Underwriting attestation gap

Your Insurer Can Already Check Whether You'd Pass. Can You?

The fastest way to lose a claim you've already paid premiums for isn't the breach — it's the gap between what you attested to and what a five-minute external check turns up. Business email compromise alone drives 58% of the claims insurers pay out on, and email authentication is one of the only things about your security posture they can verify without asking you a single question. Run the same check yourself, free, before they do.

Run your free scan →
~75%of cyber carriers now run an external scan before underwriting or renewal (Corvus, 2026)
25–40%of claims get reduced, disputed, or denied over an attestation mismatch (industry estimates, 2025–26)

Many carriers run a second scan after a claim is filed, comparing it against what was originally attested. This isn't hypothetical:

"An insurer rescinded a policy and denied a ransomware claim after finding that MFA, attested to as fully deployed, was missing from a single server unrelated to how the breach occurred."

That's the widely-reported Travelers v. ICS case. A separate case involving an $18.3 million loss ended the same way: a $5 million claim denied over incomplete MFA coverage. In both, the gap that mattered wasn't the size of the breach — it was the size of the mismatch between the application and reality.

Some insurers — Coalition, At-Bay, and a few others — give their own policyholders a continuous-monitoring tool built for exactly this problem. It's a real product and it works. But it only exists if you're already their customer, it's owned by the same party that decides whether to pay your claim, and if you're with one of the traditional carriers most small healthcare practices actually use, you don't have access to anything like it.

You're already paying for coverage based on an attestation. The only question that matters is whether that attestation would still hold up if your insurer, or their forensic team, checked it today. Here's what they'd actually be checking.

The Nine Categories Insurers Check

Two of these you can verify externally, right now, free, in under two minutes. The other seven require documentation your insurer will ask for directly — no scan, ours or anyone else's, can see them from outside your network. Here's the honest split.

Verified by this free scan, today
01

External attack surface

Open ports, exposed admin panels, invalid or self-signed certificates, cleartext credentials, unpatched public-facing services.

Verified via external scan of the domain and IP range · fails on any exposed service with a known vulnerability or default credential

05

Email authentication

SPF, DKIM, and DMARC configured and enforced, not just present in “monitor” mode.

Verified via external DNS record check · fails on DMARC policy set to p=none, or missing SPF/DKIM entirely

Also checked by your insurer — requires documentation, not covered by this scan
02

MFA evidence

Whether MFA is enforced on email, VPN, and remote access — not just present somewhere.

Verified via login-flow testing or configuration evidence, not a checkbox · fails on MFA “available” but not enforced org-wide

03

EDR/MDR coverage

Whether endpoint detection is active and monitored 24/7, not just installed.

Verified via vendor attestation or agent-presence check · fails on EDR installed but unmonitored, or partial deployment

04

Backup integrity

Whether backups are immutable and restore-tested, not just scheduled.

Verified via restore-test logs or immutability configuration · fails on backups that have never been test-restored, or are reachable from the primary network

06

Patch SLA

Time-to-patch for critical vulnerabilities.

Verified via vulnerability scan history · fails on known CVEs unpatched past a defined window

07

Incident response plan

Whether a tested IR plan exists, with a named point of contact.

Verified via documentation request, sometimes a tabletop exercise summary · fails on no plan, or a plan that's never been exercised

08

Security awareness training

Completion rates for staff training, particularly phishing simulation.

Verified via training platform records · fails on no program, or low completion rates

09

Vendor/third-party risk

Whether business associates and vendors with system access are assessed.

Verified via vendor risk questionnaire or attestation · fails on no vendor inventory, no assessment process

Why This Matters Right Now

The mismatch between what's attested and what a scan actually finds is the single most common thread in cyber insurance claim disputes right now — not the breach itself, but whether the controls described on the application were still in place when it happened.

96 dental practices, scanned externally. 50% had a critical-severity finding — the kind an insurer's own scan would catch in seconds. 96% had no DMARC configured, the single control tied to the majority of claims insurers actually pay out on. Fixing it costs nothing. Not fixing it can cost everything, if a claim ever gets picked apart the way the case above was.

Full dataset page →

Why a One-Time Check Isn't Enough

You don't get to choose when this actually gets tested. It might happen at your next renewal — a growing number of carriers now re-scan mid-policy-term, not just at renewal. It might happen after an incident, the worst possible time to discover the gap, and the one time it matters most.

A scan tells you whether you'd pass today. It says nothing about three months from now, after a new hire reuses a password, a certificate quietly expires, a vendor's access is never revoked, or an EDR agent silently stops reporting. The only way to know you'd pass whenever the question actually gets asked, on a timeline you don't control, is to already be checking continuously, not just once.

Check Your Own Practice, Independently

Run the same categories of check we just described against your own domain, free, in under two minutes, without going through the insurer whose decision depends on the answer.

Run your free scan →

Frequently Asked Questions

Does my current MSP already cover this?

Most MSP contracts cover break-fix and day-to-day IT support, not ongoing verification against what an insurer specifically checks. An MSP can install MFA; it usually doesn't monitor whether that MFA stays enforced on every account, every day, or re-check after a new hire, a config change, or a vendor integration. The scan on this page checks the categories an insurer can verify from outside your network — attack surface and email authentication — independent of what your MSP is doing internally. It won't tell you whether your MSP's MFA or backup claims hold up; that still requires the documentation review your insurer will also ask for.

How often do insurers actually re-check this?

At minimum, at every renewal. A growing number of carriers also run a scan mid-policy-term, and virtually all of them re-verify after a claim is filed, comparing what they find to what was originally attested. There's no fixed schedule you can plan around, which is exactly why a single point-in-time check only answers the question for the day you ran it.

What happens if I fail one of the nine categories?

Failing one category doesn't automatically void coverage, but it does create a gap between what you've attested to and what's actually true. If that gap exists at underwriting, it can affect your quote. If it exists at the time of a claim, insurers have used gaps this narrow, a single admin account without MFA, for example, as grounds to reduce or deny a claim entirely, even when that account had nothing to do with the incident.

Methodology: All checks referenced on this page are passive and external: DNS records, TLS configuration, HTTP response headers, and public breach-exposure data. No authentication was attempted against any system, and no practice's internal network was accessed. This is the same category of external observation insurers themselves use before a renewal decision.

Last updated: July 22, 2026