What does cyber insurance cover? Most policies pay for two things: your own costs after an incident (first-party coverage) and claims others bring against you (third-party coverage). The details live in the conditions, the exclusions and the answers you gave on the application, and those details decide whether a claim gets paid.
Consider a bookkeeper who gets an email that looks like it came from a long-time vendor, with new bank details for next week’s payment. The money goes out, the vendor never sees it, and the owner calls the insurance agent. That call is when many organizations learn whether their policy covers this kind of fraud, covers it only up to a small sublimit, or doesn’t cover it at all.
What does cyber insurance cover?
The FTC’s guidance for small businesses describes the usual coverage. Policies vary, so compare this list with your own declarations page.
| Coverage | Type | What it usually pays for |
|---|---|---|
| Incident response | First-party | Forensic investigators, crisis management and public relations |
| Legal and notification | First-party | A lawyer to work out your duties, customer notices, call center support and credit monitoring |
| Data recovery | First-party | Restoring lost or damaged data and systems |
| Business interruption | First-party | Lost income while systems are down |
| Cyber extortion | First-party | Ransomware negotiation and, where lawful and approved by the insurer, a ransom payment |
| Liability | Third-party | Lawsuits and settlements from customers or partners whose data was exposed |
| Regulatory | Third-party | Responding to regulators, and in some policies fines where the law allows them to be insured |
| Media liability | Third-party | Defamation or copyright claims tied to your online content |
Look for a 24/7 breach hotline and, if you can get it, “duty to defend” language, which means the insurer provides and manages your legal defense instead of reimbursing you later.
The exclusions and limits that surprise owners
The fine print matters as much as the coverage list. These are the gaps that catch small organizations most often.

- Funds transfer and social engineering fraud, the scenario above, is often covered only through an add-on with a much lower limit than the rest of the policy. Check this line first.
- State-backed attacks. Since March 31, 2023, Lloyd’s has required standalone cyber policies in its market to exclude losses from state-backed cyber attacks unless Lloyd’s agrees otherwise. Other insurers use their own war wording, so ask how yours defines and attributes these attacks.
- An attack that started before the policy did, or a problem you knew about and didn’t report.
- Security upgrades after a breach. Policies usually pay to put systems back the way they were.
- Customers you lose over the following year.
- Devices ruined by an attack, which may need a specific endorsement.
- Deliberate damage by an employee or contractor, depending on the wording.
$3.05 billion
lost to business email compromise in 2025, from 24,768 complaints (FBI Internet Crime Report 2025)
Four gaps insurers commonly flag
We fill out the security questionnaires for our clients when their policies come up, and insurers commonly flag the same four gaps:
- MFA that isn’t turned on everywhere, especially for email, remote access and admin accounts.
- No endpoint detection and response (EDR). Our post on what EDR is explains why insurers ask.
- Backups that aren’t offline or immutable, so ransomware can reach them. See our backup best practices.
- No security awareness training or phishing tests.
Broker Marsh publishes a longer list of key controls that insurers treat as minimum requirements, including email filtering, patching and replacing end-of-life systems, an incident response plan, logging and monitoring, and vendor risk management. Expect your application to ask about most of them.
Your answers on that application become part of the contract. In 2022, Travelers asked a court to rescind a policy after a ransomware attack, saying the insured had attested to using MFA and the statement was false. The two sides agreed to void the policy from day one, which left no coverage for that claim or any other. If you aren’t sure an answer is true, find out before you sign. Our cybersecurity controls are built to make those answers easy to verify.
Questions to ask your broker before you renew
- What are the limits and sublimits for ransomware, business interruption and funds transfer fraud?
- How long is the waiting period before business interruption coverage starts?
- Do we have to use the insurer’s panel of lawyers and forensic firms?
- Are regulatory fines covered where the law allows?
- Are breaches that start at our cloud providers or other vendors covered?
- Which security controls are conditions of coverage, and what happens if one lapses mid-term?
Have your broker and your IT provider review the policy together. The broker knows the policy language, and the IT side knows whether the controls you attested to are really in place.
When an incident happens
- Contain the damage by isolating affected devices, but don’t wipe or rebuild anything yet.
- Call the insurer’s breach hotline before hiring outside help or paying anyone. Many policies reimburse only vendors and costs the insurer approved.
- Preserve logs, emails and ransom notes for the forensic team and the adjuster.
- Report fraud to your bank right away and file a complaint at ic3.gov.
- Track your deadlines. Louisiana’s breach law requires notice to affected residents without unreasonable delay and no later than 60 days after discovery, and healthcare and financial firms have federal rules on top.
A written plan makes these steps routine. Our post on data breach response goes deeper, and a solid business continuity plan gets your systems back even if the claim takes months.
Limits deserve a look too. IBM’s 2026 Cost of a Data Breach Report puts the global average cost of a breach at $4.99 million. That figure comes mostly from large companies and won’t match a 20-person office, but forensics, legal advice, notification and downtime add up quickly, and a limit chosen years ago may not keep pace.
Don’t guess at the answers on a renewal questionnaire. Book an intro call and we’ll go through it with you. Healthcare, accounting, legal and other businesses with compliance requirements can see how our compliance services tie these controls to the rules you answer to.
FAQ
Frequently asked questions
What is cyber insurance?
Cyber insurance is a policy that pays for losses from cyber attacks and data breaches. Most policies cover your own costs after an incident, such as forensics, notification, data recovery and lost income, plus claims others bring against you. What a given policy pays depends on its conditions, its exclusions and the answers you gave on the application.
What does cyber insurance not cover?
Common gaps are funds transfer and social engineering fraud (often covered only by a lower-limit add-on), state-backed attacks, incidents that started before the policy, security upgrades after a breach, customers who leave and devices ruined by an attack. A false answer on the application can void the policy entirely.
What is cyber liability insurance?
Cyber liability is the third-party part of a cyber policy. It pays for lawsuits and settlements from customers or partners whose data was exposed, responses to regulators and, in some policies, media claims such as defamation. Most cyber policies pair it with first-party coverage for your own costs.
Sources: FTC: Cyber Insurance (Cybersecurity for Small Business); FBI IC3: 2025 Internet Crime Report; IBM: Cost of a Data Breach Report 2026; Clifford Chance: Lloyd’s cyber war exclusion (Market Bulletin Y5381), 2023; Marsh: Cyber resilience, 12 key controls; Insurance Journal: Travelers, policyholder agree to void cyber policy, 2022; Louisiana R.S. 51:3074, breach notification.




