What Is Cyber Insurance?

Also called: Cyber liability insurance, Cybersecurity insurance

Related problems: Our cyber insurance renewal questionnaire asks about controls we don't have; Premiums went up and coverage went down at renewal; Not sure what our policy would actually pay for after a ransomware attack; Who do we call first if we get breached

Cyber insurance is an insurance policy that pays some of the costs and liability that follow a cyberattack, data breach or similar incident. Typical policies combine first-party coverage, for your own costs such as investigation, recovery and lost income, with third-party coverage, for claims made against you by customers, partners or others. What a specific policy covers, and how much, depends heavily on its wording, limits and exclusions.

At a glance

  • Coverage commonly includes incident response, forensics, legal advice, notification, data restoration, business interruption and liability claims, each with its own limits.
  • Underwriting has tightened: insurers often ask detailed questions about security controls before quoting.
  • Many policies route you to a panel of approved breach lawyers and response firms, and expect prompt notice of an incident.
  • Exclusions, sublimits and waiting periods decide what you actually recover, so the wording matters more than the headline limit.
  • Insurance transfers part of the financial risk; it does not prevent incidents or restore systems by itself.

What problem it solves

A serious incident is expensive in ways that are hard to budget for. Forensic investigators, outside counsel, notification and credit monitoring for affected people, overtime, system rebuilds and lost revenue during downtime can add up quickly, and lawsuits or regulatory inquiries may follow. Few mid-sized companies hold reserves for that kind of shock.

Cyber insurance moves part of that cost to an insurer in exchange for a premium. Many policies also provide something just as useful in the first hours: a hotline and a ready-made team of breach counsel and responders, so you are not choosing strangers in the middle of a crisis.

How it works

Application and underwriting. You complete an application, often a detailed questionnaire about your security. Common topics include multi-factor authentication (MFA), endpoint detection and response (EDR), offline or immutable backups, patching, privileged access, email security and training. Some insurers also scan your internet-facing systems. Answers need to be accurate: misstatements can put a claim at risk.

Policy structure. A policy has an overall limit, a retention (deductible) and often separate sublimits for items such as ransom payments, funds transfer fraud or regulatory matters. Business interruption cover usually starts only after a waiting period. Exclusions vary; ask about war and state-sponsored attacks, known unpatched vulnerabilities, prior incidents and contractual liability.

When something happens. You notify the insurer or its hotline as the policy requires. The insurer typically assigns breach counsel, who brings in forensic and incident response firms, often from its panel. Costs are reimbursed or paid directly according to the policy terms.

Renewal. Each year the questions, price and terms can change. Improvements you make in between, such as rolling out MFA or adding 24/7 monitoring, are worth documenting for the renewal.

When it matters for buyers

  • At renewal time. The questionnaire is often the first time leadership sees which controls are missing, so start it early enough to fix gaps before the policy expires.
  • When choosing security services. Insurers frequently ask about EDR and around-the-clock monitoring, which is one reason companies buy managed detection and response (MDR).
  • When signing an incident response retainer. Check that the firm is acceptable to your insurer, or you may pay twice.
  • After a peer is hit. Boards ask whether the company is covered and for how much; a risk assessment helps size the limit.
  • When customers require it. Some contracts specify minimum cyber coverage for suppliers.

Our incident response overview covers how to line up response help that works with your policy.

Questions to ask vendors

Most of these are for your insurance broker, and some for your security providers:

  • What exactly is covered, and what are the sublimits for ransomware, business interruption and funds transfer fraud?
  • What are the main exclusions, and what would cause a claim to be denied?
  • Which security controls are you assuming we have, and what happens if one fails during an incident?
  • Must we use your panel firms, and can our existing incident response provider be approved in advance?
  • How quickly must we notify you, and through which channel?
  • How is business interruption loss calculated, and what is the waiting period?
  • For security providers: can you document the controls the insurer asks about, in a form we can attach to the application?

How it differs from an incident response retainer

An incident response retainer is a contract with a security firm that puts investigators on call and sets response times and rates in advance. It buys people and speed. Cyber insurance buys financial protection: it reimburses or pays for covered costs, including response work, up to the policy’s limits. Many companies have both, and the important step is making sure they fit together, so that the retainer firm is acceptable to the insurer and the first call in an incident is clear. Neither replaces the security controls, such as MFA, EDR and tested backups, that reduce the chance of needing either one.

Frequently Asked Questions

What does cyber insurance usually cover?
It depends on the policy, but many cover incident response and forensics, legal advice, notifying affected people, restoring data, lost income from downtime, extortion demands and claims from third parties. Each item can have its own sublimit, deductible and exclusions, so read the policy rather than the summary.
Why are insurers asking about MFA, EDR and backups?
Because claims data has shown that these controls reduce the chance and size of losses. Many insurers ask about multi-factor authentication, endpoint protection, backups kept separate from the network, patching and security training, and the answers can affect whether you are offered coverage and at what price.
Can we use our own incident response firm?
Sometimes. Many policies expect you to use the insurer's approved panel of breach lawyers and forensic firms, or to get approval first, or costs may not be covered. If you already have a retainer with a firm you trust, ask the insurer before an incident whether it can be used.
Does cyber insurance pay ransoms?
Some policies cover extortion payments, subject to limits, insurer consent and the law. Paying can be restricted or prohibited in some circumstances, for example where the attacker is sanctioned, and rules vary by country. Treat it as a question for your broker and counsel, not a plan.
Does our general liability policy already cover cyber incidents?
Often not, or only narrowly. Many general and property policies now exclude or limit cyber losses. Ask your broker to confirm in writing what each existing policy covers and where a standalone cyber policy fills the gap.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.