GlossaryCompliance operations

Cyber insurance

Short answer

Cyber insurance is a policy that covers the financial losses from a cyber incident, such as incident response costs, business interruption, data recovery, legal advice and liability to third parties. Insurers increasingly require minimum security controls before they offer cover.

What it usually covers

First party cover pays the company's own costs: forensic investigation and incident response, restoring systems and data, business interruption and crisis communication. Third party cover handles claims from customers or partners affected by the incident, legal defence and, where insurable, regulatory proceedings. Many policies include access to a response team available around the clock.

What insurers now require

After heavy losses from ransomware, insurers ask detailed questions before quoting. Common requirements are MFA on email and remote access, EDR on all devices, offline or immutable backups, patch management, awareness training and an incident response plan. Missing controls can mean higher premiums, exclusions or no cover at all.

Read the exclusions

Policies differ widely. Points to check include exclusions for acts of war or state attacks, failure to maintain declared controls, unpatched known vulnerabilities, and limits on ransom payments. Answers given in the application must match reality, since inaccurate declarations can void the policy.

Insurance is not a security strategy

Insurance transfers part of the financial risk but does not prevent an incident, protect reputation or restore customer trust. It works best as one of the risk treatment options decided in the risk assessment.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub