Mike Boutwell

Your cyber insurance application was denied — or it will be.

Mid-market firms are losing cover at the form, not at the attack. Carriers now want proof of multi-factor authentication, endpoint detection, and tested backups. If the answers on the cyber insurance renewal are ahead of the network, two things follow: the application is declined, or a later cyber insurance claim is denied.

Mike Boutwell CISO

What I do

I sit with the managing director, the CFO, and whoever runs IT, and I go through the application as an underwriter and a claims examiner would. What is true. What would fail. What must change before an officer signs.
You keep your broker. The first conversation does not need the policy. It needs the date, and whether you have already been refused.

Who this is for

Manufacturers and other mid-market companies facing a cyber insurance renewal, a declined application, or a policy they could not defend after a ransomware event.

Who am I?

I'm Mike Boutwell a former CISO. I've lead security and risk work for Euroclear, AT&T, IBM, Cisco, Takeda, First Data, and Kyndryl.I hold the following credentials
→ CISSP
→ CISA
→ CGEIT
→ ISO 27001 Senior Lead Implementer and Auditor
→ Certified Non-Executive Director
→ Author of Profit-Driven Cybersecurity and The Ransomware Handbook

Why a cyber insurance claim gets denied

Most refusals are not about the hack. They are about the gap between the signed application and what forensics finds — MFA missing on remote access or a service account, EDR that was not on every machine, backups that were never restored. If that gap is already in the file, the policy is paper.

If the renewal or the refusal is on the desk, get in touch. We will know on a short call whether there is work to do.