Cyber insurance claim examples and what actually responds
Cyber claims rarely look like the headlines. The common ones are an email account taken over, a payment sent on a fraudulent instruction, and an outage that stops work for a few days. The useful question is not whether you are covered, but which insuring agreement responds and where it stops.
Representative scenarios
The scenarios below are illustrative and generic. What responds in any real claim depends on the policy actually issued.
| Scenario | What generally responds | Where it commonly falls short |
|---|---|---|
| Ransomware encrypts servers and work stops for six days | Cyber extortion, business interruption, data restoration, incident response. | The business interruption waiting period can absorb the first several hours. Extortion may carry coinsurance and a sublimit. |
| Finance pays an invoice after a spoofed email from a supplier | Social engineering or funds transfer fraud. | Almost always sublimited well below the policy limit. Some forms require documented call-back verification that was not followed. |
| An email account is compromised and used to reach clients | Incident response, privacy liability if data was exposed. | Notification obligations can be triggered by access alone. Costs land in first party before any lawsuit exists. |
| A cloud provider outage halts operations for two days | Dependent business interruption. | Often narrower than your own business interruption cover, and absent on some forms entirely. |
| A laptop with client records is lost | Incident response, notification, privacy liability. | Encryption status usually decides whether notification is required at all. |
| A regulator opens an inquiry after a breach | Regulatory defence, and penalties where insurable. | Insurability of penalties varies by jurisdiction. Defence costs may erode the limit. |
What the pattern tells you
Three things recur across these.
The first-party side does most of the work. Forensics, counsel, notification and lost income usually dwarf any third-party liability, and they arrive immediately rather than years later.
Sublimits decide the outcome more often than the policy limit does. A business with a healthy headline limit can still be substantially uninsured for the fraudulent-payment scenario, which is one of the most frequent.
Timing is coverage. A waiting period measured in hours and a retroactive date set at inception both quietly remove real events from the policy.
The two scenarios businesses are least prepared for are the fraudulent payment and the vendor outage. Both are common, and both are the ones most likely to be sublimited or missing.
What to check on your own policy
- The sublimit for social engineering and funds transfer fraud, read separately from the policy limit.
- The business interruption waiting period in hours, and whether dependent business interruption is included.
- The retroactive date, since intrusions are often discovered long after they begin.
- Whether any verification procedure is a condition of the fraud coverage.
- Who chooses breach counsel and forensics, and whether that is decided in advance.
What cyber insurance covers sets out the insuring agreements in full, and the cyber liability glossary defines the terms used above.
Have someone read the policy with you
If you want to know how your current policy would have responded to any of these, that is a readable answer rather than a guess. 4J reviews cyber programs for Texas businesses against the scenarios most likely to happen.
Talk to a broker or call (469) 756-8776.
Educational content prepared from policy forms, carrier materials and regulatory sources. It is not a binder, a policy interpretation, or a guarantee of coverage. Coverage, availability and pricing depend on underwriting and the terms of the policy actually issued.
Common questions
What is the most common cyber claim?
Incidents beginning with a compromised email account, and fraudulent payment instructions, are among the most frequently reported for mid-sized businesses. Both are far more common than a large-scale data breach.
Does cyber insurance pay for lost income?
Business interruption coverage may, once the waiting period has elapsed. That period is measured in hours and shorter outages can fall entirely below it.
Are we covered if the breach was our vendor’s fault?
Possibly, under dependent business interruption or contingent coverage. It is a distinct agreement, and it is narrower or absent on some forms.
Does the policy pay if an employee caused it?
Employee error is generally the expected cause rather than an exclusion. Deliberate acts by an insured are treated differently, and policy language governs.
How quickly should an incident be reported?
Immediately, and before engaging your own forensics or counsel if the policy requires panel providers. Using a non-panel firm without consent can affect recovery.
.png?width=500&height=136&name=4J%20commercial%20insurance%20broker%5B1%5D%20(1).png)