top of page

What does cyber insurance cover? And not cover?

May 23, 2022
7 min read

Updated: Aug 18


Updated August 17, 2026

Man in suit studies a cyber insurance clipboard at a desk with a laptop; bold text asks, What does cyber insurance cover? and not cover?

Kosh gets asked all the time about cybersecurity and what cyber insurance actually covers—and whether a business even needs cyber insurance. If you're still deciding whether coverage makes sense for your organization, see our article: Is Cyber Insurance Necessary for My Business?.


When we first put this guide together, we asked insurance brokers in New Mexico and Orange County to help break down what they commonly saw covered and not covered by cyber insurance.


Nickie Tran, President of IQ Risk Insurance Services in Orange County, identified several of the biggest costs cyber insurance may help protect against:

  1. Legal fees and expenses

  2. Customer notifications following a breach

  3. Credit or identity monitoring for affected individuals

  4. Recovery of compromised data

  5. Repair and recovery of computer systems


Those remain good examples, but cyber insurance has continued to evolve.

Modern cyber policies can combine first-party coverage for losses your own business suffers with third-party coverage for claims made against your business.


Depending on the policy, coverage may address ransomware, data breaches, business interruption, cybercrime, regulatory proceedings, social engineering, funds-transfer fraud and other cyber events.


The important phrase is depending on the policy.

Cyber insurance policies are not all the same. Definitions, exclusions, sublimits, deductibles or retentions, waiting periods and coverage triggers can vary significantly between insurers.

Related Articles:

Use the calculator below to get a rough idea of what a significant cyber incident could cost your organization.




Costs Typically Covered by Cyber Insurance


Ransomware and Cyber Extortion

Cyber insurance may cover costs related to a ransomware attack, including:

  • Cybersecurity and forensic specialists brought in to investigate the attack, determine how the attacker entered the environment and help contain the incident

  • Data and system restoration

  • Legal and incident-response assistance

  • Business interruption and lost income while covered systems are unavailable

  • Cyber-extortion specialists who negotiate with an attacker

  • A ransom payment when the payment is lawful, permitted under the policy and approved by the insurer

  • Public relations or crisis-management expenses


Ransomware coverage does not mean paying the ransom is automatically the best option.


The response should be coordinated with your insurer, legal counsel, incident-response specialists and law enforcement when appropriate.

See our article on ransom decisions: Pay for Backups or Pay the Ransom?

Data Breaches and Privacy Incidents

A data breach can create expenses long after the technical problem itself has been fixed.

Depending on the policy, cyber insurance may help cover:

  • Forensic investigation

  • Legal counsel

  • Restoring systems and data

  • Breach-notification expenses

  • Call-center services

  • Credit or identity monitoring for affected individuals

  • Public relations and crisis communications

  • Defense against lawsuits from customers or other third parties

  • Regulatory defense costs

  • Certain regulatory fines and penalties where they are legally insurable


This is where the difference between first-party and third-party coverage becomes useful.


First-party coverage generally addresses costs your own organization incurs responding to the incident.


Third-party coverage generally addresses liability when customers, employees, vendors or others allege they were harmed because of the incident.


Business Email Compromise and Funds-Transfer Fraud

This deserves much more attention today than it did when we originally published this article.


An attacker may compromise an employee's email account, impersonate an executive or vendor, change payment instructions, or convince an employee to wire money to a fraudulent account.


Depending on the policy and coverage selected, cyber or crime insurance may provide protection for:

  • Funds-transfer fraud

  • Social-engineering fraud

  • Fraudulent payment instructions

  • Invoice manipulation

  • Certain phishing and impersonation events


But don't assume this is automatically included with a large limit just because you have a cyber policy.


Social-engineering and funds-transfer coverage can have their own definitions, exclusions, conditions and sublimits.


If your business routinely wires large amounts of money, this is something worth specifically discussing with your broker.


Business Interruption

A cyberattack does not need to steal data to become expensive.


If ransomware, malware, a denial-of-service attack or another covered event takes important systems offline, cyber insurance may help cover lost income and certain additional expenses during the interruption.


Some policies can also offer dependent business interruption coverage.

That addresses certain losses caused when a third-party technology provider or other dependent organization experiences a qualifying event that disrupts your business.


For a company heavily dependent on cloud services, hosted software or outside technology providers, this is an increasingly important part of the coverage conversation.


Data and System Restoration

Cyber insurance may also cover expenses associated with rebuilding or restoring damaged software, systems and electronic data.


This is different from simply reimbursing a company for the theoretical value of the information.


The coverage generally focuses on the costs associated with recovering, repairing, recreating or restoring covered systems and data.


Costs That May Not Be Covered by Cyber Insurance

This is where we need to be careful with the word “not.”


There is no universal list of exclusions applying to every cyber policy. Some things that one policy excludes may be covered or available by endorsement under another.


However, businesses should pay close attention to the following areas.


War and State-Sponsored Cyberattacks

Cyber policies may contain exclusions or limitations involving war, hostile acts or certain state-sponsored cyber activity.

Exactly how those provisions apply depends heavily on the wording of the particular policy and the circumstances of the event.

