Cyber Insurance

A policy that pays for the clean-up after an attack, with conditions that can quietly cancel the cover.

Also known as cyber liability insurance cyber risk cover data breach insurance

Definition

Cyber insurance is a policy that pays out when something goes wrong with your computers or your data. A break-in. Stolen customer records. A system locked up until you pay. A member of staff tricked into sending money to a fake supplier. Your normal business insurance usually covers none of that.

A policy pays for the work that follows the incident more than for the damage you picture. The specialists who find out how the attacker got in. The lawyers. The cost of telling every affected customer. The income lost while you could not trade. Sometimes the ransom, sometimes the fine, sometimes a claim a customer makes against you. Check which of those your quote actually includes, because they are priced separately and a cheap policy quietly leaves out the expensive ones.

The conditions are where the trouble sits. Most insurers now require a second step at every login, so a stolen password on its own is not enough to get in. They require backups you have actually restored from, not backups that merely run each night. They require you to report an incident within a stated number of hours, often 72, and a claim raised two weeks later can be refused for that alone. Some ask you to install security updates within a set time. None of this is hidden. It is simply in the part nobody reads.

The application form is a legal document. If you answer yes to two-step login because you believe someone set it up, and the insurer later finds one account without it, the claim can fail. Answer what is true today. Where the answer is no, say no, then ask what it would cost to fix. That conversation is far cheaper than a refused claim, and it is a normal part of any cybersecurity review.

Linkysoft is often asked to check a client's questionnaire before it goes back to the broker. Half the time an answer has to change. Backups are the usual one. The copies run every night, but nobody has ever put a file back from them, so nobody knows whether they work. Test a restore before you sign. If your customer data sits in a web application, ask Linkysoft or whoever maintains it to prove that test in writing.

Questions about Cyber Insurance

Does my normal business insurance cover a hack?
Usually not. A standard policy covers damage you can see, like fire or a stolen laptop. Lost data, ransom demands and customer claims sit in a separate cyber policy.
What makes an insurer refuse to pay?
A wrong answer on the application form, a late report, logins with no second step, or backups nobody ever tested. Each of those is avoidable in an afternoon.
Is cyber insurance worth it for a small company?
Work out what a week without your system would cost. If you hold card or health details, telling everyone after a loss usually costs more than a year of premium.
Do I need two-step login before I can buy a policy?
In most markets now, yes, at least for email and remote access. Insurers treat it as the cheapest single change that prevents most claims.
How fast must I tell the insurer?
Find the number in your own policy and pin it on the wall. It is often 72 hours from the moment you notice, not from the moment you understand.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.