Cyber Insurance: What It Actually Covers
A plain-English guide to what a cyber insurance policy really pays out for, the exclusions that catch businesses out, and how to read yours before you need it.
Cyber insurance is a policy that helps cover the cost of a cyber attack or data breach — the money you spend cleaning up the mess, and the money you owe other people because of it. That’s the whole idea in one sentence. Everything else is detail about what counts as “the mess” and where the insurer draws the line.
It’s worth understanding that detail before you buy, and certainly before you claim. A lot of businesses discover what their policy actually does — and doesn’t — do at the worst possible moment, halfway through an incident. This guide walks through what a typical policy covers, the exclusions that catch people out, who genuinely needs it, and how to read yours properly.
What a cyber insurance policy usually includes
Most policies split into two halves: costs you incur, and costs you cause other people. The first-half items are the ones you’ll likely lean on most.
- Incident response. Access to a specialist team who investigate what happened, contain it and help you recover. For many businesses this is the single most valuable part — you’re not left googling “what do I do” during a live attack.
- Data recovery and system rebuild. The cost of restoring systems and getting data back after ransomware or deletion. Note this assumes there’s something to restore from — which is where your own backups still matter enormously.
- Business interruption. Lost income while you’re offline. If an attack takes your systems down for days, this covers some of the trading you couldn’t do.
- Ransom and extortion. Where covered, the cost of dealing with a ransom demand — often with strict conditions attached.
- Legal and regulatory costs. Help with your obligations after a breach, including notifying the ICO and affected people, plus any fines the policy is allowed to cover.
- Third-party liability. Claims from customers, suppliers or partners whose data was exposed because of an incident on your side.
The mix and the limits vary a lot between insurers, which is exactly why two quotes at similar prices can offer very different protection.
The exclusions that catch businesses out
This is the part worth reading twice. Insurers pay out on the basis that you held up your end, and the exclusions are where claims quietly fall apart.
- Poor security you declared as good. The application form asks whether you have multi-factor authentication, patching, tested backups and staff training. If you answered yes and the reality was no, that’s grounds to reduce or refuse a claim. The form is effectively part of the contract.
- Unpatched, known vulnerabilities. If an attacker walked in through a flaw that had a fix available for months and you never applied it, some policies won’t cover the fallout. Ongoing managed IT support that keeps systems patched isn’t just good hygiene — it protects the policy too.
- Human error and authorised transfers. Many policies treat invoice fraud or someone being tricked into sending a payment differently from a “hack”. Social engineering and funds-transfer fraud are often a separate section with their own, lower limit — or excluded entirely.
- Prior incidents. Anything you knew about, or reasonably should have known about, before the policy started.
- Nation-state and “act of war” clauses. A grey area that has grown in recent years, sometimes used to contest large ransomware claims linked to state-backed groups.
None of these mean cyber insurance is a con. They mean it’s a contract that rewards a business already doing the basics — and penalises one that treats the policy as a substitute for proper security.
Who needs it, and when
If your business would struggle to trade for a few days without its systems, or you hold personal or financial data about other people, cyber insurance is worth serious thought. Law firms, accountants, dental practices, agencies — anyone holding client data or moving client money — sit squarely in the frame. So does any business that relies on online ordering, cloud tools or a busy inbox.
The right moment to sort it is before you need it, obviously, but also after you’ve got the fundamentals in place — not instead of them. Buying a policy while your backups are untested and staff have never had security training is buying something you may not be able to claim on. Get the basics running first; the insurance then covers the residual risk that no defence fully removes.
Read it before you need it
The single most useful thing you can do is read your policy while nothing is wrong. Check the limits, find the exclusions, and confirm the security controls it assumes you have are actually switched on. If the application asked about MFA and backups, make sure those are genuinely in place across the business — not on the to-do list.
If you’d like a hand lining your defences up with what your insurer expects — MFA, patching, tested backups, staff awareness — we’re happy to review your setup and tell you honestly where the gaps are. You can get in touch for a straight conversation, no jargon and no pressure.
Frequently asked questions
Does cyber insurance pay the ransom if we get hit by ransomware?
Many policies do cover ransom payments, but not automatically. The insurer usually has to approve it, will insist on using their own incident team first, and may decline if paying would breach sanctions rules. Cover for the ransom itself is also increasingly capped or sold as an add-on, so read that section carefully rather than assuming it's included.
Will a claim be refused if our security wasn't up to scratch?
It can be. Most insurers now ask about specific controls — multi-factor authentication, patching, backups, staff training — when you apply. If you tick "yes" and it later turns out those controls weren't actually in place, the insurer can reduce or reject the claim. Answer the application honestly and make sure what you've described is genuinely running.
We're a small business. Do we really need it?
Small businesses are targeted precisely because their defences tend to be thinner. Insurance won't stop an attack, but it can cover the costs that would otherwise be crippling — forensic investigation, recovery, legal advice and lost income. Whether it's worth it depends on how much a few days offline would actually cost you, not on your headcount.
Related services
Want a hand with any of this?
Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.
