Cyber insurance can cover certain financial losses and liabilities arising from data breaches, ransomware, network attacks, privacy incidents, data restoration, cyber-related business interruption, incident response, and lawsuits. Policies may include first-party coverage for the insured business and third-party liability coverage for claims against it. Cyber insurance is highly customized, however, so ransomware payments, vendor outages, fraudulent transfers, regulatory matters, and other losses may be limited, excluded, or require specific coverage.

Key Takeaways

  • Cyber insurance can include both first-party and third-party protection. First-party coverage addresses certain losses suffered by your business, while third-party coverage can address covered claims made against it.
  • Data breaches are a core cyber exposure. Depending on the policy, covered costs can include investigation, notification, credit-monitoring services, data recovery, legal assistance, and related response expenses.
  • Ransomware and business interruption may be covered, but conditions matter. Coverage can depend on policy wording, security requirements, prior insurer approval, applicable law, waiting periods, sublimits, and other provisions.
  • Standard business policies should not be assumed to cover cyber losses. The NAIC notes that most commercial property and general liability policies do not cover cyber risks.
  • Cyber policies are highly customized. Compare definitions, exclusions, deductibles or retentions, sublimits, incident-response services, vendor coverage, and security conditions rather than comparing premiums alone.

What Is Cyber Insurance?

Cyber insurance is business insurance designed to address specified financial losses and liabilities arising from cyber events. Depending on the policy, those events can include unauthorized access to computer systems, theft or exposure of sensitive information, ransomware, malware, privacy breaches, data corruption, and certain disruptions to business operations.

The NAIC identifies cyber-related risks that can include business interruption, data repair costs, theft of customer lists or trade secrets, hardware and software repair costs, credit-monitoring expenses, and litigation. It also warns that cyber policies are highly customized.

That customization is important. Two policies both called “cyber insurance” can contain substantially different triggers, limits, exclusions, deductibles, incident-response requirements, definitions, and endorsements.

Cyber insurance is not a standardized package. The question should not be only whether a business has cyber insurance, but whether its particular policy addresses the cyber events, systems, data, vendors, financial losses, and liabilities that create the business’s most significant exposures.

First-Party vs. Third-Party Cyber Insurance Coverage

One useful way to understand cyber insurance is to separate first-party losses from third-party liability claims.

Coverage CategoryGeneral PurposePossible Examples
First-party cyber coverageAddresses certain direct losses and response costs suffered by the insured businessIncident investigation, data recovery, business interruption, breach response, and certain cyber-extortion costs
Third-party cyber liabilityAddresses certain covered claims or proceedings brought against the insured businessPrivacy claims, network-security liability, legal defense, and some regulatory matters where covered and legally insurable

A business can face both types of loss from the same incident. For example, a data breach may force the business to pay forensic and notification expenses while also creating claims from customers whose personal information was compromised.

Data Breach and Privacy Incident Costs

A data breach is one of the most recognizable cyber insurance exposures. A breach may involve customer information, employee records, financial data, login credentials, health information, trade secrets, or other sensitive information.

Depending on the policy and incident, cyber insurance may cover costs such as:

  • Forensic investigation to determine what happened and which systems or information were affected.
  • Legal assistance related to breach-response obligations.
  • Required or covered notifications to affected individuals.
  • Credit-monitoring or identity-related services for affected individuals when covered.
  • Public-relations or crisis-management services included by the policy.
  • Other incident-response expenses specified by the policy.

The NAIC specifically identifies credit monitoring, litigation costs, data repair, and other response expenses among the risks associated with cyberattacks. Actual reimbursement remains subject to the policy’s definitions, sublimits, approved vendors, notification requirements, and other terms.

Cyber Incident Response and Forensic Investigation

A company hit by a cyberattack may not immediately know whether an intruder accessed sensitive records, whether malware remains active, which systems are trustworthy, or what legal notification duties apply.

Cyber policies can provide or pay for access to specialized response professionals, depending on the policy. These may include forensic investigators, breach-response attorneys, data-recovery specialists, notification vendors, public-relations professionals, and other approved providers.

Some insurers maintain an incident hotline or response panel. Review whether the policy requires the insured to contact the carrier before hiring outside professionals. Hiring vendors without required approval can create a reimbursement dispute if the policy restricts which expenses or providers qualify.

Know whom to call before an incident occurs. A cyber policy is more useful during an emergency when employees already know the insurer’s reporting process, breach hotline, approved response providers, and any consent requirements.

Data Restoration and System Recovery

A cyberattack can damage, encrypt, alter, or delete electronic information. It can also require a business to rebuild or restore affected software and systems.

The NAIC identifies data repair and hardware or software repair costs among potential cyberattack exposures. A cyber policy may therefore cover specified costs to restore data or systems after a covered incident.

Coverage does not necessarily mean the insurer pays to upgrade old equipment, improve systems beyond their pre-loss state, or reimburse every internal technology expense. Review valuation provisions, restoration definitions, sublimits, betterment restrictions, deductibles, and exclusions.

Cyber Business Interruption Coverage

A cyberattack can prevent a business from processing transactions, accessing files, taking orders, operating production systems, communicating with customers, or performing other essential functions.

Cyber business interruption coverage can help address specified lost income and extra expenses resulting from a covered cyber event. The NAIC includes business interruption among the significant risks posed by cyberattacks.

Cyber business interruption should be distinguished from the business income coverage commonly found in a business owner’s policy. Traditional business interruption coverage often depends on qualifying physical property damage, whereas cyber coverage can be designed around specified network or system disruptions.

Check the Waiting Period

Business-interruption protection can contain a waiting period before covered loss begins. Review how the policy measures the interruption, when the waiting period begins, how lost income is calculated, and how long coverage can continue.

Does Cyber Insurance Cover Ransomware?

Many cyber policies can provide some protection for ransomware and cyber-extortion incidents, but coverage should never be assumed from the policy name alone.

Depending on the policy, potentially covered costs may include:

  • Forensic investigation and incident response.
  • Data and system restoration.
  • Cyber business interruption losses.
  • Specialized negotiation or response services.
  • Certain extortion-related payments or expenses where covered and legally permissible.

Ransom payments present significant legal, practical, and security concerns. New York’s Department of Financial Services recommends against ransom payments and notes potential sanctions issues. A payment also does not guarantee that systems or data will be restored.

Cyber policies may impose strict notification, consent, security-control, or other requirements for ransomware claims. Some coverages may also have separate sublimits or deductibles.

Network Security and Privacy Liability

A business may face liability when customers, employees, clients, or other parties allege that the company’s network security or handling of sensitive information caused them harm.

Third-party cyber liability coverage may address covered claims alleging failures involving privacy or network security. Depending on the policy, protection can include legal defense costs and covered settlements or judgments.

Potential allegations could involve unauthorized disclosure of information, failure to adequately protect data, transmission of malicious software, or another covered security or privacy event. The definition of a covered wrongful act or privacy event is critical.

Regulatory Investigations, Fines, and Penalties

A significant privacy or cybersecurity incident can result in regulatory inquiries in addition to private lawsuits. Some cyber policies include specified coverage for regulatory defense expenses arising from a covered event.

Policies may also refer to regulatory fines or penalties, but coverage depends on the contract and whether the particular fine or penalty is legally insurable under applicable law. Do not assume every government assessment can be transferred to an insurer.

Review any regulatory coverage sublimit, applicable jurisdiction, consent requirements, exclusions, and definitions of covered proceedings.

Does Cyber Insurance Cover Third-Party Vendor Incidents?

Modern businesses frequently depend on cloud platforms, payment processors, managed service providers, software vendors, data centers, and other outside organizations. A cyber event at one of those providers can disrupt the insured business even when its own network was not directly attacked.

New York’s Department of Financial Services identifies concentration in cloud and managed-service providers as a significant source of systemic cyber risk. Cyber insurance may include certain dependent or contingent business interruption and third-party incident coverage, but the scope varies considerably.

Ask whether the policy covers incidents affecting vendors that host your data or provide critical technology. Some policies may limit protection to specifically defined providers or types of services.

Vendor dependence deserves its own review. If your company cannot operate without a particular cloud, payment, software, or managed-service provider, confirm whether an outage or cyberattack at that provider can trigger your policy.

Does Cyber Insurance Cover Business Email Compromise and Fraud?

A business email compromise can occur when a criminal impersonates an executive, employee, supplier, or other trusted party and tricks someone into transferring money or changing payment instructions.

Do not assume a cyber policy automatically covers the resulting stolen funds. Social engineering, fraudulent instruction, computer fraud, and funds-transfer fraud can be handled differently among cyber and commercial crime policies. Coverage may be optional, separately endorsed, subject to a low sublimit, or excluded.

If fraudulent transfers are a significant exposure, ask specifically how the policy treats social engineering and business email compromise instead of relying on the general term “cyber fraud.”

