---
title: "Rescission: when a cyber policy is treated as never issued"
url: https://insuranceposture.com/glossary/rescission
category: "Glossary, consequence terms"
term: "Rescission"
updated: 2026-08-24
---

# Rescission: when a cyber policy is treated as never issued

URL: https://insuranceposture.com/glossary/rescission
Section: Glossary, consequence terms
Term: Rescission

A claim denial takes away one claim. Rescission takes away the policy, retroactively, including the claims it already paid.

SecValley research team. Reviewed 2026-08-24.

SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. This page explains vocabulary; it is not legal advice, not insurance advice, and not a coverage determination, no attorney-client relationship arises from reading it, and the answer in any real matter turns on your own policy wording and the law of your state.

## Definition

Rescission is an insurer's remedy that unwinds a policy as though it had never been issued, typically sought on the ground that a material misstatement appeared on the application. Premium is generally returned; coverage disappears for every claim, not just the one in dispute.

Cancellation ends a policy going forward. Rescission goes further and treats it as void from inception, unwound as though it had never been issued. The carrier generally returns the premium. Everything the policy would have covered disappears with it, which is why rescission is the most severe outcome available in an application dispute and the reason it is pursued relatively rarely.

In cyber the ground is almost always a material [misrepresentation](/glossary/misrepresentation) on the application. The carrier argues that it would not have issued the policy, or would not have issued it on those terms, had the answer been accurate.

## How it works in a cyber policy

A carrier seeking rescission is generally required to show three things, and the details vary by state.

The statement was inaccurate. This is the easiest element on a cyber form, because control state is enumerable after the fact from logs and configuration.

The statement was material, meaning it would have changed the underwriting decision. Carriers evidence this with their own underwriting guidelines and with the referral rules that route a submission differently when an answer flips. A control that is a condition of quoting in the market, such as MFA on remote access, carries a strong materiality argument almost automatically.

The carrier relied on it. The incorporation clause on the application, which the signer attests to, is what supplies this element in most cyber policies.

Several states then add their own gloss. Some require the misstatement to have been knowing or fraudulent before a policy can be rescinded; some restrict the remedy where the carrier had the means to discover the truth and did not look. There is no contestability period here: that is a life and health concept and US commercial cyber forms do not carry one. The nearest equivalents are negotiated rather than statutory, in the form of a severability of application clause, which confines the consequences of an inaccurate answer to the person who knew it was inaccurate rather than imputing it to every insured, or a non-rescindable endorsement, which removes the remedy altogether. Both are worth asking a broker about; neither appears by default. This is why a general statement about what happens is worth less than a specific one about your own wording and governing law.

## What these two disputes actually show

Two US disputes are cited constantly in this area, and both are cited more confidently than the record supports. It is worth being precise about what each one actually decided, because the difference changes how much weight the answer on your form carries.

**Columbia Casualty Co. v. Cottage Health System.** Columbia Casualty, a CNA unit, had issued a NetProtect360 policy to a Southern California hospital group that, according to the complaint and contemporaneous reporting, experienced a 2013 exposure of roughly 32,500 patient records. After funding a $4.125 million class settlement, Columbia sued to recover what it said it had spent. Its theory rested on the application. Columbia's complaint alleged that the policy incorporated a Risk Control Self Assessment in which Cottage had answered yes to a series of security questions, and that those answers were false. Cottage did not concede the allegations, and the court never ruled on them. According to Columbia's complaint, the policy also carried a Minimum Required Practices exclusion barring loss arising out of "[a]ny failure of an Insured to continuously implement the procedures and risk controls identified in the Insured's application."

The court never reached whether the answers were false. On 17 July 2015 it dismissed the case without prejudice because the policy required the parties to work through an alternative dispute resolution clause, non-binding mediation or arbitration, before either could sue, and Columbia had not. That requirement was itself a condition precedent, and the carrier's own suit was dismissed on one, without prejudice. Columbia refiled in May 2016; that action did not produce a published merits ruling on the application answers either.

