Cybersecurity

Decoding Cyber Insurance: What Policies Really Cover (and What They Don’t)

A cyber policy is not a safety net if the exclusions apply. What these policies actually cover, what voids them, and what to check before you renew.

Cyber insurance has become close to mandatory for small businesses — required by lenders, by clients, and in many cases by common sense. But a policy is only as good as its terms, and the gap between what business owners think they bought and what the policy actually pays is where the unpleasant surprises live.

Here is what these policies generally cover, what they generally do not, and the handful of things that will get a legitimate claim denied.

First-party versus third-party coverage

Every cyber policy splits into two halves, and you need both.

First-party coverage pays for your own losses: the forensic investigation to work out what happened, the cost of notifying affected individuals, credit monitoring, data restoration, business interruption while you are down, and — depending on the policy — ransom payment and negotiation.

Third-party coverage pays when someone else sues you or a regulator comes calling: legal defense, settlements, and regulatory fines where they are insurable.

A cheap policy that is heavy on first-party and thin on third-party looks fine until a class action arrives.

The coverage most businesses underestimate

Two line items deserve a closer read than they usually get.

Business interruption is often the largest real loss in a ransomware event, and it is frequently sublimited well below the headline policy limit. Check the waiting period too — many policies do not begin paying until you have been down eight, twelve, or twenty-four hours, and a practice that is back up in ten hours collects nothing.

Social engineering and funds transfer fraud — the wire that goes to the wrong account because someone impersonated a vendor — is very often excluded from the base policy and sold as a separate rider with a much lower limit. Given that business email compromise causes more direct financial loss to small businesses than ransomware does, this is worth confirming in writing.

What is typically excluded

Standard exclusions include prior known incidents — anything you were aware of before the policy started. Acts of war, which insurers have been broadening in the wake of state-sponsored attacks. Bodily injury and property damage, which belong to your other policies. Failure to maintain the security standards you attested to. And in many policies, unencrypted devices.

That last category is where good claims go bad.

The application is a warranty, not a questionnaire

This is the single most important thing to understand about cyber insurance today.

When you complete a renewal application, you are making representations about your controls: that MFA is enforced on all remote access and all email, that backups are tested and offline or immutable, that endpoint detection and response is deployed everywhere, that patching happens within a defined window, that staff receive security awareness training.

If those statements are not accurate at the time of the incident, the insurer can deny the claim — and after a breach, forensics will establish exactly which controls were in place. “We had MFA on most accounts” is a very different answer from the box you checked.

We have seen applications answered optimistically by someone in the office who genuinely did not know the technical state of the environment. That is an expensive way to find out.

Questions to ask before you sign

Ask what the sublimits are for ransomware, business interruption, and social engineering — not just the aggregate limit. Ask what the waiting period is and how it is measured. Ask whether you must use the insurer’s panel of forensic and legal vendors, and what happens if you call your own IT provider first. Ask whether the policy covers incidents at your vendors and cloud providers, since that is where a growing share of outages originate. And ask whether the retroactive date covers the period before the policy started, because dwell time in a breach is often measured in months.

Insurance is the last layer, not the first

A policy pays out after the damage. It does not restore the trust of a patient whose records were exposed, and it does not give you back the two weeks your team spent recovering.

The controls the insurer asks about are the same controls that prevent the incident in the first place. That overlap is not a coincidence — insurers are pricing risk with real claims data, and they now know exactly which measures work. Treat the application as a security roadmap.

If you have a renewal coming and you want the technical questions answered accurately, send us the application. We will tell you honestly what is true in your environment today and what needs to change before you can claim otherwise.

One accountable technology partner.

Tell us what's slowing your team down. We'll show you exactly how we'd fix it — no pressure, no jargon.

Book a Free Consultation
Book a Free Consultation