Underwriting attestation gap
Your Insurer Can Already Check Whether You'd Pass. Can You?
The fastest way to lose a claim you've already paid premiums for isn't the breach — it's the gap between what you attested to and what a five-minute external check turns up. Business email compromise alone drives 58% of the claims insurers pay out on, and email authentication is one of the only things about your security posture they can verify without asking you a single question. Run the same check yourself, free, before they do.
Run your free scan →Many carriers run a second scan after a claim is filed, comparing it against what was originally attested. This isn't hypothetical:
"An insurer rescinded a policy and denied a ransomware claim after finding that MFA, attested to as fully deployed, was missing from a single server unrelated to how the breach occurred."
That's the widely-reported Travelers v. ICS case. A separate case involving an $18.3 million loss ended the same way: a $5 million claim denied over incomplete MFA coverage. In both, the gap that mattered wasn't the size of the breach — it was the size of the mismatch between the application and reality.
Some insurers — Coalition, At-Bay, and a few others — give their own policyholders a continuous-monitoring tool built for exactly this problem. It's a real product and it works. But it only exists if you're already their customer, it's owned by the same party that decides whether to pay your claim, and if you're with one of the traditional carriers most small healthcare practices actually use, you don't have access to anything like it.
You're already paying for coverage based on an attestation. The only question that matters is whether that attestation would still hold up if your insurer, or their forensic team, checked it today. Here's what they'd actually be checking.
The Nine Categories Insurers Check
Two of these you can verify externally, right now, free, in under two minutes. The other seven require documentation your insurer will ask for directly — no scan, ours or anyone else's, can see them from outside your network. Here's the honest split.
Verified by this free scan, todayExternal attack surface
Open ports, exposed admin panels, invalid or self-signed certificates, cleartext credentials, unpatched public-facing services.
Email authentication
SPF, DKIM, and DMARC configured and enforced, not just present in “monitor” mode.
MFA evidence
Whether MFA is enforced on email, VPN, and remote access — not just present somewhere.
EDR/MDR coverage
Whether endpoint detection is active and monitored 24/7, not just installed.
Backup integrity
Whether backups are immutable and restore-tested, not just scheduled.
Patch SLA
Time-to-patch for critical vulnerabilities.
Incident response plan
Whether a tested IR plan exists, with a named point of contact.
Security awareness training
Completion rates for staff training, particularly phishing simulation.
Vendor/third-party risk
Whether business associates and vendors with system access are assessed.
Why This Matters Right Now
The mismatch between what's attested and what a scan actually finds is the single most common thread in cyber insurance claim disputes right now — not the breach itself, but whether the controls described on the application were still in place when it happened.
96 dental practices, scanned externally. 50% had a critical-severity finding — the kind an insurer's own scan would catch in seconds. 96% had no DMARC configured, the single control tied to the majority of claims insurers actually pay out on. Fixing it costs nothing. Not fixing it can cost everything, if a claim ever gets picked apart the way the case above was.
Full dataset page →Why a One-Time Check Isn't Enough
You don't get to choose when this actually gets tested. It might happen at your next renewal — a growing number of carriers now re-scan mid-policy-term, not just at renewal. It might happen after an incident, the worst possible time to discover the gap, and the one time it matters most.
A scan tells you whether you'd pass today. It says nothing about three months from now, after a new hire reuses a password, a certificate quietly expires, a vendor's access is never revoked, or an EDR agent silently stops reporting. The only way to know you'd pass whenever the question actually gets asked, on a timeline you don't control, is to already be checking continuously, not just once.
Check Your Own Practice, Independently
Run the same categories of check we just described against your own domain, free, in under two minutes, without going through the insurer whose decision depends on the answer.
Run your free scan →Frequently Asked Questions
Does my current MSP already cover this?
Most MSP contracts cover break-fix and day-to-day IT support, not ongoing verification against what an insurer specifically checks. An MSP can install MFA; it usually doesn't monitor whether that MFA stays enforced on every account, every day, or re-check after a new hire, a config change, or a vendor integration. The scan on this page checks the categories an insurer can verify from outside your network — attack surface and email authentication — independent of what your MSP is doing internally. It won't tell you whether your MSP's MFA or backup claims hold up; that still requires the documentation review your insurer will also ask for.
How often do insurers actually re-check this?
At minimum, at every renewal. A growing number of carriers also run a scan mid-policy-term, and virtually all of them re-verify after a claim is filed, comparing what they find to what was originally attested. There's no fixed schedule you can plan around, which is exactly why a single point-in-time check only answers the question for the day you ran it.
What happens if I fail one of the nine categories?
Failing one category doesn't automatically void coverage, but it does create a gap between what you've attested to and what's actually true. If that gap exists at underwriting, it can affect your quote. If it exists at the time of a claim, insurers have used gaps this narrow, a single admin account without MFA, for example, as grounds to reduce or deny a claim entirely, even when that account had nothing to do with the incident.
Methodology: All checks referenced on this page are passive and external: DNS records, TLS configuration, HTTP response headers, and public breach-exposure data. No authentication was attempted against any system, and no practice's internal network was accessed. This is the same category of external observation insurers themselves use before a renewal decision.
Last updated: July 22, 2026