I dont know about xapo but coinbase says they store all customers vaulted coins on paper wallets and usb cold storage in bank vaults around the world. So virus on customers computer should not be an agument with insurance. Employee security is still a concern but should not stop the payouts.
To deny insurance they must prove negligence on the customers part.
I would be all for a annual or quartly independent audit of all coin that should be accounted for in their vaults at anytime.
if user negligence means you lose insurance, you are better off printing a cold wallet yourself!
Not what bitcoin is really about but a very good way to move it mainstream.
I would say that for not tech savvy people, the companies should handle that kind of security by default, and not offering it as a premium service, if you are using the vault and they give the user the key, then the user needs to understand what the key is doing, so a bit tech savvy.
The best would be for the basic user not to need to know anything at all about the tech.