Cyber insurance can help businesses pay certain costs arising from data breaches, ransomware, network attacks, cyber-related business interruption, data recovery, regulatory inquiries, and liability claims. Coverage can include both the company’s own losses and claims brought by customers or other third parties. Policies are highly customizable, however, so coverage for ransom payments, fraud, vendors, regulatory penalties, and other losses depends on the policy’s wording, limits, exclusions, security requirements, and applicable law.
Key Takeaways
- Cyber insurance can cover both first-party and third-party losses. First-party protection focuses on the insured business’s own response and recovery costs, while third-party coverage can address liability claims.
- Data breaches and ransomware can create several types of expense. Forensic investigation, legal counsel, customer notification, data restoration, business interruption, crisis management, and cyber extortion are examples of costs that may be insured.
- Cyber policies are not standardized. NAIC notes that cyber insurance is highly customized, making exclusions, definitions, sublimits, waiting periods, and endorsements especially important.
- Traditional business insurance may leave cyber gaps. NAIC states that most commercial property and general liability policies do not cover cyber risks.
- Cyber insurance does not replace cybersecurity. Businesses should still maintain security controls, backups, employee training, vendor oversight, and incident-response plans.
What Is Cyber Insurance?
Cyber insurance is commercial insurance designed to address specified financial losses associated with cyber incidents and privacy or network-security events. The Federal Trade Commission describes cyber insurance as one option businesses can use to protect against losses resulting from cyberattacks.
Potential incidents can include network breaches, theft or exposure of personal information, ransomware, attacks involving information held by vendors, and other events covered by the policy. Cyber coverage may also provide access to services that help a company investigate and respond quickly after an incident.
Cyber insurance should not be treated as one standardized policy. NAIC describes commercial cyber policies as highly customized. Two policies carrying the same general label may therefore cover different incidents, expenses, technologies, vendors, geographic areas, and liability exposures.
The policy wording matters more than the label. Businesses should review covered events, definitions, exclusions, waiting periods, sublimits, security conditions, and incident-reporting requirements rather than assuming every cyber policy provides the same protection.
First-Party vs. Third-Party Cyber Insurance
A useful way to understand cyber insurance is to separate first-party coverage from third-party coverage. Many businesses may need elements of both.
| Coverage Type | Who or What It Generally Protects | Examples of Potential Covered Costs |
|---|---|---|
| First-party | The insured business’s own data, systems, operations, and incident-response expenses | Forensics, data restoration, notification, business interruption, crisis management, cyber extortion, and specified legal expenses |
| Third-party | Liability to customers, clients, vendors, or other parties alleging harm | Defense expenses, settlements, judgments, regulatory-response costs, and other covered liability expenses |
The FTC advises businesses considering cyber insurance to discuss whether they need first-party coverage, third-party coverage, or both. A company that stores sensitive customer information, depends heavily on computer systems, or provides digital services may have several exposures at the same time.
How Cyber Insurance Can Help After a Data Breach
A data breach can create costs long before a liability lawsuit reaches court. A business may need to identify how attackers gained access, determine which systems and records were affected, obtain legal advice, communicate with affected people, restore systems, and manage business disruption.
The FTC identifies several expenses that first-party cyber insurance may cover, subject to the contract:
- Legal counsel related to notification and regulatory obligations.
- Forensic investigation of the breach.
- Recovery or replacement of lost or stolen data.
- Notification and call-center services for affected individuals.
- Crisis-management and public-relations expenses.
- Covered lost income from business interruption.
- Certain cyber extortion or fraud-related expenses when included by the policy.
The FTC’s breach-response guidance also emphasizes that businesses should quickly secure operations, mobilize appropriate experts, investigate the incident, consult legal counsel where appropriate, and determine which people or organizations may need notification.
Incident-response services can be an important part of the policy. The FTC recommends checking whether a cyber insurer offers a breach hotline available at all times. Review the policy’s reporting instructions before an incident so employees know whom to contact.
