Cyber insurance has moved from a niche product for large enterprises to a practical consideration for small businesses, professional practices, and organisations of any size that store customer data, process payments, or rely on digital operations. A successful ransomware attack, data breach, or business email compromise can produce costs — remediation, legal fees, regulatory penalties, notification expenses, and business interruption losses — that far exceed what most small businesses can absorb from cash reserves. For a broader walkthrough, our Complete Guide to Online Security and Privacy is a good next read.
This cyber insurance guide explains what policies cover, what they exclude, how underwriters assess risk, and how to use the application process to simultaneously improve your security posture. The market has changed significantly since 2020 — premiums have risen, coverage has been restricted, and security requirements at underwriting have become more stringent.
What cyber insurance actually covers
Policies are not standardised — coverage varies significantly between providers and tiers. Use these typical coverage categories as a checklist when evaluating any policy:
First-party coverage (costs the insured organisation incurs directly):
- Incident response costs — forensic investigation to determine scope and root cause
- Data restoration — restoring systems and data from backups or reconstruction
- Ransomware payment (increasingly restricted; organisation must demonstrate payment was genuinely necessary)
- Business interruption losses — revenue lost during the period of inability to operate. This is typically the largest first-party cost in significant incidents — a week of inability to operate can exceed all other incident costs combined.
- Crisis management and public relations costs for reputational damage
Third-party coverage (costs arising from claims against the insured):
- Data breach notification costs — legally required notification to affected individuals
- Regulatory fines and penalties (GDPR, HIPAA, state privacy law — coverage for regulatory fines is one of the most variable terms; verify explicitly rather than assuming)
- Legal defence costs for data breach lawsuits
- Settlement payments to customers whose data was compromised
What it does NOT cover — the surprises that matter
Nation-state attacks are excluded from most policies under war exclusions. The 2017 NotPetya attack — attributed to Russian military intelligence — cost companies billions of dollars, and several claims were denied by insurers citing war exclusions. The exclusion language now often explicitly includes “acts of war, whether declared or undeclared, including state-sponsored cyberattacks.” Review war exclusion language carefully — this matters particularly for organisations in sectors targeted by nation-state actors (critical infrastructure, defence, financial services, healthcare).
Infrastructure failures are excluded. A cloud provider outage, ISP failure, or power grid disruption causing business interruption is not typically covered by cyber insurance. Significant coverage gap for organisations highly dependent on third-party infrastructure.
Prior known incidents are excluded. Security issues the organisation was aware of before the policy period are not covered. If an organisation has received breach notifications, identified vulnerabilities in its systems, or experienced prior incidents, these must be disclosed and may affect coverage.
Social engineering financial fraud — where an employee is deceived into transferring funds through a fraudulent wire transfer — is sometimes excluded or covered only under a separate rider. Business email compromise losses may not be covered by the base policy. Always verify explicitly.
Intentional acts by the insured are excluded, as is coverage for the cost of improving security controls after an incident — cyber insurance pays for the incident response and damages, not for the security upgrades that should have been in place beforehand.
The underwriting requirements — what insurers now require
The underwriting process has become significantly more rigorous since the ransomware surge of 2020–2022 dramatically increased claims. Understanding these requirements serves two purposes: preparing for the application process, and identifying the specific security controls that directly reduce both cyber risk and premiums.
Universal underwriting requirements in 2026:
- Multi-factor authentication on all remote access (VPN, Remote Desktop, cloud applications)
- Multi-factor authentication on email and administrative accounts
- Endpoint detection and response (EDR) on all workstations
- Documented backup procedures with offline or immutable backup copies
- Security patch management with defined SLAs
- A documented incident response plan
These are the baseline controls that nearly every insurer now verifies before binding coverage — absent any of these, coverage may be declined or significantly limited. Treat the underwriting questionnaire as a security audit: complete it honestly, identify the gaps it reveals, remediate them, and then apply for coverage with the controls in place.
Additional underwriting factors that affect premium: number of employees and revenue, industry sector (healthcare and finance face higher regulatory exposure), data types handled (PCI, PHI, PII), prior claims history, and jurisdictional exposure (EU GDPR exposure carries specific premium loading).
Most impactful single premium reduction action: MFA enforcement across all users. Underwriters view this as the control most predictive of reduced claim frequency, because credential-based attacks that MFA prevents represent the majority of initial access vectors for insured losses.
Choosing and using a policy
Policy limits: most small businesses choose limits between $1–5 million. The appropriate limit depends on the organisation’s revenue, the type of data handled, regulatory exposure (GDPR fines can reach €20 million or 4% of global turnover), and the potential business interruption duration. Modelling a specific incident scenario — “what would a week of ransomware cost us?” — provides a more grounded basis for limit selection than guessing.
Retention (deductible): cyber policies typically have retentions of $1,000–50,000 depending on organisation size and coverage tier. Higher retentions reduce premiums. The retention should be set at a level the organisation can genuinely self-fund — a $25,000 retention on a business with $50,000 in cash reserves is a self-funding risk that undermines the policy’s purpose.
Panel firms vs. vendors: many cyber policies require use of insurer-approved panel law firms, forensic investigators, and public relations firms. The quality of these panel firms varies significantly. Before purchasing, ask the insurer for the names of the panel firms available in your jurisdiction and research them. If you have an existing relationship with a preferred attorney or forensics firm, confirm whether they are on the panel or whether the policy allows for pre-approval of alternatives.
