At 9:12 on a Tuesday morning, the owner of a 38-person HVAC distributor opened an eleven-page cyber renewal application. Forty-one of its forty-seven technical questions were already filled in. They had been answered at 11:48 the night before by an account manager at his IT company, who had done a careful and conscientious job. The owner read the first page, scrolled past the security section, and signed. Elapsed time on the document: ninety seconds.

His name is the only name on it.

Whose representation is it?

The phrase that does the damage is "my IT company handles that." It is doing a lot of quiet work.

Give it its due, because it is mostly correct. You should not be reading conditional access policy exports. You hired someone precisely so that questions about endpoint agent coverage and backup immutability get answered by a person who looks at those consoles daily rather than one who has never opened them. Division of labor is not negligence. It is why the answers on that form are more accurate than anything you would have guessed at yourself.

What "my IT company handles that" does not do is move the signature. Insurance applications are structured around the applicant. Florida's statute on representations in applications illustrates the general architecture: it treats "any statement or description made by or on behalf of an insured" in an application as a representation, and provides that a misrepresentation, omission, or incorrect statement may prevent recovery if it is fraudulent or material to the acceptance of the risk, or if the insurer in good faith would not have issued the policy, or not at the same premium, or not in as large an amount, or would not have covered the hazard resulting in the loss. Other states phrase it differently and the differences matter, which is work for counsel — but note the four words near the front. On behalf of. The statute already contemplates that someone else supplied the answer. It does not treat that as a defense.

A companion principle runs through most jurisdictions: a person who signs a document is generally charged with knowledge of what it says. One long-standing formulation holds that a party who knowingly and voluntarily assents to a contract whose terms are in a writing is bound by those terms, absent fraud, mistake, or some other excusing cause. A few states recognize exceptions where an insured relied on an agent's representations. Whether any of that helps in a given dispute is entirely a question of policy language, state law, and facts — which is why this is a description of how these documents are built, not an opinion about how any of them come out.

"My IT company told me we had it" is true and still weak

Say the sentence out loud at claim time and listen to what it is. It is a statement about a conversation. It is not a statement about a system, and it is not evidence.

There is a real distinction underneath, worth being precise about:

  • A factual statement is verifiable and dated. "As of January 14, MFA is enforced on all 61 Microsoft 365 accounts; four service principals and one emergency access account are excluded, listed below." That is checkable against a console export. If it turns out to be wrong, the wrongness is locatable.
  • A professional opinion is a judgment about a question. "In our view this satisfies question 7." That is an interpretation of an insurance form by someone who is not an insurance professional, and it carries whatever weight the reader decides to give it.
  • A verbal reassurance is neither. "Yeah, we're covered on that." It survives no scrutiny at all, and it is the form the exchange usually takes.

Forrester's analysis of an MFA misrepresentation dispute made the underlying observation well: "A reliance on questionnaires and clarifying questions is common. Also common is no mention of any requirements for ongoing monitoring or evidence that requirements are met." The application asks for a claim. Nothing in the process asks anyone to prove it.

The fix is boring and takes about twenty minutes

  • Your provider writes the facts, not the conclusions. A short dated memo listing each control question, the factual state of the environment, and every exception. Not "yes to question 7" — the actual sentence describing what is and is not enforced.
  • You read it before you sign. Not the whole application. The memo. If a line does not match your understanding of your own business, that is the twenty minutes paying for itself.
  • Both of you keep the same version. In the folder with the signed application and the quote. Two years from now the question will be what was true on the signing date, and only a document created near that date can answer it.
  • The exceptions go in writing, on purpose. A disclosed exception is a fact you told the underwriter. An undisclosed one is a fact someone else discovers later.

The application was accurate. The upkeep was not.

Here is the part that gets almost no coverage, and it is the more dangerous half.

Some cyber policies have historically required the insured not merely to have the controls described in the application, but to keep them. The best-documented example is the Columbia Casualty Company v. Cottage Health System coverage dispute, filed in the Central District of California in May 2015 after a 2013 incident in which, per the insurer's complaint, file transfer protocol settings on internet-facing servers permitted anonymous user access, exposing records for roughly 32,500 patients between October 8 and December 2, 2013. A third-party vendor was involved in storing the records. The insurer funded a $4.125 million class settlement under a reservation of rights, then sought reimbursement.

