Cyber Insurance: What Does It Really Protect?

Cyber insurance can support a business following a cyber incident, but policies, exclusions and security requirements vary. Here is what to check before buying or renewing.
Cyber insurance can provide valuable financial and specialist support following ransomware, data loss, business interruption, fraud or another serious cyber incident. However, buying a policy does not mean every cyber-related loss will automatically be covered.
Policies contain conditions, exclusions, limits and security requirements. The protection available depends on the wording purchased, the information provided during the application and whether the business continues to operate the security controls it declared.
The most useful question
It is not simply, “Do we have cyber insurance?” It is, “Do we understand what it covers, what we must maintain and what we need to do when an incident happens?”
What is cyber insurance?
Cyber insurance is intended to help an organisation manage some of the financial and operational consequences of a cyber incident. Depending on the policy, it may provide:
- Financial reimbursement
- Specialist incident-response support
- Forensic investigation
- Legal advice
- Data-breach support
- Public-relations assistance
- System-restoration support
- Business-interruption cover
- Liability protection
- Access to specialist negotiators, where legally and contractually permitted
Several points apply to almost every policy: policies vary considerably; cover depends on the wording; policy limits and sub-limits apply; excesses may apply; not every incident or cost is covered; and some support may require prior insurer approval. Cyber cover may also be included within another business policy — but businesses must check the actual extent of that cover rather than assuming it exists.
The key message
The policy wording — not the policy title — determines what protection the business has.
First-party and third-party cover
Most cyber policies group protection into two broad areas, and the distinction is worth understanding before any broker conversation.
| First-party cover | Third-party cover | |
|---|---|---|
| What it concerns | Direct losses and response costs suffered by the insured business | Claims or liabilities arising because customers, employees, partners or others were affected |
| Possible examples | Forensic investigation, legal advice, data restoration, system recovery, business interruption, additional operating costs, customer notification, crisis communications, cyber-extortion response where covered and lawful, certain cyber-fraud losses where explicitly included | Privacy claims, legal defence costs, claims relating to confidential information, regulatory investigation costs where insurable and covered, contractual or professional liability where specifically included |
Not every policy includes every item listed above, and whether regulatory penalties can be insured depends on the legal position and the policy — it should never be assumed.
What cyber insurance may cover
Subject to the policy wording, and within the applicable limits, a cyber policy may respond to areas such as:
- Ransomware response, where specifically included
- Malware incidents
- Data breaches and notification support
- Forensic investigation
- Restoration and recovery costs
- Business interruption, subject to waiting periods and limits
- Crisis management and communications
- Legal advice
- Certain fraud losses, where explicitly included
- Certain supplier-related incidents, where the wording extends to them
- Certain cloud-service interruptions, where specifically covered
- Third-party claims
Every item above is conditional. There is no universal coverage list — only the list in the policy your business actually holds.
What may not be covered?
Exclusions and limitations vary between insurers and policies. Examples worth reviewing in any wording include:
- Incidents known before the policy began
- Inaccurate or incomplete application answers
- Failure to maintain declared security controls
- Unsupported or obsolete systems
- Unencrypted devices or data where encryption was required
- Weak or absent multi-factor authentication where it was declared or required
- Voluntary shutdowns outside the policy wording
- Contractual liabilities not otherwise covered
- Losses below the excess or above the policy or sub-limit
- Certain payment-diversion or social-engineering fraud
- Infrastructure failure not caused by a covered cyber event
- Bodily injury or physical damage
- Acts involving sanctioned parties
- War, state-backed activity or systemic cyber-event exclusions
- Costs incurred without required insurer approval
- Reputational harm that cannot be quantified under the policy
Not all policies contain every exclusion above — which is precisely why the specific wording matters.
The key message
A business should understand the exclusions before an incident — not while trying to make a claim.
Why application answers must be accurate
Cyber-insurance applications and renewal forms may ask about multi-factor authentication, backups, encryption, security updates, endpoint protection, administrator accounts, remote access, incident-response plans, employee training, email security, unsupported software, cloud services, previous incidents, the types of data held, business continuity and supplier access.
