You Passed the Audit. That Wasn't the Question.

July 27, 2026

Most security reviews answer one question: do these controls exist. Attackers ask a different one: do these controls still work once someone actively tries to defeat them. Most organizations answer the first question and assume they've answered the second.

Does passing a cyber insurance audit mean you're secure

Cyber insurance renewals now require documented proof of specific controls: phishing resistant MFA, continuous EDR, tested backups, a written incident response plan. Passing that review means you've shown the insurer those controls are in place. It does not mean they will hold up during an actual attack. Those are two different claims, and only one of them gets tested.

What Dave Chronister found after the audit already passed

Dave Chronister has run incident response and penetration testing engagements since 2007. He walked through this exact gap in a recent episode of Signed, "The EDR Was Running. The Ransomware Still Won."

One case involved a parent company and its subsidiary running on shared infrastructure. The CIO, also a co owner of the smaller company, told his business partner they didn't need MDR. Their prior reviews hadn't turned up any real gaps, so they assumed the environment was in good shape. They were hit with ransomware the following week.

When Dave's team investigated, they found both companies sitting on the same domain. One sysadmin covered both. One PC technician handled support for everyone. Every user, including end users, ran as local admin. A single compromised credential could move freely across both companies with nothing to stop it.

The ransomware didn't expose a missing control. It exposed a control that existed on paper and failed the moment it was actually tested.

Existing versus working, control by control

The same gap shows up everywhere, once you know to look for it.

MFA enabled tells you a control exists. Every privileged, service, and emergency account actually being covered by it, including the ones somebody forgot to enroll, tells you it works.

EDR installed tells you a control exists. Someone actively reviewing alerts, tuning detections, and chasing down suspicious activity before it turns into ransomware tells you it works.

Backups completing on schedule tells you a control exists. Restores being tested regularly, with recovery times that actually meet the business, tells you it works.

An incident response plan sitting in a shared drive tells you a control exists. The people named in it having rehearsed their roles, so they know who's making the call thirty minutes into a live breach, tells you it works.

Why this goes well beyond cyber insurance

This isn't unique to cyber insurance. It's how nearly every compliance framework operates. SOC 2, ISO 27001, PCI, HIPAA, and most vendor risk assessments confirm that controls are documented and implemented. They aren't built to simulate how an attacker would actually exploit the space between those controls.

That's why the same sequence keeps repeating: documentation gets produced, the audit passes, leadership assumes the risk is handled, the operational weakness underneath never gets touched, an attacker finds it anyway, and afterward everyone wants to know how the audit missed it. It didn't miss anything. It was never designed to catch it.

None of this means the required controls are wrong. MFA, EDR, tested backups, and a real incident response plan are exactly what should be in place. A passed audit should give you real confidence those foundations exist. It shouldn't be mistaken for proof they'll hold up under pressure.

Three questions worth asking before you trust your next audit

Before you accept the result of your next cyber insurance renewal, compliance audit, or customer security review, ask three questions about anything on that list. Was this control verified through active testing, or just documented. Has anyone actually tried to defeat it under realistic conditions. If it failed tomorrow, how long would it take anyone to notice.

If you can't answer those three with confidence, the review you just passed told you less than it felt like it did.

Dave walks through several more cases like this one, and where the gap tends to hide, in the full episode: The EDR Was Running. The Ransomware Still Won.

If you're heading into a cyber insurance renewal, a customer security review, or a compliance audit, start there. Separate what's documented from what's actually been validated. That gap is where the most expensive assumptions hide.

We'll show you exactly where the gap is. Get Started.

No pitch. No prep. Just answers.