30.07.2026

4 Min. read

The policy is in the drawer, MFA only on some access points. When the insurer reviews and denies a claim, what felt like risk transfer becomes a governance failure by the executive board-not the IT department.

Key Takeaways

  • Claim denials are a board-level issue. Around 37 percent of cyber claims fail. In 2024, missing MFA was a contributing factor in 82 percent of denials.
  • Policies demand architecture. By 2026, insurers will require MFA, EDR, tested backups, and documented incident response across the board-sometimes, “partial” won’t cut it.
  • NIS-2 shifts liability upward. Since December 2025, executives face personal liability. Tolerating a false sense of security risks operational damage, policy voids, and fines.

RelatedCyber Insurance: Managing Risks and Avoiding Losses / NIS-2 Executive Liability Applies Despite Registration

A mid-sized company with around 200 employees had cyber insurance for years. Then ransomware struck: systems encrypted, operations halted. The damage landed with the insurer-and was denied. The application questionnaire had promised company-wide multi-factor authentication. In reality, MFA was only active on some access points. For the insurer, that gap was enough.

This pattern keeps surfacing in incident response cases. It’s rarely malicious intent. It’s the gap between what an organization *thinks* it has and what it can actually prove.

A Cyber Policy Is No Shield

Many leadership teams read their cyber policy as a safety net and breathe a sigh of relief. Understandable-but risky. A cyber insurance policy doesn’t stop an attack. It’s financial risk transfer for when preventive and detective measures fail. It only pays out if all the fine-print obligations were met at the time of the attack. Signing the contract alone doesn’t count.

If you have a policy but no security architecture that lives up to it, you’ve created a false sense of security. This isn’t an IT tweak. It’s a leadership decision about risk transparency.

Claims denied
~37 %
Share of cyber claims denied-trend rising.
MFA as a contributing factor
82 %
of denials linked to missing MFA (Coalition 2024).
MFA requirement
~95 %
of insurers demand full MFA, not partial.
EDR prerequisite
89 %
require Endpoint Detection and Response on all devices.

What Insurers Will Demand in 2026

After years of ransomware waves, the short questionnaire has turned into a technical audit. Full MFA on email, VPN, remote access, cloud platforms, and admin accounts. Endpoint Detection and Response across the entire device fleet. Backups that work and are tested for recovery in an emergency. Consistent patch management. A documented incident response plan.

Fail to meet these, and in 2026 you’ll either get no policy at all-or one that won’t pay out when it counts. If you promise more in the questionnaire than you deliver in operations, you risk claim denial and, in some cases, complete loss of coverage. The Higher Regional Court of Schleswig confirmed this in a ruling in January 2025.

Many companies don’t have a pure security problem. They have a governance problem: the gap between promised and practiced controls rarely makes it into board papers.

A false sense of security is a leadership failure

Investments in tools, policies, and service providers create a clean picture on paper. In practice, three answers at C-level are often missing:

  • How high is MFA coverage really – as a measurable figure, not as a project status?
  • When was the last backup successfully restored – not merely written?
  • Who owns the full overview of protected vs. unprotected systems?

These questions too often get stuck in IT. NIS-2 pulls them upward: Since December 6, 2025, the NIS-2 Implementation Act has been in force. Around 29,500 companies in 18 sectors are affected. Senior management is personally liable – fines of up to 10 million Euro or 2 percent of worldwide annual revenue. Cybersecurity is a capital and liability decision. A purely technical to-do list falls short.

Three control questions for senior management

Three review steps separate a false sense of security from reliable risk transfer:

  1. Read the policy, not just the cover sheet. Which obligations were promised – and can they be evidenced today?
  2. Measure the real status. MFA coverage in percent, date of the last successful restore, EDR coverage, patch lag on critical systems.
  3. Close the gap or openly declare the risk. A policy that does not pay in the event of a claim is not a transfer. It is burned budget with a false feeling of security.

Background

Deeper dive on false security in the midmarket: We are putting an end to false security (enthus). The guest commentary by Wolfgang Hahl (CRO, enthus) appears in parallel on MyBusinessFuture.

Frequently Asked Questions

When does cyber insurance not cover a ransomware attack?

If agreed security measures weren’t fully implemented at the time of the attack-such as MFA only being active on some access points. The denial then stems from policy obligations, not the damage itself.

What security controls will insurers demand in 2026?

Full MFA on critical access points, EDR on all endpoints, tested backups, patch management, and a documented incident response plan. Partial coverage counts as a gap.

Why should this be on the executive board’s agenda?

Because NIS2 introduces personal liability, and a policy denial combined with operational downtime plus fines becomes a capital risk-not something to leave buried in IT tickets.

What’s the first measurable step?

Compare your policy’s obligations against your actual control status: MFA adoption rate, last restore test date, EDR coverage. The gap is your governance mandate.

Image source: AI-generated (July 2026)

Share this article:

Also available in

More Articles

09.09.2026

Nvidia Buys Hugging Face for Over 11 Billion Euros

Eva Mickler

4 min read Nvidia is acquiring Hugging Face for around 11.1 billion euros; the contract was signed on ...

Read Article
08.09.2026

SAP Lets Joule Steer Robots Directly, Liability Still Open

Bernhard Liebl

4 min read SAP has documented the first Embodied AI Jam at the Swiss Smart Factory in Biel. Inspection ...

Read Article
15.08.2026

ChatGPT wants to read the Mac

Eva Mickler

6 min read On 13 August 2026, OpenAI described Computer History for the ChatGPT Mac app in its release ...

Read Article
14.08.2026

SpaceX acquires Cursor: EU clauses stay open

Eva Mickler

5 min read The purchase agreement was finalized on 14 August 2026. Any company using the tool now has ...

Read Article
13.08.2026

CRA forces manufacturers to report within 24 hours

Bernhard Liebl

9 min read On 11 September 2026, Article 14 of the Cyber Resilience Act comes into force. From that ...

Read Article
11.08.2026

NVIDIA capital plans and what operators must check now

Bernhard Liebl

7 min read On 10 August 2026, NVIDIA announced it will partner with six capital partners to build financing ...

Read Article
A magazine by Evernine Media GmbH