These answers should be verified rather than assumed. If an application states that MFA protects all remote and administrator access, the business should confirm that this is genuinely true across every relevant account and system — not just the obvious ones.
In practice, application forms may be completed by a director, finance, an insurance broker, an office manager or an IT provider. Whoever fills in the form, ensuring the answers are accurate remains important — inaccurate declarations are a common route to disputes at claim time.
A simple rule
Do not answer an insurance question based on what everyone believes should be in place. Answer it based on what has been checked.
The security controls insurers may expect
Expectations vary according to business size, turnover, sector, the data handled, the systems used, claims history, risk profile, policy limits and the individual insurer. Controls commonly asked about include:
- Multi-factor authentication
- Endpoint protection
- Vulnerability and patch management
- Protected administrator accounts
- Secure remote access
- Encrypted backups
- Isolated or offline backups
- Restoration testing
- Supported software
- Staff awareness training
- Email security
- Incident-response planning
- Access reviews
- Logging and monitoring
- Business-continuity planning
Not every insurer requires all of these. But a control used to obtain cover must continue operating throughout the policy period where the policy requires it — switching MFA off in month three can matter as much as never having it.
Cyber insurance does not replace security
Insurance transfers some financial risk. It does not prevent an attack, install security updates, stop phishing, protect administrator accounts, restore data automatically, communicate with customers, run the business during an outage, make unsupported software safe or guarantee that every claim will be paid.
In one line
Insurance can help fund the response. It cannot run the security controls for you.
What happens during a claim?
- 1Recognise and contain the incident.
- 2Follow the organisation’s emergency plan.
- 3Contact the insurer or approved incident hotline promptly.
- 4Follow the policy’s notification and consent requirements.
- 5Preserve evidence and records.
- 6Use approved forensic, legal, recovery or communications specialists where required.
- 7Keep a record of decisions, costs and communications.
- 8Assess whether other notifications may be required, including customers, regulators, insurers or law enforcement.
- 9Continue regular communication with the insurer and response team.
- 10Complete a post-incident review.
Do not delay urgent safety or containment action while trying to locate policy documentation. However, businesses should avoid committing to major forensic, legal, recovery or ransom-related expenditure without contacting the insurer where prior approval is required.
The incident-response service may matter as much as the payout
A useful cyber policy may provide access to forensic investigators, specialist lawyers, data-breach advisers, recovery specialists, crisis-communication support, specialist negotiators, identity-monitoring services and claims coordinators.
This matters because, during a serious incident, the business may not know what happened, whether attackers still have access, what data was affected, whether systems are safe to restore, who must be informed, what evidence must be retained or what communications are appropriate.
Why the service matters
Access to the right expertise during the first few hours can be more useful than receiving reimbursement months later.
Business interruption
Business-interruption cover is one of the most commonly misunderstood parts of a cyber policy. Before relying on it, a business should understand the waiting period, the indemnity period, the definition of interruption, how lost income is calculated, whether increased operating costs are covered, whether supplier or cloud outages are included, whether voluntary shutdown is covered, the applicable limit, any sub-limit and the evidence required to support the loss.
For example, a policy may cover certain lost income after a qualifying cyber incident — but only after a waiting period and only within the defined indemnity period.
Social engineering and payment fraud
Business email compromise, invoice redirection, fraudulent payment instructions, impersonation and funds-transfer fraud may not always be covered by standard cyber wording. Some businesses may need specific social-engineering cover, crime cover, fidelity cover, funds-transfer fraud cover or endorsements and extensions. The final position depends on the actual policies held.
Worth remembering
Do not assume that every loss involving email is automatically a cyber-insurance claim.
Suppliers and cloud services
Many businesses depend on managed IT providers, cloud platforms, hosted applications, payment providers, website hosting, data centres, payroll providers and other outsourced services. It is worth checking whether the policy covers incidents affecting those suppliers — concepts to ask about include dependent business interruption, contingent business interruption, system-failure cover and any supplier-related exclusions.
The supply-chain point
Your business may stop even when your own systems were not the original target.
