First-party coverage: the insured's own costs. Forensic investigation and containment, system and data restoration, lost income from business interruption, notification to affected individuals and authorities, crisis management and PR, and in many policies extortion expenses (negotiation and, where applicable, the ransom itself).
What is cyber insurance?
Cyber insurance is a policy that transfers to an insurer part of the financial impact of a cybersecurity incident: forensic investigation and incident response costs, system and data restoration, business interruption, crisis management and third-party claims. It is the practical expression of one of the four classic risk treatment options —avoid, mitigate, transfer, accept— which is why it only makes sense as the outcome of a proper risk assessment, never as a substitute for protective controls. The ransomware wave of 2019-2021 drove loss ratios through the roof and reshaped the market: insurers now audit a client's technical maturity before underwriting, and their questionnaires have become, in practice, a de facto security baseline for thousands of companies.
Why does it matter?
Because a serious incident generates costs most organisations cannot absorb at once: forensic experts, lawyers, notification to affected individuals and regulators, weeks of operational downtime and the claims that follow. But cyber insurance also matters for a less obvious reason: it has become a maturity lever. To get insured —or to renew without the premium exploding— the insurer demands MFA on remote access and privileged accounts, EDR deployed and monitored, immutable or offline backups with tested restores, patch management with defined SLAs and network segmentation. Many companies have implemented in months controls they had postponed for years, simply because the renewal questionnaire turned them into a condition of cover. The reverse is equally true: declaring controls you do not actually have gives the insurer contractual grounds to deny the claim exactly when you need it most. Exclusions matter too: after NotPetya and the litigation that pitted Merck and Mondelez against their insurers, the Lloyd's market imposed clauses in 2023 excluding cyberattacks attributable to acts of war or state-backed actors — a scenario less remote than it sounds.
Key points
Third-party coverage: liability towards those harmed by the incident. Claims from customers and partners over leaked data, legal defence, damages. Whether administrative fines (GDPR) are insurable is legally contested across much of Europe: do not build your plan around it.
Underwriting requirements: the insurer's questionnaire works as a pre-audit. MFA, EDR, immutable and tested backups, patching SLAs, encryption, awareness training and an incident response plan. Without them: higher premium, larger deductible, aggressive sublimits or outright refusal.
Common exclusions: acts of war and state-attributed attacks (Lloyd's market clauses since 2023), incidents known before inception, failure to maintain the controls declared in the questionnaire, end-of-life systems, and frequently reduced sublimits for ransomware and funds-transfer fraud.
Ransom payments: policies that cover extortion condition it on the insurer's prior authorisation, specialised negotiators and sanctions screening (OFAC, EU): paying a sanctioned group is illegal whether or not the policy would cover it. The decision is never purely financial.
Fit within risk management: transferring risk does not remove it. The policy does not restore reputation, lost customers or exfiltrated intellectual property, and there is always residual risk above the limits purchased. Cyber insurance complements business continuity; it does not replace it.
Example: a policy renewal that turns into a security roadmap
A 200-employee manufacturer receives its cyber insurance renewal questionnaire and discovers the market has changed: the insurer requires MFA on the VPN and every administrative account, EDR on servers and endpoints, immutable backups with documented restore tests and an incident response plan. The company fails three of the four requirements, and the alternative is a doubled premium with a ransomware sublimit of 20% of the overall limit. Management approves within weeks a plan that had sat in a drawer for two years: company-wide MFA, EDR rollout and an immutable backup repository.
A year later a ransomware affiliate gets in through stolen credentials, but the story plays out differently: EDR cuts the encryption short on two servers, the immutable copies allow restoration without negotiating, and the company triggers the policy to cover forensics, recovery overtime and the lost income from three days of partial downtime. The insurer brings in its incident response panel and the claim settles without friction, because the controls declared in the questionnaire genuinely existed and left evidence in the logs. The insurance did not prevent the attack: it turned a potentially existential event into a bad quarter.
Common mistakes
- Buying the policy as a substitute for security controls. Transferring risk without mitigating it is extremely expensive (premium, deductible, sublimits) and does not restore what no policy covers: reputation, customers and intellectual property.
- Filling in the underwriting questionnaire optimistically. Declaring MFA 'deployed' while service accounts are missing, or backups 'tested' that have never been restored, hands the insurer contractual grounds to deny the claim.
- Not reading exclusions and sublimits until the day of the incident. A generous overall limit with a much lower ransomware or funds-transfer sublimit completely changes the real value of the policy.
- Leaving the insurer out of the incident response plan. Policies impose notification deadlines and panel providers for forensics and legal; engaging your own vendors without authorisation, or notifying late, can jeopardise coverage.
- Counting on the policy to pay GDPR fines. Their insurability is contested and many policies limit it to 'where legally insurable' — wording that moves the problem to a courtroom rather than solving it.
Related services
This concept may be related to services such as:
Frequently asked questions
I run an SMB with no security team: is it smarter to buy cyber insurance or to spend that money on protection?
It is not a real either-or: without a minimum level of protection nobody will insure you on reasonable terms. The practical route is to use the insurer's questionnaire as your roadmap: MFA, EDR, tested immutable backups and up-to-date patching are the four controls that most reduce both your premium and the likelihood of the incident itself. Build that baseline first —with outside help if you have no team— and then buy the policy for the impact you cannot absorb: forensics, downtime and third-party claims. That way the insurance covers the tail of the risk, not your unfinished homework.
What requirements will the insurer impose before writing a policy?
The current market standard includes MFA on remote access, email and privileged accounts; EDR deployed on servers and endpoints (ideally monitored 24x7); immutable or offline backups with restore tests; patch management with deadlines for critical vulnerabilities; basic network segmentation; anti-phishing training; and an incident response plan. The larger the revenue or the more sensitive the sector, the deeper the scrutiny: on larger policies expect external scanning of your attack surface and even technical interviews. Lying on the questionnaire is the fastest route to a denied claim.
If I pay a ransomware ransom, will the policy cover it?
It depends on the policy and the circumstances. Many cover extortion expenses, but always with conditions: the insurer's prior authorisation, specialised negotiators, and verification that the criminal group is not on sanctions lists (OFAC, EU), because paying a sanctioned actor is illegal with or without insurance. There are usually specific extortion sublimits as well. The operational lesson is to prepare the decision in advance —legal, technical and business criteria— and above all to maintain immutable backups so you never depend on the attacker's decryptor.
When can the insurer refuse to pay a claim?
The most frequent grounds are four. First, a gap between what was declared and reality: if the questionnaire said MFA everywhere and the intrusion came through an account without MFA, there is a problem. Second, exclusions: state-attributed attacks or those qualified as acts of war (Lloyd's-style clauses), incidents predating inception, unsupported systems. Third, late notification or engaging providers outside the panel without authorisation. Fourth, sublimits: the insurer pays, but far less than expected. Reviewing the policy with technical and legal advice before signing avoids most of these surprises; a serious risk assessment helps size limits and deductibles.