Skip to content

Cyber Insurance and the WISP: What Carriers Ask in Writing, and What One Named Case Actually Shows

Checked against the primary record: July 19, 2026Case record: filed July 6, 2022; dismissed with prejudice August 30, 2022 (No. 2:22-cv-02145, C.D. Ill.)

Dolev Arama, Founder/Last updated July 20, 2026/Every figure primary-sourced

The short answer

Most cyber insurance applications never ask for your WISP, the written information security plan, by name. They ask for its contents: multi-factor authentication, backups, training, and whether the answers your firm signs are true. Signed answers are representations a carrier can rely on, and one named federal case shows a policy unwound over them.

This page explains how cyber insurance underwriting intersects with a tax practice's written information security plan. It is general information, not legal or insurance advice for your specific situation. For that, consult a qualified professional.

At a glance

Travelers v. International Control Services: what the docket shows

Case
Travelers Property Casualty Co. of America v. International Control Services, Inc., No. 2:22-cv-02145 (C.D. Ill.)
Filed
July 6, 2022: a complaint for rescission and declaratory judgment. Travelers alleged the signed application misrepresented the company's use of multi-factor authentication. Allegations, not findings: no court ever ruled on them.
The application
Signed by the CEO and a person responsible for network security, per the July 2022 trade press account of the complaint. The policy had been issued in April 2022; a ransomware event followed in May 2022.
Resolution
August 26, 2022: Travelers moved for rescission and dismissal. August 30, 2022: the court dismissed the case with prejudice, each party bearing its own costs and attorneys' fees, and entered judgment. Trade press dated the same day reported the parties had agreed the policy was void from inception.
Money
No fine, no damages award, no merits ruling. The consequence was the policy itself: unwound back to day one, before any claim could be paid under it.
What the record teaches
The lever was the application, not the ransomware. Answers a firm can document are answers it can defend; answers from memory are the kind a carrier can move to unwind.
Prepared by Safeguards Monitor from the court docket, No. 2:22-cv-02145 (C.D. Ill.), and two dated Insurance Journal reports (July 12, 2022 and August 30, 2022, labeled as press). Verified July 19, 2026.

Do cyber insurance carriers require a WISP?

Not the way a regulation does, and the difference matters. No statute makes a carrier demand a written information security plan before selling you a policy. The binding duties sit elsewhere: in the FTC's Safeguards Rule for every covered tax firm, and in state data-security law on top of it for firms with clients in certain states (Massachusetts and New York among them). What carriers control is access and terms, and they exercise that control through the application. Underwriting asks about the controls a WISP documents, in writing, and treats the answers as the basis of the deal.

That last part is not an inference; it is printed on the forms. Travelers, the same insurance group (the form issues under Travelers Casualty and Surety Company of America), publishes a Multi-Factor Authentication Supplement (form CYB-14306 Rev. 03-23, captured July 19, 2026) whose attestations include, verbatim: "Multi-Factor authentication is required for all employees when accessing email through a website or cloud based service" and "Multi-Factor authentication is required for all remote access to the network provided to employees, contractors, and 3rd party service providers." The signature block has an Executive Officer represent that "to the best of his or her knowledge and belief, and after reasonable inquiry, the statements provided in response to this Application are true and complete" and that they "may be relied upon by Travelers as the basis for providing insurance" (a reliance sentence the form itself carves out for North Carolina). A checkbox on a form like that is not paperwork. It is a knowledge-based representation with a job.

What do cyber insurance applications actually ask?

Read a cyber application next to the Safeguards Rule and the overlap is hard to miss: the questions walk through a compressed version of the program the Safeguards Rule already requires. That overlap is the practical reason the WISP matters at application time. A firm that maintains the written program holds documented answers to most of what underwriting asks; a firm without one is answering from memory. The table maps the common question classes to the rule element each one mirrors, and to what an inaccurate answer risks.