Two pieces of that policy are worth reading closely. The exclusion, titled "Failure to Follow Minimum Required Practices," applied to loss arising out of "[a]ny failure of an Insured to continuously implement the procedures and risk controls identified in the Insured's application for this Insurance and all related information submitted to the Insurer in conjunction with such application." A related condition required the insured to maintain all risk controls identified in the application and any supplemental information.

The word carrying the weight is continuously. Not "had on the application date." Not "intended to have."

The self-assessment answers the insurer pointed to were ordinary questions any small business would say yes to without hesitating — "Do you check for security patches to your systems at least weekly and implement them within 30 days?" and "Do you replace factory default settings to ensure your information security systems are securely configured?" among them.

Be accurate about how this ended, because most write-ups are not. No court ever ruled on whether that exclusion applied. The first federal suit was dismissed without prejudice in July 2015 because the insurer had not completed the policy's mandatory alternative dispute resolution process before filing. A second action followed in May 2016, alongside a state proceeding and an appeal. The case is famous for language in a policy form, not for a holding. Treat it as a specimen of drafting, not a prediction — and if similar language sits in your own policy, that is a conversation for your broker and counsel.

The agent that stopped reporting on 12 of 60 endpoints

Make it concrete, because "continuously" is an operational word before it is a legal one.

In January, the EDR console showed 60 devices. The application said EDR was deployed to all endpoints, and that was true. In March, a Windows feature update broke the agent's driver on a batch of machines imaged from the same base. In April, six replacement laptops went out from a spare pool that predated the current deployment script. By May, 12 of 60 endpoints had not sent telemetry in more than thirty days.

The console still said 60. That is the part that catches people. Most endpoint consoles report enrolled devices by default, and a machine that stopped checking in does not disappear — it just gets an older last-seen date in a column nobody sorts by. Nobody disabled anything. Nobody made a decision. Coverage went from 100 percent to 80 percent through pure entropy, and the only artifact that would have shown it was a report nobody was running.

The control you attested to was true in January and false by May. If a claim lands in June, the question is not whether you lied. You did not. The question is what you can show about the four months in between.

Continuous evidence rather than annual attestation

  • Capture the coverage number on a schedule, not on demand. Monthly, filtered by last-seen inside a fixed window, exported with a date, and kept. A number you can only produce today proves today.
  • Reconcile against something that is not the security tool. Compare the agent inventory to a device list from your directory, your RMM, or your asset ledger. A tool cannot report on machines it does not know exist.
  • Make the exception list a living document. Same fields every month — system, reason, compensating control, owner, target date. Exceptions that close should close on the record; ones that persist should persist visibly, so the next application discloses them.
  • Build the renewal file as you go. Twelve monthly coverage reports, the current exception schedule, patch compliance exports, training completion rosters, and the memo your provider signed last year. That file answers "was it maintained" in a way an annual attestation cannot.

An IT provider has every commercial reason not to tell you this

Nearly everything published on this subject is advertising for errors-and-omissions insurance aimed at IT providers. That is a reasonable product and a poor way to learn about your own exposure, so it is worth naming what an honest version costs the person writing it.

An IT provider that says "make us put the facts in writing, then read it yourself before you sign" is arguing for a document that can be held against it. It converts a friendly verbal assurance into a dated record. It invites a customer to check its work, monthly, with numbers. Every incentive points the other way — toward answering the form quietly, sending the PDF at 11:48 p.m., and letting a busy owner sign in ninety seconds. The convenience is real, so is the exposure it creates, and the exposure lands on the signature.

None of this is a knock on IT providers, who are usually the only people in the room who know the answers, and none of it is a knock on carriers, whose questions are the right questions. It is a comment on a process that collects one signature, once a year, for facts that change every week. The application is a snapshot. The exclusion, where one exists, is about the film.

Everything specific here — what any policy requires, what any answer means, what any exclusion does — is governed by that policy's language and by qualified insurance and legal counsel. What is not a legal question is whether you can produce, on demand, a dated record of what was true and when. That part is just operations.