How Cyber Insurance Can Cover Business Interruption
A cyberattack can prevent a business from accessing software, customer records, websites, payment systems, production technology, or other digital resources needed for operations. Cyber business-interruption coverage may respond to specified income losses and expenses when an eligible cyber event causes a covered interruption.
This is different from assuming an ordinary commercial property policy’s business-income coverage applies. Traditional business-interruption coverage is commonly connected to covered physical property damage, while cyber interruption can involve network or system events without traditional physical damage.
Businesses comparing cyber interruption coverage should examine:
- Which cyber events trigger coverage.
- Whether a waiting period applies.
- How covered income loss is calculated.
- The maximum period or amount covered.
- Whether extra expenses incurred to continue operations can qualify.
- Whether outages involving outside technology or service providers are included.
Does Cyber Insurance Cover Ransomware?
Cyber insurance may cover certain ransomware-related losses, but coverage cannot be assumed. NAIC guidance notes that many cyber policies cover ransom payments, extortion-related expenses, and repair costs, while also emphasizing that coverage may require prior notification and security controls.
A ransomware incident can create several separate insurance issues, including:
- Forensic investigation.
- System restoration.
- Data restoration.
- Business interruption.
- Cyber extortion response.
- Legal, notification, or liability expenses if sensitive information was also accessed or exposed.
Do not pay a ransom without coordinating with the appropriate professionals and insurer. Government authorities discourage ransom payments because payment does not guarantee data recovery. Insurance coverage can also depend on notice, consent, legal restrictions, policy conditions, and use of approved response resources.
How Third-Party Cyber Liability Protects a Business
A cyber event may harm people or organizations outside the insured company. Customers can allege that personal information was inadequately protected, clients can claim a security failure caused financial harm, or regulators may investigate whether applicable obligations were satisfied.
According to FTC guidance, third-party cyber coverage can include, depending on the policy:
- Claims and settlement expenses related to disputes or lawsuits.
- Payments associated with affected consumers when covered.
- Litigation expenses.
- Costs of responding to regulatory inquiries.
- Covered settlements, damages, or judgments.
- Other specified liability costs included in the policy.
Businesses should also determine how defense costs affect the available liability limit and whether the insurer has a duty to defend eligible claims. The FTC specifically suggests looking for duty-to-defend wording when evaluating a cyber policy.
Can Cyber Insurance Cover Incidents Involving Vendors?
Modern businesses often rely on cloud providers, payment processors, software companies, payroll platforms, data-storage providers, and other outside vendors. A security event affecting one of those organizations can still disrupt your operations or expose information for which your business has responsibilities.
FTC cyber-insurance guidance recommends checking for protection involving cyberattacks on data held by vendors and other third parties. The exact scope can vary substantially, however.
When vendor dependence is significant, review whether the policy addresses:
- Data stored or processed by third parties.
- Business interruption caused by specified outside providers.
- Definitions of covered service providers or dependent businesses.
- Separate limits or sublimits applying to dependent-system losses.
- Contractual or notification requirements involving vendors.
Cyber Insurance Coverage at a Glance
| Cyber Exposure | Coverage That May Respond | Important Policy Question |
|---|---|---|
| Data breach | Breach response, forensics, notification, legal expenses, and privacy liability | Which types of data and privacy events qualify? |
| Ransomware | Cyber extortion, restoration, forensics, and interruption coverage where included | What notice, consent, and security requirements apply? |
| Network shutdown | Cyber business interruption | What waiting period and loss-calculation rules apply? |
| Customer lawsuit | Privacy or network-security liability | Are defense costs inside or outside the limit? |
| Vendor cyber incident | Dependent-system or third-party-related cyber coverage where included | Which vendors and services qualify? |
| Regulatory inquiry | Specified regulatory defense or response coverage | Which investigations, penalties, or other amounts are insurable and covered? |
What Cyber Insurance May Not Cover
Exclusions vary widely, so businesses should not rely on a generic list as a substitute for reading the policy. A loss can also fall outside coverage because it does not meet a definition, exceeds a sublimit, occurs outside the covered period, or involves a security representation or policy condition that becomes relevant to the claim.
