What your cyber policy actually excludes
The application is a legal document and the policy is a contract full of conditions. Almost nobody has counsel read either one until the day of the claim.
This page is general information for operators, current as of the date shown. It is not legal advice, and reading it does not create an attorney-client relationship. Specific facts change the answer.
The application becomes the policy
Cyber applications ask very precise questions. Is MFA enforced on all systems? Is endpoint protection deployed everywhere? Are backups segregated from production? Whoever signs that form is making representations, and warranty language plus failure-to-maintain provisions give the carrier a clean route to void the claim if a control was true when you applied and had quietly lapsed by the time of the incident. Insurance does not recognize a category called "mostly true." So have someone with authority read the application the way opposing counsel eventually will, as a list of dated promises you now have to keep for the life of the policy.
Denials aren't rare
A large share of applications don't survive first submission, and missing MFA and endpoint gaps are the reasons that come up most. Underwriters increasingly scan your external attack surface themselves rather than take your word for it, so what you wrote on the form gets checked against what they can see from the outside. The market started demanding evidence faster than most startups changed how they answer.
The sublimit you didn't price
Social engineering is where startups actually lose money: the fraudulent wire, the fake vendor email, the finance hire who did exactly what the message told them to do. That exposure is routinely written as a sublimit rather than full policy coverage, and courts enforce sublimits exactly as drafted. In one recent case, a $250,000 sublimit was all that answered an $874,000 wire loss, which left the company carrying the remaining six figures itself. Find your number before you need it, then spend the difference on controls.
The AI exclusions are arriving
Standard-form generative-AI exclusions took effect in 2026, and carriers are now filing AI endorsements across general liability, E&O, and D&O lines. At the same time, your enterprise customers are asking you to indemnify them for AI output. Put those two facts next to each other and follow the logic. If your policy excludes AI-related harms while your MSA promises to cover them, the gap between the documents doesn't vanish. It lands on your balance sheet, payable in cash, at the worst moment. This is the flow-down problem again, viewed from the insurance side of the table.
Claims-made mechanics
Most of these policies are claims-made, which means coverage turns on when the claim gets made and reported to the carrier, not on when the incident actually happened. Retroactive dates, notice provisions, and consent-to-settle clauses are where a covered event quietly turns into an uncovered one, usually through nothing worse than a missed calendar entry. Track those dates in the same system where you track court deadlines, because functionally that's what they are.
Have counsel read five things
Insurance is a contract you buy hoping you never have to test it. Having someone read it closely before you sign is probably the cheapest legal work you'll ever commission, and it's the only version of that reading that happens on your schedule instead of the carrier's.