What cyber applications ask, next to the Safeguards Rule element each question mirrors
Control areaHow applications askThe rule element it mirrorsIf the answer is wrong
Written security programA yes/no class: does the firm maintain written information security policies or a security plan?The written program itself (16 CFR 314.3(a)), the duty the whole rule hangs on.A yes with no document behind it is a representation the carrier can test after an incident, when the file gets read.
Multi-factor authenticationAttestation items, often per system. The Travelers supplement asks it for email, remote access, and four classes of administrative access, verbatim quoted above.16 CFR 314.4(c)(5) (what the MFA element actually demands).The subject of the named case: Travelers alleged the signed MFA answers did not match practice, and sued to rescind.
EncryptionA yes/no or scope class: is client data encrypted in transit and at rest?16 CFR 314.4(c)(3), including its compensating-controls path, which runs through your Qualified Individual.An unqualified yes where the honest answer is partial invites the same misrepresentation lever.
Backups and recoveryA recovery class: does the firm keep separated backups, and do they restore when tested?No single element says backups. The honest map is the incident-response plan's recovery goals (314.4(h)) plus the risk-driven safeguards of 314.4(c).Recovery representations get tested at the worst time: during the incident the policy exists for.
Security trainingA cadence class: do employees receive security awareness training?16 CFR 314.4(e)(1).Training answers are checkable against records, or against their absence.
Vendor oversightA third-party class: are service providers assessed and under contract for security?16 CFR 314.4(f).A yes here implies contracts and assessments that either exist in the file or do not.
Incident historyA disclosure class: any prior breaches, claims, or ransomware events?No rule mirror. This one is a plain factual history question.History is verifiable against public records, including state breach archives.
Prepared by Safeguards Monitor from 16 CFR 314.3 and 16 CFR 314.4 (eCFR), checked July 19, 2026, and the Travelers Multi-Factor Authentication Supplement (CYB-14306 Rev. 03-23, captured July 19, 2026). Question classes beyond that form are described from application practice, not quoted from any single form.

What happened in Travelers v. International Control Services?

The short version circulating in the field says a claim was denied because a company had no MFA. The court record says something more precise, and for a firm filling out an application, more useful. In July 2022, after a ransomware event at International Control Services, an Illinois electronics manufacturer, Travelers did not deny a claim and walk away. It filed a federal lawsuit (complaint filed July 6, 2022, C.D. Ill.) asking the court to rescind the entire policy and declare it had no duty to defend or indemnify, alleging the application's signed MFA answers misrepresented what the company actually ran. The July 2022 trade press account reported the complaint's core allegation: MFA protected the firewall and no other digital assets, while the signed application said more.

Then it ended quickly, and without a verdict. On August 26, 2022, per the docket, Travelers moved for rescission and dismissal; the August 30 press report described an agreement between the parties that the policy was void from inception. On August 30, 2022 the court dismissed the case with prejudice, each party bearing its own costs and attorneys' fees. So the field's flattening gets the mechanism wrong twice. Nothing here was a claim denial, and nothing was adjudicated: the allegations stayed allegations. What the record actually shows is an insurer using the application, not the loss, as its lever, and a policyholder giving up the whole policy with the allegations never tested in court.

Understood precisely, the case is scarier than the myth in one specific way. A claim denial is a fight about one loss. Rescission unwinds the policy to day one, as if coverage never existed, for every past and future claim under it. The instrument that opens that door is the application, and the application is signed before any incident happens. That is why the plan behind your answers matters on the day you fill the form in, not just on the day something goes wrong.

Can a claim be denied because you have no WISP?

Here is the honest ceiling. We could not locate any public record, court or regulator, of a cyber claim denied solely because the insured lacked a written information security plan (search depth, checked July 19, 2026). If a vendor tells you "no WISP means no payout," ask for the case; we have not found it. The documented mechanisms run through the application instead: misrepresentation and rescission, as in the Travelers case, and underwriting screening that conditions the policy's terms on attested controls. A widely repeated claim that around 40 percent of cyber claims are denied circulates in vendor marketing without a named, methodologically documented source behind it; we tried to trace it (July 19, 2026) and do not repeat it as fact.

What the record does support is narrower and still serious. The state insurance regulators' association, in its latest Report on the Cybersecurity Insurance Market (NAIC, 2024 data), counts 9,941 cyber claims closed with payment against 28,555 closed without payment. The report does not say why individual claims closed unpaid, and closed without payment is not a synonym for denied: a claim can fall below the retention, land outside the policy's scope, or be withdrawn. The precise reading is uncomfortable enough without inflation: most closed cyber claims in that data ended with no check, and the instrument that decides which side of the line a firm lands on is written before the incident.

One more thread comes from the IRS rather than any carrier. The Office of Professional Responsibility, in its June 2025 bulletin on WISPs, warned that failing to maintain one "may also expose a practitioner to liability for violating the Safeguards Rule and the terms of their malpractice insurance coverage" (OPR Issue 2025-8, June 9, 2025). That is an IRS office connecting a missing WISP to insurance exposure in plain words. And insurance is only one consequence lane for a tax practice: the machinery that ends practices runs through e-file credentials, and what actually puts an EFIN at risk is its own documented story.

