Cyber Insurance
Cyber insurance covers the financial consequences of a network security failure or data breach. It is written in two halves — first-party cover for the cost of responding to an incident, and third-party cover for liability to the people whose data was exposed.
Definition maintained by the InsurTool Editorial Team. Last reviewed .
Core Takeaways
- Split the policy in two: first-party cover for the cost of responding, third-party cover for liability to others.
- It is not a substitute for security. Conditions such as multifactor authentication and offline backups are claim prerequisites, not suggestions.
- Limits are usually an aggregate with small sublimits per head of cover — the ransomware sublimit is often a fraction of the headline figure.
- Other policies have been deliberately narrowed to exclude cyber, so there is no silent fallback.
What is Cyber Insurance?
In plain English: cyber insurance pays the bills a security incident generates — the investigators, the lawyers, the notifications, the lost trading days, and the lawsuits. It does not stop the incident, and it increasingly will not pay out if the basic controls it asked you to maintain were not in place.
The Two Halves
First-party: the cost of responding
| Head of cover | What it pays for |
|---|---|
| Forensic investigation | The specialist firm that determines what happened, what data was taken, and whether the attacker is still present |
| Breach counsel | Legal advice on notification duties, which vary by state and by sector, and privilege over the investigation |
| Notification | Printing, mailing, call centres, and the standing up of a notification website |
| Credit monitoring | Identity protection for affected individuals, often the largest single line item in a consumer breach |
| Business interruption | Lost income while systems are down, usually subject to a waiting period and calculated from financial records |
| Data restoration | Rebuilding systems and recovering data from backups |
| Cyber extortion | Ransom negotiation and, where lawful and approved, payment |
| Reputational response | Public relations and customer communication |
Third-party: the cost of being blamed
Network security liability responds when a third party alleges you failed to protect their data. Privacy liability responds to allegations that you mishandled personal information. Media liability responds to content-related claims such as defamation or copyright in material you published. All three are defence-costs-heavy: the legal bill for defending a claim frequently exceeds the settlement, and defence is usually inside the limit rather than in addition to it.
Why a Dedicated Policy Is Necessary
For years the exposure sat in a gap: general liability forms assumed tangible property and bodily injury, and property forms assumed physical damage. Whether a data breach was covered depended on wording never written for it, and courts reached different answers.
Insurers closed the gap from both directions. They added cyber insurance as a product, and they added exclusions to general liability, commercial property, crime, and even some professional liability forms to remove the ambiguity. The practical result is that the question is no longer “might my other policies cover this” but “which policy is going to, and is it this one”.
Underwriting Conditions Are Claim Conditions
Cyber policies are unusual in how directly the security questionnaire feeds the coverage. Common requirements include:
- Multifactor authentication on remote access, privileged accounts, and email
- Backups held offline or immutable, with restoration tested rather than assumed
- Endpoint detection and response on servers and workstations
- Patch management on a defined schedule, with evidence of it
- An incident response plan naming who to call and in what order
- Segregation of networks holding sensitive data
These appear as warranties or conditions precedent. A claim arising from a failure to maintain one can be reduced or declined, which means the security control is doing double duty: it reduces the chance of a loss and it protects the coverage if one happens anyway.
The Ransom Decision
Cover for cyber extortion does not settle whether to pay. Two constraints sit outside the policy:
The first is sanctions. Paying a ransom to a person or entity designated under US sanctions is prohibited, and the prohibition applies to the payer regardless of what the insurance policy provides. Insurers therefore require notification to, and usually approval from, the carrier and often counsel before any payment is made.
The second is that payment does not reliably end the incident. Attackers who are paid sometimes return, and stolen data is frequently sold or held for a second demand whether or not a payment was made. This is why many policies now fund negotiation, decryption tooling, and recovery from backups as alternatives to payment, and why the incident response plan matters more than the sublimit.
Common questions about cyber insurance
What is the difference between first-party and third-party cyber coverage?+
First-party coverage pays your own costs: forensic investigation, legal advice on notification duties, notifying affected individuals, credit monitoring, public relations, restoring data, and lost income while systems are down. Third-party coverage pays what you owe others: defence costs and damages when customers, partners, or regulators pursue you.
Does my general liability policy already cover this?+
Usually not, and where it might, the answer is narrowing. Commercial general liability forms were not drafted for data. Insurers responded by adding exclusions to general liability, property, and crime policies to remove any silent cyber exposure, which is precisely why a dedicated policy is needed rather than hoped for.
Does it cover ransomware payments?+
Many policies include cyber extortion cover, but the decision to pay is not purely a matter of coverage. Paying a ransom to a person or entity subject to US sanctions is prohibited regardless of what the policy says, and insurers increasingly require notification and approval before any payment. Some policies now fund negotiation and recovery instead of the payment itself.
What conditions does the insurer impose?+
Multifactor authentication on remote access, tested backups held offline, endpoint detection, patch management, and an incident response plan are common. Failing a condition can reduce or void a claim, so these are underwriting requirements to be read as commitments rather than recommendations.
How are limits structured?+
Usually as an aggregate limit for the policy period with much smaller sublimits for specific heads of cover — cyber extortion, notification costs, and regulatory defence are typically capped well below the aggregate. A headline limit of $5 million can contain a $250,000 ransomware sublimit.
Are small businesses expected to buy it?+
The underwriting question is not size but data. A business holding customer payment details, health information, or personal identifiers has the exposure whether it has five employees or five thousand, and attackers target smaller firms partly because their defences are weaker.
About this definition
Written and checked against the primary sources linked on this page by the InsurTool Editorial Team. Definitions describe how these terms are used in the United States; policy wording differs between insurers, and state law changes the meaning of some terms. Your own policy document is the authority for your coverage.
Found something wrong? Tell us — corrections are checked at the source and recorded. Read our editorial policy.