Practical business implications
Ownership
Assign responsibility for the insurance relationship, technical verification, policy renewal, incident notification, document storage and an annual review. Insurance that nobody owns tends to be insurance nobody has read.
Documentation
- Policy schedule and full wording
- Broker details and insurer emergency number
- Policy number
- Incident-response instructions
- The security controls declared to the insurer
- Application and renewal answers
- Endorsements, exclusions, excesses, limits and sub-limits
Testing
- Insurer contact details
- The incident-response plan
- Backup restoration
- Alternative communication
- Management escalation
- Decision-making responsibilities
Questions to Ask Your Broker or Insurer
- 1What events and losses does the policy cover?
- 2What are the principal exclusions?
- 3What is the policy limit?
- 4Which areas have separate sub-limits?
- 5What excesses and waiting periods apply?
- 6Does the policy cover business interruption?
- 7How is lost income calculated?
- 8Are cloud and technology-supplier outages covered?
- 9Is social-engineering or payment-diversion fraud included?
- 10Does the policy cover ransomware response?
- 11What restrictions apply to extortion-related costs?
- 12Does the policy include forensic and legal support?
- 13Which specialists must we use?
- 14Must we obtain approval before incurring costs?
- 15How quickly must an incident be reported?
- 16Is cover available for regulatory investigation or defence costs?
- 17Are state-backed or systemic cyber incidents excluded?
- 18What security controls must remain in place?
- 19What changes must we report during the policy period?
- 20What evidence would be required during a claim?
- 21Does another existing business policy already include or exclude cyber losses?
- 22Who should we contact outside normal working hours?
A broker can explain and arrange cover, but the business should still read the policy schedule, wording, endorsements and exclusions.
Questions to Ask Your IT Provider
- 1Can you verify the technical answers in our insurance application?
- 2Is MFA enabled for all administrator and remote-access accounts?
- 3Are any systems or users excluded from MFA?
- 4Which systems are unsupported or approaching end of support?
- 5How are security updates monitored?
- 6What endpoint protection is deployed?
- 7Which accounts have administrative access?
- 8Are our backups encrypted?
- 9Are backups separated from the production environment?
- 10When was restoration last tested?
- 11How long would full recovery take?
- 12Is Microsoft 365 or other cloud data backed up separately?
- 13How is supplier access controlled and logged?
- 14Do we have an incident-response plan?
- 15Who should contact the insurer during an incident?
- 16Can you support an insurer-appointed forensic team?
- 17Which security-control changes must be reported before policy renewal?
- 18Can you provide written evidence of the controls we have declared?
The IT provider should confirm technical facts. It should not provide regulated insurance advice unless authorised and qualified to do so.
Is Your Business Ready to Buy or Renew Cyber Insurance?
- We know whether cyber cover already exists within another policy.
- We understand the organisation’s main cyber risks.
- A suitable broker or insurer has explained the available cover.
- We have read the policy schedule and key exclusions.
- We understand limits, sub-limits, excesses and waiting periods.
- Application answers have been checked with appropriate technical evidence.
- MFA protects relevant administrator and remote-access accounts.
- Unsupported systems have been identified.
- Security updates are monitored.
- Endpoint protection is active and monitored.
- Backups include critical on-premises and cloud data.
- Backups are encrypted and appropriately isolated.
- Restoration has been tested.
- We have a documented incident-response plan.
- We know the insurer’s emergency contact process.
- Key policy documents are available during an outage.
- We know whether prior approval is required before appointing specialists.
- Social-engineering and payment-fraud cover has been checked separately.
- Supplier and cloud-service incidents have been considered.
- Policy conditions are reviewed when technology changes.
- Cyber controls are checked throughout the policy period, not only at renewal.
Completing this checklist does not confirm that a particular policy is suitable or that a future claim will be covered.
The IT Club View
Cyber insurance is worthwhile for many businesses, because a serious cyber incident can require expertise and expenditure that a small organisation could not quickly assemble on its own. However, the insurance must be treated as part of cyber resilience rather than a replacement for it.
The most common business mistake is to view the policy as a document that can be filed away until an incident occurs. A better approach is to connect the policy to the organisation’s security controls, the IT provider, the incident-response plan, backups, recovery testing and management decision-making.
