Incident response and claims history

In last 3 years, any cyber event, claim, loss, security breach, or extortion demand?

Of every question on the form, this is the one where an inaccurate answer does the most damage. Prior incidents are discoverable; a non-disclosure is not survivable.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking about any cyber event, claim, loss, security breach, or extortion demand in the stated period. The wording is deliberately broad. It captures events that produced no claim, no notification, and no material loss, including an extortion demand you ignored and a compromise you contained yourself.

Why it is underwritten

Loss history is the strongest single predictor of future loss, so this answer carries real weight in pricing. It carries more weight legally: an inaccurate answer to a claims history question is the clearest case a carrier can make for rescission, because materiality is difficult to dispute. Every carrier in this market has rescinded a policy on this ground.

Where the answer lives in Microsoft 365, Entra ID, and Azure

This is a disclosure question answered from records rather than from configuration. The work is establishing what actually happened, which usually requires asking beyond the IT team.

PlatformWhere the setting livesWhat has to be true
Incident recordsTicketing, security tooling, and incident logs for the periodA search rather than a recollection, since events three years old are rarely remembered accurately
Insurance recordsPrior claims, notifications, and circumstance notificationsAnything reported to any carrier, including notifications that produced no claim
Legal recordsRegulatory notifications, correspondence, and demand lettersAny regulator contact or third-party demand relating to data or systems
Finance recordsPayments made in response to fraud, including recovered fundsInvoice fraud and payment diversion, which are often handled by finance and never reach IT
CommunicationExtortion demands, including those not acted onDemands received and ignored still count, and they are frequently omitted because nothing happened
Ask finance, not only IT

The most commonly omitted event is a payment diverted by invoice fraud, resolved by the bank or absorbed as a loss, that the security team never heard about. It is squarely within the question, and the record exists in the finance system. Ask the question there before you answer.

What a defensible yes requires

  • The answer is based on a documented search across IT, legal, finance, and insurance records.
  • Contained incidents are included, not only those that produced a claim or a notification.
  • Extortion demands are disclosed even where nothing was paid and nothing happened.
  • Disclosed events include what happened, what was done, and what changed as a result.
  • The search covers the full period and any acquired entities.

How this answer goes wrong

The answer is no because nothing was reported to an insurer, while the organisation contained a mailbox compromise eighteen months ago and finance recovered a diverted payment the year before. Both are within the question. The carrier will discover them during the investigation of any subsequent claim, and the discovery will be characterised as non-disclosure.

Frequently asked

Does a contained incident count?

Read the wording. Most forms ask about events, not claims, which captures anything you would internally call a security incident regardless of outcome.

Will disclosing hurt us?

Less than you expect, and far less than non-disclosure. A disclosed event with a clear remediation story is routine. Carriers are more concerned by an insured who does not know what happened to them.

What about incidents at an acquired company?

They generally count once acquired. Include them and note the acquisition date, because the alternative is a gap discovered later.

What if we are not sure?

Disclose and describe. Carriers accept qualified disclosure; they do not accept an unqualified no that turns out to be wrong.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture