Cyber Insurance
Coverage for Digital Events and Their Business Costs
What Can Cyber Insurance Help Cover?
Cyber insurance is designed to help businesses respond to certain computer, network, privacy, data, and electronic-fraud incidents. Depending on the policy, it may address expenses paid directly by the business as well as claims brought by customers, employees, vendors, regulators, or other affected parties.
Cyber Investigation
May help pay specialized professionals to determine what happened, how systems were accessed, what information was affected, and what steps may be needed to contain the incident.
Data & System Recovery
May help restore qualifying data, remove malicious software, rebuild affected systems, and return computer operations to an appropriate working condition.
Privacy Response & Notification
May help with qualifying legal guidance, customer notices, mailing, call-center services, credit monitoring, identity protection, and other response expenses.
Business Interruption
Cyber business-interruption coverage may help replace qualifying income lost when a covered network or computer-system interruption prevents normal operations.
Two Sides of Cyber Protection
Your Business Costs vs. Claims Against Your Business
First-Party Coverage
Costs Experienced by Your Business
Third-Party Coverage
Claims Made Against Your Business
Examples From Everyday Business Technology
When Might a Business Use Cyber Insurance?
Coverage depends on the policy, cause of loss, security controls, notification timing, limits, deductibles, sublimits, and endorsements.
Ransomware Locks the Systems
Employees cannot access important files or applications and an attacker demands payment to restore access or prevent information from being released.
Customer Data Is Stolen
A hacker accesses personal information belonging to customers, employees, applicants, vendors, or other individuals.
A Fake Email Steals Credentials
An employee responds to a phishing message and a criminal gains access to company email, payment, cloud-storage, or other accounts.
Money Is Sent to a Criminal
Fraudulent instructions appear to come from an owner, executive, vendor, customer, or employee and cause money to be sent to the wrong account.
A Vendor Is Hacked
A cloud provider, payroll company, software vendor, payment processor, or other important outside provider experiences a cyber event that affects the business.
The Business Cannot Operate
A qualifying cyber event disrupts billing, scheduling, communication, sales, production, payment processing, or customer service.
Cyber Policies Are Not All the Same
Important Coverage Options to Review
Ransomware & Cyber Extortion
May provide access to specialists and help with certain qualifying response expenses involving cyber threats, extortion, or ransomware.
Social Engineering
Certain policies may provide limited protection for qualifying losses caused by fraudulent instructions, impersonation, or deceptive payment requests.
Network & Privacy Liability
May help defend qualifying claims alleging that the business failed to protect information or prevent unauthorized access to systems.
Dependent Business Interruption
Certain policies may respond when a qualifying cyber event involving an approved outside technology provider disrupts the insured business.
Regulatory Response
May help with certain covered regulatory inquiries, investigations, legal expenses, and fines or penalties when insurable by law.
Sublimits Matter
Electronic fraud, ransomware, social engineering, notification, business interruption, and other protections may have separate limits or requirements.
Build the Policy Around the Technology You Actually Use
What Should a Business Review Before Buying Cyber Insurance?
Cyber applications may ask detailed questions about customer information, employee data, payment activity, cloud systems, outside vendors, multi-factor authentication, backups, employee training, remote access, prior incidents, and other security practices.
Multi-Factor Authentication
Insurers may review whether important email, administrator, cloud, remote-access, and financial accounts use additional authentication beyond a password.
Data Backups
Applications may ask how frequently important data is backed up and whether backup copies are separated or protected from the main network.
Employee Training
Security-awareness and phishing training may help reduce the chance that employees respond to fraudulent emails or reveal sensitive credentials.
Software Updates
Insurers may ask about patching procedures, supported software, operating systems, endpoint protection, and vulnerability management.
Outside Technology Vendors
Cloud platforms, software providers, payroll companies, payment processors, and IT firms can create important dependencies that should be disclosed.
Incident-Response Plan
A documented plan can help employees understand whom to contact, what systems to protect, and how to respond when a potential cyber event is discovered.
A Real-Looking Email Can Cause a Real Financial Loss
Business Email Fraud & Fake Payment Instructions
Criminals may impersonate an owner, executive, employee, vendor, customer, or financial institution to convince someone to send money, change banking information, reveal credentials, or disclose sensitive information.
Fake Vendor Instructions
A criminal changes bank information on an invoice or requests that future payments go to a fraudulent account.
Fake Executive Request
An email or text appears to come from a company leader requesting an urgent wire transfer, gift cards, payroll change, or confidential information.
Verify Through Another Method
Businesses can reduce exposure by requiring employees to verify unusual payment requests and bank-account changes using known contact information.
Your Data and Systems May Be Somewhere Else
Cyber Events Involving Outside Vendors
Cloud & Software Providers
Email, customer management, accounting, file storage, scheduling, and other cloud systems may contain important business information.
Payroll & HR Providers
Outside providers may hold employee identification, tax, payroll, direct-deposit, benefits, and other sensitive information.
Payment Companies
Payment processors, banks, billing systems, and point-of-sale platforms may be critical to receiving and sending money.
Managed Technology Providers
Outside IT firms may have high-level access to networks, computers, passwords, security tools, backups, and administrative systems.
Use the Policy Early
What Should a Business Do After a Cyber Incident?
Cyber policies may require prompt notice and may provide access to approved attorneys, forensic investigators, negotiators, restoration firms, and other response professionals.
Report the Incident
Contact the cyber insurer’s incident hotline or claims contact as soon as reasonably possible.
Limit Additional Damage
Follow professional guidance for affected devices, passwords, remote access, backups, and compromised accounts.
Preserve Evidence
Keep suspicious emails, payment instructions, account records, device information, logs, messages, and other relevant evidence.
Coordinate the Response
Work with approved professionals to investigate, restore operations, review notification duties, and document qualifying expenses.
Cyber Insurance Learning Center
Understand the Coverage Before an Incident
Explore practical guides about ransomware, data breaches, response costs, cyber extortion, privacy obligations, and business interruption.
Adding Software, Vendors, Employees, or Online Payments?
Technology Changes Can Change Your Cyber Exposure
New cloud systems, remote access, online payments, additional customer records, new employees, outside vendors, or major contracts can affect cyber insurance limits, security requirements, and available coverage.
Cyber Insurance Questions
Cyber Insurance FAQs
Clear answers about data breaches, ransomware, electronic fraud, customer information, vendors, business interruption, employee mistakes, security requirements, and cyber insurance.