Cyber insurance works best when the insurer, broker, business and IT provider all understand their responsibilities before anything goes wrong. The goal is not simply to obtain a certificate of insurance. It is to ensure that the policy, technical controls and response plan genuinely work together.
The Operational Heartbeat
Insurance conditions and technical controls can drift after the policy starts. A recurring review should check MFA coverage, administrator accounts, backup success, restore testing, endpoint-protection coverage, unsupported systems, patching, remote access, cloud backup, leaver accounts, supplier access, policy contact details, the controls declared to the insurer and any material technology changes.
Cyber insurance needs an operational heartbeat: the controls declared to the insurer should be checked, failures acted upon and evidence retained throughout the policy period.
Administrator Technical Note
Practical evidence an IT provider or administrator may need to produce when supporting a cyber-insurance application, renewal or claim.
Identity and access
- MFA coverage report
- Administrator-account inventory
- Remote-access methods
- Conditional Access configuration
- Privileged-account separation
- Emergency-access controls
- Leaver-account process
- Access-review records
Endpoint and server security
- Endpoint-protection coverage
- EDR or antivirus status
- Supported operating-system inventory
- Patch-compliance reports
- Vulnerability-management records
- Device-encryption status
- Local-administrator controls
- Mobile-device controls
Email and cloud
- Anti-phishing configuration
- SPF, DKIM and DMARC status
- Microsoft 365 or cloud-security settings
- Cloud-backup coverage
- Administrator audit logs
- Third-party application access
- Mailbox-forwarding controls
Backup and recovery
- Backup scope and retention
- Encryption and access controls
- Immutable or isolated copies
- SaaS backup
- Failure monitoring
- Restoration-test dates
- Measured recovery times
- Documented RPO and RTO where appropriate
Network and remote access
- Firewall support status
- VPN or zero-trust access
- MFA for remote access
- Exposed services
- Network segmentation
- Remote-management platform controls
- Logging
- Firmware maintenance
Incident response
- Insurer emergency contact
- Incident escalation
- Evidence-preservation procedure
- Log-retention arrangements
- Alternative communications
- Forensic-support process
- Breach-assessment responsibilities
- Recovery authorisation
- Post-incident review
A staged insurance-verification process
- 1Collect — obtain the insurer or broker’s questions before answering.
- 2Assign — identify which questions belong to management, finance, legal, HR and IT.
- 3Verify — check technical answers using current evidence.
- 4Remediate — address material weaknesses before submission where practical.
- 5Document — retain the answers, evidence and assumptions used.
- 6Review — check the issued policy against the requested cover and disclosed controls.
- 7Monitor — confirm required controls continue operating.
- 8Renew — revalidate all answers rather than copying the previous year’s form.
Do not certify that a control is fully deployed based only on the intended policy or product licence. Confirm its actual configuration, coverage and operation.
This article provides general technology and cyber-security information, not insurance, legal or financial advice. Insurance advice should be obtained from an appropriately authorised insurer or broker.
Plain-English Takeaway
Cyber insurance can provide valuable financial and specialist support after a serious incident, but cover depends on the policy wording, the accuracy of the application and the security controls the business maintains. Read the exclusions, verify your answers, keep the required controls operating and know who to contact before an emergency.
Need the practical steps?
A short, instruction-led version of this topic is available in the Knowledge Centre.
View the Knowledge Centre GuideRelated Articles
Passkeys: How to Protect Your Microsoft and Google Accounts
Passkeys let a trusted device approve sign-in with a fingerprint, face or PIN instead of a typed password. Here is how to set one up safely on a Microsoft or Google account — and what to check first.
Read articleThe UK Cyber Security and Resilience Bill: Could It Affect Your Business?
The proposed Cyber Security and Resilience Bill would strengthen UK cyber rules and bring more technology suppliers into scope. Here is what SMEs should review now.
Read articleMicrosoft Is Making Passkeys the Default: Is Your Business Ready?
Microsoft is making passkeys the default Entra authentication experience. Learn what this means for MFA, SMS authentication and business security.
Read article