This has become an important area of cyber-insurance policy language, so businesses concerned about systemic or nation-state attacks should specifically ask their broker how the policy addresses them.


Intellectual Property

Cyber insurance generally should not be assumed to reimburse your company for the lost future value of intellectual property or trade secrets that are stolen.

A cyber incident involving intellectual property may create covered response expenses, but that is different from an insurer reimbursing the business for what the stolen idea, formula, design or trade secret might have been worth.


Technology Upgrades and Betterment

Our original version of this article listed technology improvements as something cyber insurance didn't cover.


That is now too broad.


Some policies may primarily pay to restore systems to their previous condition and not fund a wholesale modernization of your technology.


However, some insurers now specifically offer betterment coverage, which can pay for certain improvements recommended after a breach to eliminate vulnerabilities that could lead to another incident.


This is a good example of why the specific policy language matters.


Known Problems and Events Outside the Policy

Insurance generally isn't intended to cover every existing technology problem a company already knows about.


Questions involving known incidents, prior breaches, events occurring before coverage began, or circumstances not reported within the required period can become complicated quickly.


Your broker should explain how the policy's effective dates, reporting requirements and exclusions apply.


Split infographic on cyber insurance: covered items left, exclusions right, with shield icons and Kosh Solutions logo.

Don't Forget About Sublimits

A business may proudly say:

“We have a $2 million cyber insurance policy.”

That doesn't necessarily mean $2 million applies to every kind of cyber loss.

The policy might have different limits or sublimits for:

  • Social engineering

  • Funds-transfer fraud

  • Cyber extortion

  • Business interruption

  • Dependent business interruption

  • Data restoration

  • Reputational harm

  • Other specific insuring agreements


There may also be waiting periods, retentions or other conditions.

This is why comparing cyber policies based solely on the headline premium and total policy limit can be misleading.


Technology Errors and Omissions

Lastly, it's important to understand that cyber liability insurance and Technology Errors and Omissions (Tech E&O) address different risks.


Tech E&O is particularly relevant for companies that provide technology products, consulting or services.


It can respond when a customer alleges that your company made an error, omitted something important or negligently performed its professional technology services and caused the customer financial harm.


Depending on the policy, Tech E&O may help with:

  • Attorney's fees

  • Court costs

  • Settlements

  • Judgments

  • Expert-witness and related defense expenses


For example, a cyber policy might respond when your own network is breached.

Tech E&O could become relevant if a technology company is sued because a customer claims its services, advice, software or implementation caused the customer's loss.


Some insurers allow businesses to purchase cyber and Tech E&O protection together.


Work with your insurance broker to determine whether your business has that exposure and what form of coverage makes sense.


Quick Cyber Insurance FAQ


Does cyber insurance cover data loss?

It can. Many cyber policies include coverage for expenses associated with restoring, recovering or recreating damaged electronic data and computer programs after a covered incident.


That doesn't necessarily mean the insurer pays the business for the intrinsic or future value of whatever data was lost.


Does cyber insurance cover ransomware?

Cyber policies commonly offer coverage for ransomware-related expenses, including incident response, system and data restoration, business interruption and cyber extortion.


The exact coverage depends on the policy.


Does cyber insurance cover stolen money?

Sometimes. Funds-transfer fraud and social-engineering coverage may protect against certain fraudulent payments or transfers, but these coverages can have separate limits, conditions or exclusions.


Ask your broker specifically how your policy handles BEC, social engineering and funds-transfer fraud.


Do you have a Cyber Insurance Coverage Checklist?

Yes. Kosh developed a checklist covering many of the technical questions businesses encounter when applying for cyber insurance.


What are the benefits of cyber insurance?

Cyber insurance helps transfer part of the financial risk associated with a cyber incident.


Just as importantly, a good cyber policy can give a business rapid access to specialized resources such as breach counsel, forensic investigators, incident-response professionals, notification services and crisis-management experts.


Cyber insurance does not replace cybersecurity. The two work together.


Are there cyber insurance coverage limits?

Yes. Every cyber policy has limits, and individual types of coverage may have their own sublimits, retentions or waiting periods.


Rather than assuming a certain dollar amount is appropriate for every small or midsized business, work with your insurance broker to determine what limits make sense based on your organization's revenue, data, operational dependency, contractual obligations and potential loss exposure.


The Bottom Line

Cyber insurance can cover considerably more than ransomware.

A well-designed policy may address breach response, privacy liability, business interruption, cybercrime, data restoration, ransomware, social engineering and other losses.


But having cyber insurance and having the right cyber insurance are not necessarily the same thing.


Ask your broker to walk through the actual insuring agreements, limits, sublimits, exclusions and conditions—not just the premium and the number at the top of the policy.


And make sure your IT and cybersecurity team understands the technical safeguards your insurer expects you to maintain.

Those two conversations belong together.

Disclaimer

The information contained in this communication is intended for limited use for informational purposes only. It is not considered professional advice, and instead, is general information that may or may not apply to specific situations. Each case is unique and should be evaluated on its own by a professional qualified to provide advice specifically intended to protect your individual situation. Kosh is not liable for improper use of this information.



Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page