// Blog / Guide

Cyber insurance: what it actually covers (and what voids a claim)

Share

Cyber insurance has gone from a nice-to-have to something clients, lenders, and even some contracts now expect. But a policy is not a magic shield, and plenty of small businesses discover at the worst moment that their claim is smaller than they hoped, or denied outright. Knowing what a policy actually covers, and the ordinary mistakes that void it, is the difference between a safety net and a false sense of security. This is general guidance, not insurance advice.

What it typically covers

Most small business cyber policies split into two halves. First-party cover pays for your own costs after an incident: investigating what happened, restoring data and systems, lost income during downtime, notifying affected customers, and in many cases the ransom and negotiation in a ransomware event. Third-party cover pays for harm to others: legal costs and settlements if customer data is exposed, and regulatory fines where they are insurable. A good policy also comes with an incident-response team on call, which for a small business is often worth as much as the money, because someone experienced picks up the phone at 2 a.m.

What it does not cover

The gaps surprise people. Insurers generally will not pay for upgrading your systems to be more secure afterward (that is your investment, not their loss), for losses from a known vulnerability you left unpatched, or for money lost to ordinary invoice fraud if it falls outside the specific "social engineering" or "funds transfer fraud" section, which often carries a much lower sub-limit. Read what the payout ceilings are per category, not just the headline policy limit.

The part that voids claims: your own answers

Here is the trap. To get cover, you fill in an application attesting to your security: that you have multi-factor authentication, that you patch, that you keep backups, that you train staff. If a claim reveals those statements were not actually true, the insurer can reduce or refuse the payout on the grounds that you misrepresented your risk. In practice, the most common reason a cyber claim shrinks is that the business said it had a control it did not really have. The application is not a formality; it is effectively a set of promises you have to be able to keep.

How to actually qualify (and keep it valid)

Insurers now require real controls before they will quote, and the same controls keep a future claim valid:

  • MFA everywhere, especially email and remote access, ideally the phishing-resistant kind.
  • Tested, offline backups you can actually restore from.
  • Patching and endpoint protection that is genuinely in place, not aspirational.
  • Staff phishing awareness and a basic incident response plan.

Answer the application honestly, and if you cannot yet truthfully say yes to something, fix it before you sign rather than hoping it never gets tested. Our earlier piece on qualifying for cover goes deeper on the requirements.

Want your security to match what your cyber policy assumes?

Talk to us

Related