Breach response planning: know the claims notification requirements before an incident occurs. Most policies require notification within a specific timeframe (24–72 hours for some; up to 30 days for others). Delayed notification can result in claim denial. Keep the insurer’s claims hotline number accessible — not buried in a policy document you’ll spend 30 minutes finding during an active incident.
Using the application process to improve security
One of the most practical benefits of the cyber insurance application process is that the underwriting questionnaire functions as a structured security gap assessment. Insurers ask specifically about the controls that matter most for claim frequency — MFA, EDR, backups, patch management, incident response plans. Working through the questionnaire honestly reveals which controls are absent or inadequately documented.
The recommended approach: complete the questionnaire 60–90 days before the policy start date or renewal, identify gaps, remediate them, then complete the formal application with the controls in place. This approach both improves the security posture and maximises the likelihood of favourable terms. Organisations that can demonstrate year-over-year improvement in their security programme are better positioned to negotiate favourable renewal terms than those who cannot document security posture evolution.
Our guide on incident response planning covers the documentation requirements that cyber insurance underwriters increasingly mandate as a condition of coverage. For CISA’s guidance on cyber insurance for small and medium organisations, CISA’s Cyber Essentials guidance covers the foundational security controls that align directly with underwriting requirements.
Broker selection — the most overlooked decision
Cyber insurance is a specialist product that generalist brokers may not understand deeply enough to advise on effectively. A broker who specialises in technology or professional liability insurance understands the coverage nuances, the market of available insurers, and the negotiation leverage points that a generalist placing one or two cyber policies per year does not.
When selecting a broker: ask for the number of cyber placements they manage annually and whether they have dedicated cyber practice staff. A specialist can negotiate coverage terms — sub-limits, exclusion language, retention levels, panel firm access — that a generalist may not know to ask for. The premium difference between a generalist-placed and specialist-placed policy may be minimal; the coverage quality difference can be substantial. Related: How to Use QuickBooks.
The most important cyber insurance purchase decision is therefore not the premium or the limit — it’s the broker. A specialist who understands the current market can translate the complex and rapidly-evolving product landscape into coverage that actually responds to the incidents organisations in your sector and size actually experience. If this sounds familiar, VPN No-Logs Policy is worth a look.
The claims process — what happens after an incident
Understanding the claims process before an incident occurs prevents costly mistakes during it. A well-managed claim begins in the first hours of an incident:
- Notify the insurer immediately. Call the 24/7 breach response hotline (not email). The notification clock starts when the incident is discovered, not when you call — delayed notification is the most common reason for claim complications. Have the hotline number and policy number accessible in a physical document, not only in the email system that may be compromised.
- Do not engage third-party responders without insurer approval. Hiring your own forensics firm, PR agency, or legal counsel before the insurer approves may result in those costs not being covered. The insurer typically wants to deploy their approved panel firms. Notify the insurer first, then engage the panel firms they direct you to.
- Document everything from the moment of discovery. Timestamped notes of who discovered the incident, what they did, who was notified and when, and every action taken create the claims record. The forensics investigation relies on this contemporaneous documentation — gaps in the timeline create gaps in the claim.
- Preserve evidence. Don’t wipe or restore systems before forensics has collected the evidence needed to determine scope and root cause. An insurer may deny a claim where evidence was destroyed before the investigation could determine what happened.
- Do not pay a ransom without insurer approval. Most policies require insurer approval for ransomware payments and provide specialists who assess whether payment is genuinely necessary and negotiate with attackers. Paying without approval may not be covered; insurers also have access to decryptors for some variants that make payment unnecessary.
Coverage comparison — what to ask for in each category
| Coverage category | What to verify | Common gaps to watch for |
| Business interruption | Waiting period (hours before coverage kicks in), trigger definition, revenue calculation method | Long waiting periods (48h+); revenue calculated on profit rather than gross |
| Ransomware | Whether payment is covered; limit on payment coverage; extortion negotiation service | Sub-limits well below main policy limit; mandatory approval process |
| Regulatory fines | Whether explicitly included; which regulations covered; jurisdiction of coverage | Complete exclusion; covered in some but not all jurisdictions |
| Social engineering fraud | Whether covered at all; limit; conditions (training requirement) | Complete exclusion from base policy; separate rider required |
| Nation-state war exclusion | Exact language of exclusion; whether attribution threshold is clear | Vague attribution language that could apply to sophisticated non-state attackers |
| Notification costs | Per-record limit; credit monitoring period covered | Per-record costs capped below actual cost |
| Forensics and remediation | Whether panel firm is pre-approval required; time limit on coverage | Required use of panel firms of variable quality |
Cyber insurance is most valuable as part of a broader security programme rather than as a substitute for one. Insurers have become sophisticated enough to know the difference: an organisation that invests in security controls reduces both the likelihood of an incident and the likely severity of claims, while organisations that purchase insurance hoping it will cover the consequences of inadequate security increasingly find coverage unavailable or prohibitively expensive. The cyber insurance application process, approached as a structured security review rather than just a purchasing exercise, is one of the most practically useful ways for small businesses to identify and close their highest-priority security gaps. Our guide on Small Business Cybersecurity covers an adjacent issue.







