Cyber Insurance: Why Questionnaires Fail to Assess Today's Risk
Static controls on a form tell you nothing about live credential exposure — and insurers are paying for the gap.
What this report covers:
- The structural flaw
Questionnaires measure static controls at a point in time and ignore real-time threats like actively circulating compromised credentials.
- Two case studies
23andMe (October 2023) and Marks & Spencer (2025) — well-intentioned security measures that failed, leaving insurers to cover preventable claims.
- Financial implications
How the gap between declared controls and live exposure translates into unexpected loss ratios.
- Better questions to ask
Targeted underwriting questions on credential screening, NIST-aligned audit frequency, and penetration testing for credential security.
