Cyber insurance is an insurance policy that pays some of the costs and liability that follow a cyberattack, data breach or similar incident. Typical policies combine first-party coverage, for your own costs such as investigation, recovery and lost income, with third-party coverage, for claims made against you by customers, partners or others. What a specific policy covers, and how much, depends heavily on its wording, limits and exclusions.
At a glance
- Coverage commonly includes incident response, forensics, legal advice, notification, data restoration, business interruption and liability claims, each with its own limits.
- Underwriting has tightened: insurers often ask detailed questions about security controls before quoting.
- Many policies route you to a panel of approved breach lawyers and response firms, and expect prompt notice of an incident.
- Exclusions, sublimits and waiting periods decide what you actually recover, so the wording matters more than the headline limit.
- Insurance transfers part of the financial risk; it does not prevent incidents or restore systems by itself.
What problem it solves
A serious incident is expensive in ways that are hard to budget for. Forensic investigators, outside counsel, notification and credit monitoring for affected people, overtime, system rebuilds and lost revenue during downtime can add up quickly, and lawsuits or regulatory inquiries may follow. Few mid-sized companies hold reserves for that kind of shock.
Cyber insurance moves part of that cost to an insurer in exchange for a premium. Many policies also provide something just as useful in the first hours: a hotline and a ready-made team of breach counsel and responders, so you are not choosing strangers in the middle of a crisis.
How it works
Application and underwriting. You complete an application, often a detailed questionnaire about your security. Common topics include multi-factor authentication (MFA), endpoint detection and response (EDR), offline or immutable backups, patching, privileged access, email security and training. Some insurers also scan your internet-facing systems. Answers need to be accurate: misstatements can put a claim at risk.
Policy structure. A policy has an overall limit, a retention (deductible) and often separate sublimits for items such as ransom payments, funds transfer fraud or regulatory matters. Business interruption cover usually starts only after a waiting period. Exclusions vary; ask about war and state-sponsored attacks, known unpatched vulnerabilities, prior incidents and contractual liability.
When something happens. You notify the insurer or its hotline as the policy requires. The insurer typically assigns breach counsel, who brings in forensic and incident response firms, often from its panel. Costs are reimbursed or paid directly according to the policy terms.
Renewal. Each year the questions, price and terms can change. Improvements you make in between, such as rolling out MFA or adding 24/7 monitoring, are worth documenting for the renewal.
When it matters for buyers
- At renewal time. The questionnaire is often the first time leadership sees which controls are missing, so start it early enough to fix gaps before the policy expires.
- When choosing security services. Insurers frequently ask about EDR and around-the-clock monitoring, which is one reason companies buy managed detection and response (MDR).
- When signing an incident response retainer. Check that the firm is acceptable to your insurer, or you may pay twice.
- After a peer is hit. Boards ask whether the company is covered and for how much; a risk assessment helps size the limit.
- When customers require it. Some contracts specify minimum cyber coverage for suppliers.
Our incident response overview covers how to line up response help that works with your policy.
Questions to ask vendors
Most of these are for your insurance broker, and some for your security providers:
- What exactly is covered, and what are the sublimits for ransomware, business interruption and funds transfer fraud?
- What are the main exclusions, and what would cause a claim to be denied?
- Which security controls are you assuming we have, and what happens if one fails during an incident?
- Must we use your panel firms, and can our existing incident response provider be approved in advance?
- How quickly must we notify you, and through which channel?
- How is business interruption loss calculated, and what is the waiting period?
- For security providers: can you document the controls the insurer asks about, in a form we can attach to the application?
How it differs from an incident response retainer
An incident response retainer is a contract with a security firm that puts investigators on call and sets response times and rates in advance. It buys people and speed. Cyber insurance buys financial protection: it reimburses or pays for covered costs, including response work, up to the policy’s limits. Many companies have both, and the important step is making sure they fit together, so that the retainer firm is acceptable to the insurer and the first call in an incident is clear. Neither replaces the security controls, such as MFA, EDR and tested backups, that reduce the chance of needing either one.