What Cyber Insurance May Not Cover

Cyber policy exclusions vary substantially, so there is no universal list that applies to every insurer. Businesses should nevertheless review several areas where limits or exclusions can create significant gaps.

  • Known incidents or circumstances: Problems known before coverage begins may not be covered.
  • Failure to maintain required cybersecurity controls: Policy representations or specific security conditions can affect coverage.
  • Intentional or dishonest acts: Deliberate misconduct by certain insured persons can be excluded.
  • War or hostile-action exclusions: Cyber policies may contain exclusions addressing certain state-backed, warlike, or hostile acts, subject to the wording of the policy.
  • Bodily injury or physical property damage: These exposures may fall outside the cyber policy or require other insurance, depending on the form.
  • Contractual promises: Liability assumed solely under a contract may not be fully covered.
  • Unapproved expenses: The insurer may require consent before paying ransom-related, legal, forensic, or other significant response costs.
  • Losses above a sublimit: A policy can have a large overall limit but much smaller limits for ransomware, fraud, business interruption, or other specific coverages.

Security representations deserve close attention. New York insurance regulators note that cyber insurers commonly assess controls such as access management, encryption, endpoint monitoring, vulnerability management, incident response, and third-party security practices. Make sure information provided during underwriting accurately reflects the controls actually in place.

Cyber Insurance vs. General Liability and Property Insurance

Businesses sometimes assume their existing commercial insurance already handles cyber losses. The NAIC cautions that most commercial property and general liability policies do not cover cyber risks.

Policy TypeTypical FocusCyber Consideration
Cyber insuranceSpecified cyber incidents, cyber-related first-party costs, and third-party liabilitiesDesigned specifically for cyber risk, but coverage varies widely
General liabilityCovered bodily injury, property damage, and certain personal or advertising injury claimsShould not be assumed to cover data breaches or other cyber risks
Commercial propertyCovered loss to buildings, equipment, and other insured physical propertyShould not be assumed to cover electronic data loss or cyber business interruption

Coverage can sometimes overlap or interact among cyber, crime, professional liability, property, and other policies. Review other-insurance provisions and cyber exclusions to understand where each policy is intended to respond.

Who Should Consider Cyber Insurance?

Cyber exposure is not limited to technology companies. A small business can face a significant cyber event if it relies on computer systems, accepts electronic payments, stores confidential information, communicates through email, or depends on outside technology vendors.

Businesses with exposures worth evaluating include those that:

  • Store customer or employee personal information.
  • Accept credit cards or electronic payments.
  • Depend on email for financial instructions or vendor communication.
  • Operate e-commerce websites or other internet-facing systems.
  • Store confidential professional, financial, health, or business data.
  • Depend heavily on cloud software or third-party technology services.
  • Could lose substantial revenue if computer systems became unavailable.
  • Have contracts requiring cyber liability or data-security insurance.

What Affects the Cost of Cyber Insurance?

There is no reliable single premium that applies to all businesses. Cyber insurance pricing depends on the insurer, business, requested limits, deductible or retention, coverage scope, industry, loss history, data exposure, technology dependence, and cybersecurity controls.

New York’s Department of Financial Services notes that cyber insurers assess cybersecurity practices such as governance, access controls, encryption, endpoint monitoring, vulnerability management, incident-response planning, and third-party security policies.

Factors that may affect underwriting or pricing include:

  • Business size and industry.
  • Type and amount of sensitive information handled.
  • Revenue and business-interruption exposure.
  • Prior cyber incidents and claims.
  • Multi-factor authentication and access controls.
  • Backup and recovery practices.
  • Endpoint, network, and vulnerability-management controls.
  • Use of third-party technology providers.
  • Selected limits, sublimits, deductibles, retentions, and endorsements.

How to Compare Cyber Insurance Policies

1. Identify Your Most Important Cyber Exposures

List the data, systems, revenue streams, technology vendors, online services, and payment processes that could create a significant financial loss if compromised or unavailable.

2. Compare First-Party and Third-Party Coverage

Determine whether each quote includes the response expenses, business interruption, data restoration, privacy liability, network-security liability, and other components relevant to your business.

3. Review Sublimits, Not Just the Overall Limit

A policy may advertise one large aggregate limit while providing much smaller amounts for cyber extortion, fraud, business interruption, dependent-business interruption, or other coverages.

4. Check the Deductible or Retention

Understand what the business must absorb before insurance responds. Different sections of the policy may have different deductibles, retentions, or waiting periods.