Put together, the honest fear reads like this. Carriers now ask for your security posture in writing and reserve the right to rely on every answer. One insurer has already used those answers to unwind a policy after a ransomware event, in a rescission suit that closed with the policy agreed void from inception, per the dated press report, and the case dismissed with prejudice. The fix is not exotic: answer from a document instead of from memory. The plan you can actually produce is what gives every answer a page you can point to.

How do you answer an application you can stand behind?

Treat the application as a sworn snapshot of your program, and build the snapshot from the program itself:

  1. Pull the plan before the form. Every security question gets answered from the written information security plan, not from recollection. If there is no plan to pull, that is the first finding.
  2. Walk the questions with your Qualified Individual. The rule already names the person responsible for the program (16 CFR 314.4(a)). The same person signs off on what the application says about it, including any written exception the program relies on.
  3. Check answers against systems, not intentions. For each attestation, open the actual setting: which logins enforce MFA, what the backup separation really is, when training last ran. The Travelers supplement asks per system class; answer per system class.
  4. Say no where the answer is no. A truthful no, with a dated remediation plan, is an underwriting conversation. An optimistic yes is the raw material of a rescission suit.
  5. Date the answers and file the application with the WISP. The signed application is part of your security record now. Keep the copy, note the date, and record which plan version it described.
  6. Re-run the walk at every renewal. Controls drift. The representations should not.

Cyber policies are contracts, and what an application question means turns on each policy's own wording. Before you rely on an uncertain answer, or on any exception, have a licensed insurance professional or an attorney review the question against the control it describes.

Do carriers check again at renewal?

Renewal is a fresh application event, and the attestation instruments are built for reuse: the Travelers supplement is a standing form with a revision code, signed by an Executive Officer whenever it is submitted, and it obliges the applicant to "notify Travelers of any material changes to the information provided." Whether a given carrier re-verifies controls mid-term varies by carrier and market, and we have not found a public record that settles that practice one way; what is documented is that the representations renew when the paperwork does. Two other clocks live alongside renewal. Incident-history questions reach backward, so this year's events become next year's disclosure. And if an incident happens mid-term, the policy's notice clause has its own clock, reading that clause is a same-day step, and the notification sequence after a client-data incident runs wider than the insurer.

FAQ

Does my E&O or malpractice policy already cover a data breach?

Usually not the way firms hope. Errors-and-omissions coverage responds to claims that your professional work harmed a client; cyber coverage responds to the breach event itself, including client notification, forensics, and recovery. The overlap between the two is narrower than it looks, exclusions differ by contract, and the IRS's OPR bulletin has already flagged that a missing WISP can touch malpractice coverage terms. The only reliable answer comes from reading both policies, ideally with the three agent questions below in hand.

Can an MFA misstatement really void a policy?

The named record shows the lever being used, not a court ruling on it. Travelers alleged misrepresented MFA answers and sued to rescind; the parties then agreed, per the dated press report, that the policy was void from inception, and the court dismissed the case with prejudice on August 30, 2022, without deciding whether the allegations were true. So no judicial precedent says yes, and no firm should bet its coverage on the answer being no: the case ended with the policyholder holding no policy.

Will a WISP lower my cyber premium?

We do not know, and we have not found a primary source that proves it, so we will not claim it. What the documented record supports is different: attested controls decide whether carriers offer coverage and on what terms, and the written plan is what lets a firm attest accurately. Treat premium effects as a question for your agent, and treat accuracy as the non-negotiable part.

What should a solo firm ask its insurance agent?

Three questions do most of the work. First: which of my answers are representations the carrier can rely on, and where do they live in the policy? Second: what exactly does the notice clause require from me on the day I discover an incident? Third: which controls in this application does my written plan document today, and which would I be attesting to from memory? The third question usually decides what to fix before signing.

The bottom line

Cyber carriers do not enforce the Safeguards Rule, and no public record shows a claim denied just for a missing WISP. What the record shows is sharper: applications now put your security program in writing, signatures make it a representation, and the named case above ended with a policy agreed void from inception after the MFA answers came into question. The written plan is how a firm signs that form honestly. Answer from the document, and every answer has a source you can produce.