What Does Cyber Insurance Cover (and What Doesn't It)?
Response costs, recovery, business interruption and liability, with exclusions that matter.
Cyber insurance typically covers the costs of responding to and recovering from a cyber incident: forensic investigation, legal counsel, notification and credit monitoring, data restoration, business interruption losses, extortion payments, and liability to third parties. It typically excludes losses caused by controls you said you had but did not, and it never replaces the controls themselves.
First-party coverage (your own losses)
- Incident response. Forensics, breach coaches, legal counsel, public relations.
- Notification and monitoring. Notifying affected individuals and providing credit monitoring where required.
- Data and system restoration. Rebuilding systems and recovering data.
- Business interruption. Lost income and extra expenses while systems are down, subject to waiting periods and limits.
- Cyber extortion. Ransom negotiation and, where lawful and approved, payment.
- Funds transfer fraud. Money lost to business email compromise, often sub-limited.
Third-party coverage (claims against you)
- Privacy liability for exposed customer or employee data.
- Regulatory defense and, where insurable, fines and penalties.
- PCI assessments from card brands.
- Media liability.
Common exclusions and conditions
- Misrepresented controls. If the application said MFA was enforced everywhere and it was not, a claim can be reduced or denied.
- Unpatched or end-of-life systems in some policies.
- Acts of war and state-sponsored attacks, with evolving definitions.
- Prior known incidents.
- Sub-limits on ransomware, funds transfer fraud and business interruption that are much lower than the headline limit.
- Waiting periods before business interruption coverage starts.
Why the application matters as much as the policy
Insurers now require specific controls to write coverage at all: MFA, EDR, tested and offline or immutable backups, patching, privileged access management, email security, training and an incident response plan. Your answers are warranties. See the cyber insurance requirements checklist and, for sizing, how much cyber insurance a small business needs. An incident response plan should include your carrier's claims process.
Mentis Group helps Fully Managed IT clients implement the required controls, complete annual questionnaires accurately and support insurer audits through Enhanced Cybersecurity. This article is general information, not insurance advice; policy terms vary by carrier.
Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.