Areas that deserve careful review can include:
- Events known before the policy began.
- Contractual liability beyond what the policy covers.
- Certain bodily injury or physical property damage claims.
- Losses falling under fraud, funds-transfer, or crime exclusions unless appropriately covered or endorsed.
- Cyber events involving vendors that do not meet the policy’s definition of a covered provider.
- Amounts exceeding cyber extortion, interruption, restoration, or other sublimits.
- Events outside the policy’s geographic or jurisdictional scope.
- Losses affected by exclusions or policy conditions relating to cybersecurity practices.
Regulatory fines and penalties require special attention. Even when a policy references them, coverage can depend on the specific wording and whether the amount is legally insurable in the applicable jurisdiction.
Why General Liability or a BOP May Not Be Enough
A Business Owners Policy and commercial general liability insurance can address important property and liability exposures, but they should not automatically be treated as substitutes for dedicated cyber coverage.
NAIC states that most commercial property and general liability policies do not cover cyber risks. A business relying heavily on digital systems or holding sensitive information should therefore identify exactly what its existing policies cover before assuming a separate cyber policy is unnecessary.
Some insurers offer cyber endorsements to package policies, while others offer stand-alone cyber insurance. A business should compare the scope and limits rather than assuming an endorsement provides the same breadth as a stand-alone product.
Who Should Consider Cyber Insurance?
Cyber risk is not limited to technology companies. FTC and NAIC guidance emphasize that businesses of different sizes can be cyberattack targets. A company may have meaningful cyber exposure even if technology is not the product it sells.
Cyber insurance may deserve particular consideration if a business:
- Stores customer or employee personal information.
- Processes payments electronically.
- Depends on cloud platforms or outside technology vendors.
- Would lose substantial revenue if computer systems became unavailable.
- Maintains confidential business or client information.
- Provides online services or operates an e-commerce business.
- Faces contractual requirements for cyber or privacy coverage.
- Would need outside legal, forensic, notification, or public-relations assistance after a breach.
Cybersecurity Controls Can Affect Insurance
Cyber insurance works alongside cybersecurity rather than replacing it. The FTC recommends that businesses maintain basic security practices such as regular software updates, backups, employee training, access controls, multi-factor authentication where appropriate, vendor-security practices, and incident-response planning.
Cyber insurers may ask detailed questions about security controls during underwriting. Answers to those questions should be accurate. A company should not state that a control is implemented across its organization when the actual configuration or practice is different.
NAIC ransomware guidance also notes that coverage can require robust security controls and prior notification. Businesses should therefore treat cybersecurity practices as part of both loss prevention and insurance management.
Keep underwriting answers current and supportable. Cybersecurity changes quickly. Review controls at renewal and tell the insurer about material changes when required by the policy or application process.
How to Choose Cyber Insurance for a Business
1. Identify Your Most Important Cyber Risks
List the data, systems, vendors, applications, and revenue-producing operations the business depends on. Consider what would happen if each became unavailable, corrupted, stolen, or publicly exposed.
2. Compare First-Party and Third-Party Coverage
Make sure the quote addresses the company’s own recovery costs as well as liability to outside parties where those exposures matter. One side of the coverage should not be assumed to include the other.
3. Review Sublimits
A policy can have a large overall limit while applying smaller limits to particular losses such as cyber extortion, business interruption, restoration, or certain vendor-related events. Compare these sublimits with realistic exposure.
4. Check Incident-Response Resources
Review whether the insurer provides access to breach counsel, forensic specialists, notification vendors, crisis-management professionals, or other response resources and whether using approved vendors is required for coverage.
