What does cyber insurance actually cover?
A cyber policy is really two policies in one jacket. First-party coverage pays your own costs after an incident. Third-party coverage pays what you owe other people. Most disappointment at claim time comes from assuming a policy does both generously when the sublimits say otherwise.
First party versus third party
The split matters because the two halves are triggered by different events and are often limited differently on the same policy.
| Side of the policy | What it pays for | Typical triggers |
|---|---|---|
| First party | Your own losses. Forensics, legal advice, notification, credit monitoring, public relations, data restoration, lost income during an outage and extortion payments where permitted. | Ransomware, system outage, a compromised email account, destruction or corruption of data. |
| Third party | What you owe others. Defence and settlement of claims, regulatory fines and penalties where insurable, and liability arising from data you held. | A lawsuit from affected individuals, a regulator opening an inquiry, a contractual counterparty asserting loss. |
The insuring agreements you will actually see
- Incident response. Forensics, breach counsel, notification and monitoring. Usually the first coverage to respond and often the most used.
- Business interruption. Lost income while systems are down, subject to a waiting period measured in hours.
- Dependent business interruption. The same, but when the outage happens at a vendor rather than at you. Frequently narrower or absent.
- Cyber extortion. Ransom negotiation and payment where lawful, often with coinsurance.
- Data restoration. The cost of rebuilding data and systems, which is not the same as the cost of the hardware.
- Network security and privacy liability. The third-party half, covering claims brought against you.
- Regulatory defence and penalties. Where insurable by law.
- Social engineering and funds transfer fraud. Money leaving on a fraudulent instruction. Almost always sublimited, often heavily.
The sublimits that decide real recovery
A policy can carry a headline limit and still recover very little on the loss you actually suffer, because several of the agreements above sit under their own smaller caps. Social engineering is the most common example. A business can hold a substantial policy limit and find that a fraudulent payment instruction is capped at a fraction of it.
Read the declarations page for each agreement separately rather than reading the top limit and assuming it applies throughout.
Exclusions that surprise buyers
- War and hostile act wording. How state-backed attacks are treated varies significantly between forms and has been actively litigated.
- Failure to maintain stated controls. If the application represented that a control was in place, not maintaining it can affect the claim.
- Prior known incidents. Anything a responsible person knew about before inception.
- Betterment. Upgrading systems beyond their pre-loss state is generally the insured’s cost.
- Bodily injury and property damage. Usually sit in other policies, which matters where operational technology is involved.
The exclusion that causes the most argument is not usually exotic. It is a control the application said was in place that turned out to be partially deployed.
Definitions do heavy work in cyber forms. Our cyber liability glossary covers the specific terms, and what cyber insurance costs explains how these choices affect premium.
Have someone read the policy with you
If you are not certain which half of your policy responds to the scenario you are worried about, that is worth twenty minutes before renewal rather than during an incident. 4J reviews cyber programs for Texas businesses.
Talk to a broker or call (469) 756-8776.
Educational content prepared from policy forms, carrier materials and regulatory sources. It is not a binder, a policy interpretation, or a guarantee of coverage. Coverage, availability and pricing depend on underwriting and the terms of the policy actually issued.
Common questions
Does cyber insurance cover ransomware payments?
Many policies include cyber extortion coverage, often with coinsurance and subject to a sublimit, and payment must be lawful. Coverage for the associated forensics, restoration and lost income is usually the larger part of the recovery.
Does cyber insurance cover an employee tricked into wiring money?
That is social engineering or funds transfer fraud. It is commonly covered but almost always under a sublimit well below the policy limit, and some forms require specific verification procedures to be followed.
Is a data breach the same as a cyber claim?
No. A breach is one type of event. Outages, extortion, fraudulent payments and system corruption can all trigger coverage without any personal data being exposed.
Does cyber insurance cover fines?
Regulatory defence costs are commonly covered, and penalties may be covered where insurable under applicable law. Insurability of fines varies by jurisdiction.
What if the outage happened at our vendor?
That is dependent business interruption. It is a distinct insuring agreement, it is often narrower than your own business interruption cover, and on some forms it is absent entirely.
.png?width=500&height=136&name=4J%20commercial%20insurance%20broker%5B1%5D%20(1).png)