Cyber insurance can transfer part of the financial impact of a covered incident, but it cannot replace basic security. A policy is most useful when the business knows what systems it has, how it backs them up and who will act during an incident.
What cyber policies may cover
Depending on the contract, cover can include incident-response specialists, forensic investigation, data-restoration costs, business interruption, notification expenses, third-party liability and certain extortion-related costs. Every one of those sections has definitions, limits and conditions.
Security answers matter
Proposal forms may ask about multi-factor authentication, backups, endpoint protection, privileged access, patching or employee training. Answer accurately. If your controls change materially, keep a record and ask the insurer or broker whether the change needs to be notified.
Ransomware is not a single clause
Do not assume “ransomware cover” means every payment or loss is reimbursable. Sanctions law, consent requirements, sub-limits, security warranties and incident-response procedures may all affect the claim. Your first call in a serious incident may need to be to the insurer’s approved response line before engaging outside vendors.
Business interruption needs careful reading
Check the waiting period, how lost income is calculated, maximum indemnity period and whether outages at cloud or outsourced providers are included. A short outage may fall entirely within the waiting period.
Third-party risk
If your business stores customer data or provides technology services, third-party claims can be as important as your own recovery costs. Check privacy liability, network security liability and contractual exclusions relevant to your business model.
Use insurance to improve the incident plan
Save the insurer’s breach hotline and panel-provider rules in the incident-response plan. Run a tabletop exercise: who has authority to isolate systems, contact legal counsel, notify customers and speak to the insurer?
Minimum security before shopping for cover
- Multi-factor authentication on critical accounts
- Tested backups with at least one protected/offline copy
- Supported software and timely patching
- Restricted administrator privileges
- Basic phishing and payment-change verification procedures
- Documented incident contacts
Map the business loss before buying a cyber policy
List the events that could materially hurt the business: ransomware downtime, data restoration, customer notification, legal response, third-party claims, payment diversion or incident-response costs. Then map each event to the proposed policy wording. A policy that sounds broad in marketing may divide these costs across separate insuring clauses, sub-limits or exclusions.
Security controls can be part of insurability
Insurers may ask about backups, multi-factor authentication, endpoint protection, patching, access controls and incident-response practices. Answer accurately. If the application says MFA is deployed everywhere but it is not, that mismatch can become important during underwriting or a claim. Use the insurance application as a prompt to identify security gaps rather than treating it as a formality.
Insurance is not a replacement for incident response
Keep offline or otherwise resilient backups, restrict privileged access, test restoration, maintain vendor contacts and know who will make decisions during an incident. CERT-In and other official guidance can inform security preparation. During an actual event, follow the policy’s notification requirements and obtain approval before incurring costs where the wording requires it.
Ask about vendor and social-engineering losses specifically
Business email compromise, payment-redirection fraud and cloud/vendor incidents are common sources of confusion because different policies may treat them differently. Ask the insurer or broker to point to the exact clause rather than relying on a verbal statement that “cyber fraud is covered.”
Cyber cover is a specialised commercial contract. This guide is educational and does not recommend a particular insurer, limit or security standard.
Sources and verification
Insurance rules and product terms change. These official sources are the starting point for checking the current position before you act.