5. Read the Security Requirements

Review application answers and policy provisions involving multi-factor authentication, backups, patching, endpoint protection, remote access, employee training, or other cybersecurity practices. Confirm that the business can maintain any required controls.

6. Examine Vendor and Cloud Coverage

If outside technology is essential to operations, determine whether the policy responds when a covered incident occurs at a critical third-party provider.

7. Understand the Claim Response Process

Find out whether the insurer provides a 24-hour incident hotline, which professionals can be hired, which costs need advance approval, and what information must be reported after a suspected cyber incident.

Common Cyber Insurance Mistakes to Avoid

  • Assuming general liability covers a data breach. Standard commercial policies should not be relied on as substitutes for dedicated cyber coverage.
  • Comparing only the premium and headline limit. Sublimits and exclusions can make two similarly priced policies very different.
  • Ignoring vendor outages. A business can suffer substantial loss from an incident at a cloud or technology provider.
  • Assuming every ransomware expense is covered. Consent requirements, sanctions considerations, sublimits, and security conditions can affect a claim.
  • Providing inaccurate security information. Cyber underwriting often relies heavily on representations about controls and procedures.
  • Waiting for an incident to read the policy. Employees should know the reporting process and incident-response contacts beforehand.
  • Treating insurance as a substitute for cybersecurity. Cyber insurance transfers specified financial risk; it does not prevent attacks or remove the need for effective security controls, backups, employee training, and incident planning.

Frequently Asked Questions

Does cyber insurance cover data breaches?

Cyber insurance commonly provides coverage for specified data-breach and privacy incidents. Depending on the policy, covered expenses can include forensic investigation, legal assistance, customer notification, credit-monitoring services, data restoration, and third-party liability claims. Exact coverage depends on the incident, policy wording, limits, exclusions, and response requirements.

Does cyber insurance cover ransomware payments?

Some policies can cover specified cyber-extortion expenses, potentially including certain ransom-related payments when permitted by law and policy terms. Coverage may require immediate insurer notification and prior consent and can be subject to separate limits, deductibles, sanctions rules, and security requirements. A ransom payment does not guarantee recovery of systems or data.

Does cyber insurance cover lost income after an attack?

It may. Cyber business interruption coverage can help address specified lost income and extra expenses when a covered cyber event disrupts operations. Waiting periods, restoration periods, loss calculations, exclusions, and limits apply. Coverage for an outage caused by a third-party technology provider may require separate dependent or contingent business interruption protection.

Does general liability insurance cover cyberattacks?

Do not assume it does. The NAIC states that most commercial property and general liability policies do not cover cyber risks. Businesses concerned about data breaches, network attacks, cyber-related interruption, privacy liability, or similar exposures should review dedicated cyber insurance and any cyber exclusions in their other business policies.

Do small businesses need cyber insurance?

A small business should consider its cyber exposure rather than assuming its size makes insurance unnecessary. Businesses that store sensitive information, accept electronic payments, depend on computer systems, use cloud providers, or could lose substantial revenue during a system outage may have significant cyber risk. The appropriate coverage depends on the business’s operations, security controls, contracts, and financial ability to absorb a cyber loss.

The Bottom Line

Cyber insurance can cover a broad range of costs arising from covered cyber incidents, including data-breach response, forensic investigation, data restoration, cyber business interruption, certain ransomware-related expenses, privacy and network-security liability, and legal defense. A well-designed policy can provide both financial protection and access to specialized incident-response resources.

The biggest limitation is that cyber insurance is highly customized. A policy may contain separate limits for ransomware, fraud, business interruption, vendor incidents, or regulatory matters, while exclusions and security requirements can materially affect whether a claim is covered.

Before choosing coverage, identify the systems, data, vendors, and revenue streams most important to the business. Compare first-party and third-party coverage, exclusions, sublimits, deductibles or retentions, security conditions, vendor protection, and incident-response procedures. Cyber insurance should complement effective cybersecurity and incident planning rather than replace them.

Sources

  • National Association of Insurance Commissioners, Cybersecurity, updated May 9, 2024.
  • National Association of Insurance Commissioners, Small Business Insurance, accessed August 2026.
  • National Association of Insurance Commissioners, Ransomware, accessed August 2026.
  • New York State Department of Financial Services, Insurance Circular Letter No. 2 (2021): Cyber Insurance Risk Framework, February 4, 2021.
Share This Story, Choose Your Platform!