley, have not reviewed or endorsed this page, and their inclusion implies no relationship.
Related terms
Answer from the environment, not from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer, so the answers on the form match a dated reading of the environment before anyone signs.
Assess your posture