**Travelers Property Casualty Co. of America v. International Control Services, Inc..** Travelers alleged that the insured, an Illinois electronics manufacturer, had suffered a ransomware incident on a server that was not protected by multi-factor authentication. Those allegations were never tested; the case ended by stipulation before any finding of fact. Travelers alleged that the submission, which included a signed standalone MFA self-attestation of the kind now standard in the market, had represented enterprise-wide MFA when in practice MFA protected only the firewall, and it sought rescission on the ground that the misstatement materially affected its acceptance of the risk. In August 2022 the parties stipulated to judgment: the policy was declared null and void from its inception, no coverage was available to anyone under it, and the case ended.

That outcome is often described as a court holding that a wrong MFA answer voids a policy. It is not. It is a policyholder agreeing not to contest rescission. What the record does show is that a carrier was willing to spend litigation money to unwind a policy over one application answer, and that the policyholder chose to stipulate rather than litigate. The stipulation records no reason, and no admission should be inferred from it.

**What this pair does and does not establish**

Neither case is precedent that an inaccurate answer voids cyber coverage. Both are evidence that carriers treat application answers as the lever they reach for first when a loss lands on a control the form said was in place. Whether a rescission or denial succeeds turns on materiality, the exact policy wording, and the law of the governing state, which varies considerably. Anyone facing this in a live matter needs coverage counsel, not a web page.

## Not legal advice

SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. This page explains vocabulary; it is not legal advice, not insurance advice, and not a coverage determination, no attorney-client relationship arises from reading it, and the answer in any real matter turns on your own policy wording and the law of your state. Statements on this page about what a party did, knew, or intended are allegations drawn from court filings and contemporaneous reporting, not findings of fact; neither matter was decided on the merits. If a live application, renewal, or claim depends on any of this, take advice from a licensed broker and qualified coverage counsel. Last reviewed 2026-08-24.

## What this means for the answer you are about to sign

The asymmetry is what makes rescission worth managing rather than worrying about. A carrier does not need to prove your entire security programme was misdescribed. It needs one material answer that the incident report contradicts. Meanwhile, the answer that would have avoided the whole argument was usually available to you for free at signing time, from a system you already own.

The practical hedge is a dated record. If you can show that on the day you signed, a dated reading of the environment matched the coverage you claimed, you are no longer arguing about memory. You are arguing from evidence, and a carrier that wants to rescind now has to dispute a measurement rather than an assertion. This is also why a measurement taken once at renewal is weaker than a continuous one: [policies increasingly carry ongoing conditions](/glossary/condition-precedent), and control drift between renewals is invisible until somebody looks.

## Where the evidence for that answer lives

The answers that most often become rescission arguments are the ones a live read settles cleanly: multi-factor coverage across email, remote access, and privileged accounts; backup immutability and restore testing; endpoint detection coverage; and the claims and circumstances questions, where accuracy is a matter of disclosure rather than configuration.

## Related questions

- [Is multi-factor authentication enforced on all email access?](https://insuranceposture.com/questions/multi-factor-authentication/multi-factor-authentication-enforced-email-access)
- [Is MFA enforced on all privileged / administrative user accounts?](https://insuranceposture.com/questions/multi-factor-authentication/mfa-enforced-privileged-administrative-user-accounts)
- [Are backups kept offline (disconnected) or immutable / air-gapped?](https://insuranceposture.com/questions/backup-and-recovery/backups-kept-offline-immutable-air-gapped)
- [Awareness of any fact / circumstance reasonably giving rise to a future claim?](https://insuranceposture.com/questions/incident-response/awareness-fact-circumstance-reasonably-giving-rise-future-claim)

## Frequently asked

### What is rescission in cyber insurance?

Rescission is an insurer's remedy that treats the policy as void from inception rather than cancelled going forward, usually sought on the ground that a material misstatement appeared on the application. The premium is generally returned and coverage disappears for all claims under the policy, not only the one in dispute. Whether a rescission succeeds depends on materiality, the policy wording, and the law of the governing state.