5. Review Vendor and Cloud Exposure
If a business depends on outside technology providers, determine how the policy treats outages and breaches involving them. Check the definition of covered vendors rather than assuming every provider qualifies.
6. Compare Defense Provisions and Other Insurance
FTC guidance suggests checking whether the insurer has a duty to defend eligible lawsuits or regulatory investigations and how cyber coverage interacts with other insurance. Overlapping policies can contain provisions determining which coverage responds first.
7. Read the Application as Carefully as the Policy
Cyber applications can ask detailed questions about backups, authentication, access controls, patching, employee training, vendors, data, and past incidents. Verify the answers with the people responsible for the company’s technology rather than guessing.
What to Do Before a Cyber Incident Happens
The worst time to learn how a cyber policy works is during an active attack. Incorporate insurance into the company’s incident-response planning before a loss.
- Save the policy and insurer’s emergency contact information somewhere accessible during a system outage.
- Identify who within the company has authority to notify the insurer.
- Understand when notice is required.
- Determine whether insurer consent is required before hiring forensic, legal, or restoration vendors.
- Maintain secure backups and periodically test restoration procedures.
- Train employees to recognize common attack methods.
- Review access controls and authentication practices.
- Maintain an incident-response, disaster-recovery, and business-continuity plan appropriate to the organization.
- Review important vendors and the cybersecurity risks they create.
Common Cyber Insurance Mistakes
- Assuming general liability covers cyber incidents. Traditional commercial policies can contain significant cyber gaps.
- Buying by total limit alone. Important coverage sections may have much smaller sublimits.
- Ignoring vendor risk. A business can be disrupted or exposed even when the attack occurs outside its own network.
- Assuming ransomware is automatically covered. Extortion coverage, consent requirements, exclusions, and security conditions vary.
- Providing inaccurate security information. Cyber underwriting questions should reflect actual company practices.
- Waiting until an attack to read the notification requirements. Late or improper notice can create avoidable coverage disputes.
- Treating insurance as a substitute for security controls. Prevention, detection, response, and recovery planning remain necessary.
- Failing to review the policy as technology changes. New software, vendors, locations, data, or services can change the company’s cyber exposure.
Cyber Insurance Review Checklist
- Identify sensitive customer, employee, and business data.
- Estimate how a major system outage would affect revenue and operations.
- Review first-party breach-response and restoration coverage.
- Review third-party privacy and network-security liability coverage.
- Check ransomware and cyber-extortion terms.
- Review cyber business-interruption coverage and waiting periods.
- Check vendor and dependent-system coverage.
- Compare overall limits with applicable sublimits.
- Review defense arrangements and regulatory-response coverage.
- Confirm geographic and jurisdictional scope.
- Understand notice, consent, and approved-vendor procedures.
- Verify the cybersecurity information submitted to the insurer.
- Update coverage as technology, vendors, data, and operations change.
Frequently Asked Questions
The Bottom Line
Cyber insurance can protect a business from several financial consequences of a covered cyber event. Depending on the policy, protection can include forensic investigation, data recovery, breach notification, business interruption, cyber extortion response, legal expenses, and liability claims brought by customers or other parties.
The biggest limitation is that cyber insurance is highly customized. A large policy limit does not guarantee that every cyber loss is covered, and important sections may have separate sublimits, waiting periods, exclusions, consent provisions, security requirements, or definitions affecting a claim.
Before buying or renewing coverage, map the policy to the company’s actual data, systems, vendors, revenue dependencies, and incident-response plan. Review cybersecurity controls at the same time because insurance works best as one part of a broader risk-management strategy.
Sources
- Federal Trade Commission, Cyber Insurance, accessed August 2026.
- Federal Trade Commission, Cybersecurity for Small Business, accessed August 2026.
- Federal Trade Commission, Data Breach Response: A Guide for Business, accessed August 2026.
- National Association of Insurance Commissioners, Cybersecurity, last updated May 9, 2024.
- National Association of Insurance Commissioners, Ransomware, accessed August 2026.