What Is Cyber Insurance, and What Does It Cover?

By J. Mesa

Your general liability policy almost certainly excludes a data breach. Most business owner policies do. That gap surprises people on the worst day of their business life. Cyber insurance fills it, but the application now reads like a security audit, and a wrong answer can cost you the claim.

What is cyber insurance?

Cyber insurance is a policy that pays the costs of a cyberattack or data breach. It covers your own losses, the claims other people bring against you, and access to specialists who manage the response. You may see it called cyber liability insurance or cyber risk insurance.

What does cyber insurance cover?

Policies split into two halves.

First-party coverage pays your own costs:

  • Incident response. Forensic investigators who work out what happened and how far it spread.
  • Legal counsel. A breach attorney who directs the response and identifies your notification duties.
  • Notification and credit monitoring. Letters to affected people and the monitoring services the law or goodwill requires.
  • Data restoration. The cost to rebuild systems and recover data.
  • Business interruption. Income you lost while systems were down, after a waiting period.
  • Cyber extortion. Ransom negotiation and, where legal, the payment.
  • Public relations. Help managing the message to customers and the press.

Third-party coverage pays for claims against you:

  • Lawsuits from customers, patients, or business partners whose data you exposed
  • Regulatory investigations, with fines and penalties where the law allows insurance to pay them
  • Payment card industry assessments after a card data breach
  • Media liability for content on your website

What does cyber insurance not cover?

Read the exclusions before you need them. Common ones include:

  • Incidents that began before the policy. An intruder already inside your network on the start date may fall outside coverage.
  • Failure to maintain the security you promised. If the application says you use multi-factor authentication and you do not, the insurer can deny the claim or cancel the policy.
  • Upgrades. The policy restores you to where you were. It does not pay for a better system.
  • Lost future profit and reputational harm, beyond what the business interruption terms define.
  • Loss of intellectual property value.
  • War and state-sponsored attacks. Insurers tightened this wording in recent years.
  • Bodily injury and property damage, in most policies.
  • Outages at your utility or internet provider.

Does cyber insurance cover ransomware payments?

Most policies do, subject to limits. Many insurers apply a lower sublimit or a coinsurance share to ransomware, so a $1 million policy may pay $250,000 for an extortion event. The insurer must approve the payment in advance, and paying a group under US sanctions is illegal no matter what the policy says. Call the carrier’s hotline before you communicate with the attacker.

Does it cover wire fraud and social engineering?

Often only by endorsement, and with a low limit. A fake invoice or a spoofed email that tricks your employee into sending a wire is “voluntary” in the insurer’s eyes. Social engineering or funds transfer fraud coverage commonly caps at $100,000 to $250,000, and many policies require proof that you verified the request by phone before paying. Ask your broker to show you this clause. See our post on business email compromise for the controls insurers expect.

How much does cyber insurance cost?

A small business with modest revenue and good controls often pays $1,000 to $3,000 a year for $1 million in coverage. The premium depends on:

  • Industry. Healthcare, finance, and law firms pay more.
  • Revenue
  • The number and type of records you hold
  • Your security controls
  • Your claims history
  • The limit and the deductible you choose

How much coverage do I need?

Estimate the cost of your worst realistic week. Count the records you hold and multiply by the per-person cost of notification and monitoring. Add a forensic investigation, legal fees, two to four weeks of lost income, and the cost to rebuild your systems. Check your contracts too, because larger customers often require a minimum limit, commonly $1 million or $2 million. A broker who specializes in cyber coverage can benchmark you against similar businesses.

What security controls do insurers require?

The application asks about specific controls. Expect these questions:

  • Multi-factor authentication on email, remote access, and administrator accounts
  • Backups that are offline or immutable, encrypted, and tested
  • Endpoint detection and response software on computers and servers
  • Timely patching, with no end-of-life systems
  • Security awareness training and phishing tests for staff
  • A written incident response plan
  • Email filtering
  • Call-back verification before wire transfers and bank detail changes
  • Limited administrator rights

Missing the first two items gets many applications declined outright.

Why do claims get denied?

  • Inaccurate application answers. The application becomes part of the contract. An owner who checks “yes” for multi-factor authentication on all accounts, when two mailboxes lack it, hands the insurer a reason to rescind the policy. Answer with evidence, and involve the person who runs your IT.
  • Late notice. Policies set deadlines. Report a suspected incident right away, even before you know the scope.
  • Unapproved vendors. Hiring your own forensic firm or lawyer without the carrier’s consent can leave you paying those bills.
  • Unapproved payments. The same applies to a ransom.
  • Skipped verification. A wire sent without the required call-back may fall outside the fraud coverage.

What should I do when I have an incident?

Call the carrier’s 24-hour breach hotline first. Most policies supply a breach coach, an attorney who assembles the forensic team and directs the response. Using the carrier’s panel keeps the costs covered and brings in people who handle these events each week. Put the hotline number and the policy number on paper inside your incident response plan, because your email may be down when you need them.

Does my small business need cyber insurance?

If you hold customer records, take card payments, depend on computers to operate, or move money by wire, the answer is yes. A single ransomware event at a small business often costs six figures between downtime and recovery. Insurance transfers part of that loss.

Insurance does not prevent anything. It pays after the damage, it excludes more than owners expect, and it gets cheaper and easier to buy when your controls are in place. Treat the application as a free checklist for your security program.

How do I prepare for the application or renewal?

  1. Start 60 to 90 days before renewal.
  2. Gather evidence: screenshots of multi-factor settings, backup test records, training completion reports, and your written policies.
  3. Close the gaps you find before you answer.
  4. Use a broker who places cyber coverage every week.
  5. Compare sublimits and exclusions across quotes. The lowest premium often hides the lowest ransomware and fraud limits.

Your next step

Pull out your current policy and search it for the words “cyber,” “data breach,” and “social engineering.” If you find exclusions or nothing at all, talk to a broker this month. Cerberus Cybersecurity helps small businesses get insurance-ready with assessments, written policies, and staff training. Contact us before your next renewal.