### How is rescission different from a claim denial?

A denial refuses one claim and leaves the policy standing for everything else. Rescission removes the policy itself, retroactively, so other claims under it fall away too. Carriers sometimes plead both, seeking rescission and arguing in the alternative that the claim is not covered.

### Has a US court ever rescinded a cyber policy over an MFA answer?

A federal court in the Central District of Illinois entered judgment rescinding a cyber policy in the Travelers v. International Control Services matter in August 2022, but by stipulation of the parties rather than after a contested ruling. The policyholder agreed to the rescission. That is meaningfully different from a court deciding the question on the merits.

### Is the premium returned?

Rescission generally involves returning the premium, since the remedy treats the contract as never having existed. Returned premium is a small figure set against an uncovered ransomware loss.

### Can rescission reach a claim the carrier already paid?

That is exactly what a carrier pursuing reimbursement is trying to do. In the Cottage Health matter the insurer sued to recover the $4.125 million it said it had spent settling the underlying class action. The court dismissed that suit on a procedural ground without deciding whether the recovery was available.

## Sources

- Internet Archive: [Columbia Casualty Co. v. Cottage Health System, complaint filed 7 May 2015 (copy via Internet Archive; docket available on PACER and CourtListener)](https://archive.org/details/031121143231)
- Covington, Inside Privacy: [Cyber insurer seeks to void data breach coverage because of purported misstatements in policy application (16 June 2016)](https://www.insideprivacy.com/data-security/cybersecurity/cyber-insurer-seeks-to-void-data-breach-coverage-because-of-purported-misstatements-in-policy-application/)
- Insurance Journal: [Travelers, policyholder agree to void current cyber policy (30 August 2022)](https://www.insurancejournal.com/news/national/2022/08/30/682564.htm)
- Lockton: [Travelers v. ICS underscores need to respond carefully to cyber insurance application questions (15 September 2022)](https://global.lockton.com/us/en/news-insights/travelers-v-ics-underscores-need-to-respond-carefully-to-cyber-insurance)

Full captions: Columbia Casualty Co. v. Cottage Health System, No. 2:15-cv-03432-DDP-AGR (C.D. Cal., filed 7 May 2015, dismissed without prejudice 17 July 2015), refiled as No. 2:16-cv-03759 (C.D. Cal.); Travelers Property Casualty Co. of America v. International Control Services, Inc., No. 2:22-cv-02145 (C.D. Ill., stipulated judgment August 2022). Dockets are available on PACER and CourtListener.

Sources are cited only for the facts attributed to them. The publishers listed are unaffiliated with Insurance Posture and SecValley, have not reviewed or endorsed this page, and their inclusion implies no relationship.

## Related terms

- [Misrepresentation](https://insuranceposture.com/glossary/misrepresentation)
- [Materiality](https://insuranceposture.com/glossary/materiality)
- [Claim denial](https://insuranceposture.com/glossary/claim-denial)
- [Condition precedent](https://insuranceposture.com/glossary/condition-precedent)

---

Insurance Posture by SecValley. https://insuranceposture.com
The question library is written in our own wording to reflect the control topics that recur across US cyber application and ransomware supplemental forms. No carrier form is republished.
SecValley is not a law firm, an insurance broker, an agent, or a carrier, and holds no producer licence. Nothing here is insurance advice, legal advice, or a coverage determination, and no attorney-client relationship arises from reading it. Statements about what a party to a cited case did, knew, or intended are allegations drawn from court filings and contemporaneous reporting, not findings of fact.
Your organization's authorized signer remains responsible for the accuracy of any application. Consult a licensed broker and qualified counsel before binding.
