Skip to main content
Quote My Policy

Cyber liability insurance

The expensive part is never the computers.

Standard property and liability forms were written for physical things. A data breach or a ransomware event is generally either excluded from them or capped far below what the incident costs.

Cyber cover exists because the loss has a shape nothing else insures: no physical damage, a great deal of expense, and most of it arriving in the first fortnight.

First-party costs

These are your own costs of dealing with the incident, and they are usually the larger half for a small business.

  • Forensic investigation to establish what happened and what was taken
  • Notifying the people whose data was affected, which can be a substantial exercise in itself
  • Credit monitoring and support for those affected
  • Restoring data and systems
  • Business interruption from the downtime, which standard interruption cover generally will not pay because there is no physical damage
  • Extortion costs where a ransom demand is involved
  • Public relations and crisis management

Third-party liability

These are claims made against you: by customers whose data was exposed, by partners whose systems or information were affected, and by regulators.

Defence costs are covered as they are on other liability policies, and here they are often the dominant expense because these claims are argued at length.

Regulatory fines and penalties are treated variably — sometimes covered where legally permitted, sometimes excluded entirely. It is a specific question worth asking rather than assuming either way.

The incident response service

The genuinely useful part of a cyber policy for a small business is often not the money but the response service attached to it: a number to call that produces forensic, legal and communications help immediately.

Most small businesses have no plan for the first twenty-four hours, and the first twenty-four hours determine the size of everything that follows.

That service usually has to be engaged through the insurer rather than arranged independently, so knowing how to trigger it before an incident is part of holding the cover.

What is usually required or excluded

Insurers increasingly ask about controls and treat the answers as conditions rather than as background — multi-factor authentication, backups, patching, staff training.

Answering those questions inaccurately is dangerous, because a claim can turn on whether the control described actually existed.

Common exclusions include failures the business knew about and did not address, and losses arising from unsupported systems. As with everything else on a commercial policy, cover follows what the insurer was told.

Who needs it

The test is not size. It is whether you hold data someone would want, or depend on systems you could not trade without — which now describes almost every business.

Businesses holding payment details, health information or large volumes of personal data are the obvious cases. So is any business whose operations stop entirely when its systems do.

Client contracts increasingly require it, particularly where you handle a client's own data, which is bringing it into businesses that would not otherwise have considered it.

Common questions

  • Generally not, or only to a limit far below what an incident costs. Standard property and liability forms were not written for data losses, which is why cyber is a separate cover.

Want this priced for your situation?

This page is general information, not advice about your specific circumstances. A licensed insurance professional can tell you what’s actually available to you.

General information only, not insurance advice. Coverage, availability, and terms vary by insurer and by state, and are subject to underwriting. Quote My Policy LLC is a licensed insurance producer. Nothing here binds coverage.