Cyber insurance covers losses from security incidents — response costs, business interruption, liability to third parties, and sometimes extortion payments. Coverage disputes rarely turn on whether an incident occurred; they turn on notice timing, panel-vendor requirements, and whether the insured's security representations at underwriting were accurate.
What the policy is actually made of
Cyber policies bundle several distinct coverages, and organisations frequently discover which ones they bought during a claim:
First-party — the insured's own costs: forensic investigation, legal advice, notification and credit monitoring, public relations, business interruption, data restoration, and in some policies extortion payments.
Third-party — liability to others: defence and settlement of claims by affected individuals, regulatory proceedings, and fines where insurable.
Business interruption is where expectations and policy language diverge most. Many policies impose a waiting period before interruption losses begin to accrue, and calculate loss against a contractual definition of income that may not match how the business measures it.
The three ways coverage is lost
Late notice. Most policies are claims-made and require prompt notice. "We wanted to understand the incident before reporting it" is a common and sometimes fatal instinct.
Off-panel vendors. Insurers maintain approved lists of forensic firms, breach counsel and notification providers, and often require pre-approval before costs are incurred. Retaining a trusted firm on day one, before calling the insurer, can leave those costs uncovered even though the work was necessary and well done.
The application. Underwriting increasingly turns on specific control attestations — multi-factor authentication on remote access, endpoint detection coverage, backup practices, patching cadence. Where a control was represented as universal and was not, insurers have rescinded or denied. The person who signs the application is frequently not the person who knows whether the answers are true, and closing that gap before renewal is cheaper than arguing about it afterwards.
War and state-actor exclusions
Exclusions for hostile or warlike acts were written for a different kind of loss and have been litigated hard as attacks attributed to state actors caused large commercial damage. Markets have responded with more specific state-backed-attack wording, which has narrowed the ambiguity in some policies and broadened the exclusion in others.
The practical point for an insured is that attribution is contested, slow, and outside their control, so a clause whose operation depends on it introduces genuine uncertainty. Reading that wording carefully at placement is worth more than any argument available after a claim.
Using it well
- Notify early, even where the incident's severity is unclear. Notice is cheap and its absence is not curable.
- Check the panel before retaining anyone, and negotiate preferred vendors onto the panel at placement rather than during a crisis.
- Involve the people who operate the controls in the application.
- Model the interruption cover against how the business actually loses money, not against the headline limit.
What it is not
Insurance transfers financial loss. It does not transfer the regulatory obligation, the litigation, or the reputational consequence, and it does not restore the data. Organisations that treat a policy as a substitute for controls tend to discover both limits in the same week.
From our work
Dealing with cyber insurance in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
