Subscribe to Cyber Treats! https://facettech.com/cybertreats/

Join us for our second AI Fluent Leaders Session on Wednesday, February 25. This one’s all about security. We’re introducing some brand new, game-changing information for leaders (and some crucial context around some recent Copilot news)! Hope to see you there.
More Than a Checkbox
For cyber insurance payouts, “mostly implemented” doesn’t count.
We’re sometimes the first call a business makes after a ransomware attack if they don’t have a current IT provider, or one that isn’t cybersecurity-focused. One of the first questions we hear, right after “can you help us recover?” is, “will our insurance cover this?”
In 2024, nearly three times more cyber insurance claims were closed without payment as were actually paid, per the National Association of Insurance Commissioners.
When a business gets hit, investigators come in. Their job is to cross-reference your network against every answer on the application you filled out when you signed up. They’ve got that questionnaire from two years back, and they’re checking your work.
Why claims get denied:
It mostly comes down to misrepresentation, even unintentional. 82% of denied claims involved organizations that lacked MFA (often, the business will only have MFA on their email and not on their servers). 44% were denied due to missing or undocumented controls.
Other common triggers: no formal training program, late breach notification (some policies have just a 72-hour window), and third-party exclusions if the attack entered through a vendor.
If you’re paying for the policy, it should work when you need it. That means knowing what’s required, making sure your network reflects what’s on paper, and keeping documentation.
If you’re a current Facet client, we are always here to help with completing your cyber insurance questionnaires. In fact, getting help from us can often reduce your premium.
Need some advice? Call us at (309) 689-3900 to request a consultation.
In The News:
This week, Microsoft confirmed that Copilot surfaced summaries of confidential emails to employees who shouldn’t have seen them.
Microsoft called it a bug, but the bigger story is this: your data governance policies were built for a world where humans access information one file at a time. Copilot doesn’t work that way. It synthesizes everything it can reach, and it does it instantly. Most organizations’ existing controls were never designed with that in mind.
This is another reason AI must be set up correctly from the start, with governance built specifically for how it works.
That’s what Brian Ford and Matt Ghiglieri are covering in our next AI Fluent Leaders session on February 25 at 10am. If your organization uses or is considering Microsoft 365 Copilot or another AI solution, this one’s worth 45 minutes of your time.
AI Fluent Leaders: Session 2
Want to Use AI Without the Risk?
Missed the first AI-Fluent Leaders session?
No problem—you can catch the recording here: Watch AI Fluent Leaders: Session 1
Subscribe to Cyber Treats! https://facettech.com/cybertreats/
Ellie Shaw is the Director of Marketing at Facet and the author of Cyber Treats, Facet's biweekly newsletter featuring topics like IT news, cybersecurity updates, compliance advice, and anything tech. She has been a member of the Facet team full-time since 2016 and enjoys finding new ways to share resources and information about cybersecurity with others.
