All resources
★ Field Report · 19 · Cybersecurity

Your Cyber Insurance Won't Pay Out If You Can't Prove It. Here's What Underwriters Actually Check in 2026.

41% of cyber insurance applications get denied on first submission. Here's what trucking companies need to prove — not just claim — to get covered in 2026, and what happens when a carrier can't.

Trucky × We Secure·August 27, 2026·6 min read

In October 2023, Estes Express Lines — a top-15 for-hire carrier — shut down its own email, phones, and website. Not because attackers took them down. Because Estes took them down on purpose, to stop a ransomware infection from spreading further. It took roughly three weeks to bring core systems back, and the attackers still walked away with personal data on more than 21,000 people, which led to a class action lawsuit months later. That same year, trailer and component manufacturer SAF-Holland had to shut down manufacturing sites after a cyberattack, with estimated sales losses near $44 million, and telematics provider Orbcomm was hit with ransomware that knocked out service for fleet customers who had nothing to do with the original breach.

Here's the question that matters more than any of those headlines: if it happened to your fleet tomorrow, which policy would pay for it?

For most carriers, the honest answer is none of them. And a growing number of carriers who do have a cyber policy are finding out the hard way that having one isn't the same as being covered.

Your general liability policy was never built for this

Standard commercial general liability and commercial auto policies exclude cyber events almost entirely. Most GL forms use a standardized exclusion — introduced industry-wide back in 2013 — that removes coverage for the loss, corruption, or inaccessibility of electronic data. That exclusion exists so insurers don't have to pay ransomware and data-breach claims out of a policy priced for slip-and-fall and cargo damage risk. Courts have consistently backed insurers on this. Cyber liability is a separate line, and it's the only one that actually pays for business interruption, ransomware extortion, forensic investigation, and third-party liability when a dispatch system, a payroll platform, or a factoring account gets compromised.

Underwriting stopped being a checkbox

Cyber insurance used to be a short questionnaire and a signature. That's gone. The global cyber insurance market hit an estimated $16.3 billion in premiums in 2025, and the losses behind that growth taught insurers something specific: the companies that got hit hardest almost always had the same handful of gaps — missing multi-factor authentication, untested backups, no written incident response plan, staff who'd never seen a phishing simulation.

41%
Of cyber insurance applications denied on first submission
99%
Of applications now ask specific MFA questions (Marsh McLennan 2025)
82%
Of denied claims lacked properly implemented MFA (Coalition 2024)
$16.3B
Global cyber insurance premiums in 2025

So underwriters stopped taking applicants at their word. According to Marsh McLennan's 2025 Cyber Insurance Market Report, 99% of cyber insurance applications now ask specific questions about MFA implementation. Coalition's 2024 Cyber Claims Report found that 82% of denied claims involved organizations without properly implemented MFA across their environment. Put those together and you get a hard number: 41% of cyber insurance applications are denied on first submission, with missing MFA and inadequate endpoint protection as the top two reasons.

That's not a niche problem. That's close to half of everyone who applies.

"Yes" isn't proof anymore

The trap most carriers fall into isn't lying on the application. It's answering honestly based on what they believe is true.

A documented case worth knowing: in International Control Services v. Travelers, the insurer denied a claim after discovering MFA was implemented on the firewall but not on the remote access system the attackers actually used to get in. Nobody lied. The gap was between "we have MFA" and "we have MFA everywhere it needs to be, enforced, all the time" — and that gap is exactly where claims get denied.

For a trucking operation, that gap tends to show up in predictable places:

  • MFA turned on for company email but not for the dispatch software, the TMS admin console, or the VPN a dispatcher uses from home.
  • "Backups" that are really just a synced folder — the same folder ransomware encrypted along with everything else, because it was never actually isolated from the network. We covered how one weak password ended a 158-year-old carrier — the backup gap is usually what turns that kind of breach into a total loss instead of a bad week.
  • An antivirus product nobody's checked on in months, standing in for what insurers now expect to be modern endpoint detection and response (EDR).
  • No written incident response plan — this is exactly the gap a quarterly tabletop exercise is built to close, and it's the first thing an underwriter's investigator checks after a claim.

Research cited in industry underwriting guidance found that 94% of organizations hit by ransomware saw attackers try to hit their backups first, and that ransomware was linked to roughly three-quarters of system-intrusion breaches in 2025. Insurers know this. It's why "we have backups" isn't an acceptable answer anymore — restore-test logs and dates are.

Where a carrier's cyber exposure actually sits

Trucking runs on connected systems now, and each one is a different kind of exposure:

ELDs and telematics. Your ELD reports location, speed, and hours-of-service data in real time, and it's a connected device like any other. NMFTA's research team has spent years reverse-engineering ELD and telematics hardware specifically to find the vulnerabilities before criminals do, and has already demonstrated remote attacks using nothing more than a basic antenna. A telematics provider that doesn't secure its own platform leaves every truck connected to it exposed at once.

TMS, dispatch, and load boards. Your transportation management system holds rate confirmations, customer data, and driver assignments — and it's a favorite target for business email compromise, where an attacker impersonates a broker or shipper and redirects a load or a payment.

Factoring and invoicing. A common pattern: accounts payable gets an email that looks exactly like the fleet's factoring company, right down to the logo, asking to update the remit-to bank account. Someone updates it. The next payment goes straight to the fraudster, and the fleet still owes the factoring company for money it never actually received — the same ACH-redirect and BEC pattern hitting brokerages and factoring desks industry-wide. This kind of loss usually falls under social engineering or funds-transfer-fraud coverage — a line item that's often a separate add-on, not automatic in a base policy.

Trucking-specific market data backs up why this matters at the underwriting level: ransomware demand among Marsh's clients was up 64% in a single year, with a median demand of $20 million, according to NMFTA's reporting on the trucking cyber insurance market. That's the number driving the sub-limits and exclusions carriers are now writing into every policy.

What a "proof packet" actually looks like

Underwriters increasingly want documentation, not attestation, on five things:

1

MFA enforcement

Screenshots or reports showing exactly which accounts and systems are covered, not just email.

2

EDR deployment

Coverage reports showing endpoint protection across every device, not just the office computers.

3

Backup logs

Restore-test results and dates, not a statement that backups "run automatically."

4

A dated, tested incident response plan

Ideally with notes from an actual tabletop exercise in the past 12 months.

5

Training completion records

Proof staff has been through phishing simulation in the last year, since human error remains a factor in roughly two-thirds of breaches globally according to Verizon's Data Breach Investigations Report.

Fleets that can produce this get quoted faster and cheaper. Fleets that can't either get declined, or find out during a claim that what they attested to didn't match what an investigator found.

What to do before your renewal, not after

Start the process 60 to 90 days out, not the week the renewal notice arrives. Specifically:

  • Require MFA on every account touching business data — email, VPN, TMS, dispatch software, cloud admin consoles, banking — and confirm it's enforced, not optional.
  • Verify any request to change payment or remit-to details by phone, using a number already on file, never one from the email itself.
  • Replace standalone antivirus with EDR that can detect and isolate a compromised device in real time.
  • Move backups somewhere genuinely isolated from the main network, and test restores on a schedule you can document.
  • Put a short incident response plan in writing, and actually run it once as a tabletop exercise.

None of this is exotic. It's the same baseline the Cybersecurity and Infrastructure Security Agency recommends for any small or mid-sized business — it's just that insurers are now the ones checking.

This is the exact gap We Secure closes for Trucky carriers: building the MFA enforcement, EDR coverage, tested backups, and incident response documentation that an underwriter is actually going to ask for, before the renewal notice — or the incident — forces the question. Start with a free threat assessment at /threat-console and find out where your fleet actually stands.

Sources

Pullsure — Cyber Liability Insurance for Trucking Companies · NMFTA — Cyber Insurance: What the Trucking Industry Needs to Know · BSGtech — Cyber Insurance Requirements for Businesses in 2026 · Coalition — 2024 Cyber Claims Report · Trucking Dive — Estes Express Lines Cyberattack Timeline · CISA — Cyber Guidance for Small Businesses.

★ Want this implemented for your fleet?

Book a 30-minute strategy call.

Walk away with a plan — even if we never work together.

Book a call