Key takeaways
- Cyber insurance splits into first-party coverage for your own breach response and recovery and third-party liability for harm to other people's data or systems.
- The headline limit rarely tells the whole story, because ransomware, social engineering, and regulatory fines are often capped by sublimits well below it.
- A cyber limit on its own carries no verdict, so judge it against the coverage standard for the same risk and against any minimum a contract sets.
- Advocate uses the Coverage Gap Analysis to compare a cyber policy against the coverage standard for its risk, surfacing thin limits, retentions carried for the wrong reason, and sublimit gaps.
What is cyber insurance?
Cyber insurance, also called cyber liability insurance, covers the financial consequences of a cyber incident, from a data breach or ransomware attack to a system failure that interrupts the business. It exists because a standard commercial general liability or commercial property policy was never designed for digital risk and generally excludes it.
A cyber policy has two sides. First-party coverage pays the insured's own costs to respond and recover, and third-party coverage pays what the business owes others when their data or systems are harmed. Most commercial cyber policies bundle both, but the split is the first thing to read, because a policy heavy on one side can leave a real gap on the other.
First-party versus third-party cyber coverage
Coverage | Side | What it pays for |
|---|---|---|
Breach response and notification | First-party | Forensics, legal, notifying affected individuals, credit monitoring |
Data restoration | First-party | Recovering or recreating data and systems after an attack |
Cyber extortion / ransomware | First-party | Ransom negotiation and payment, subject to policy terms |
Business interruption (cyber) | First-party | Lost income while systems are down from a covered event |
Privacy and network liability | Third-party | Claims from others whose data or systems were harmed |
Regulatory defense and fines | Third-party | Defense and, where insurable, fines from a privacy regulator |
Media liability | Third-party | Defamation or copyright/trademark infringement in digital content |
Coverage varies by insurer and form. Sublimits often apply to ransomware, social engineering, and regulatory fines, so the headline limit is rarely the whole story.
Common exclusions, and where the risk is covered instead
Typically excluded | Where it is usually covered |
|---|---|
Bodily injury and property damage | A commercial general liability policy, which is the standard home for third-party bodily injury and physical property damage claims. |
Physical loss or damage to hardware and other tangible property | A commercial property policy; physical loss or damage to computers, servers, and other tangible property is a property peril, not a cyber one. |
Prior known incidents and acts before the retroactive date | The policy that was in force when the matter was first known or should have been reported; carrying an unbroken retroactive date forward when you change insurer is what keeps this from becoming a gap. |
War and state-sponsored or hostile cyber acts | Largely uninsurable in the standard market; only narrow, separately negotiated terrorism or war terms address any part of it. |
Fraudulent funds transfer and social engineering (unless endorsed) | A commercial crime or fidelity policy, which is built to respond to theft of money and securities; some cyber forms add it back by endorsement, usually sublimited. |
Patent and trade-secret infringement | A specialist intellectual property policy; cyber forms respond to data and privacy events, not infringement or misappropriation of IP. |
Failure of third-party utility or infrastructure | Rarely insurable on the base form; outages of the public power grid, internet backbone, or telecom carriers sit outside the insured's own network, and only limited dependent-provider endorsements touch it. |
Exclusions vary by form and endorsement. Confirm the actual policy wording.
How cyber limits and retention work
A cyber policy is written with a policy limit, the most it will pay, and a retention, the amount the insured pays out of pocket before the coverage responds, similar to a deductible. Both are usually sized to the business's revenue and to how much sensitive data it holds, since a company processing millions of records carries far more breach exposure than its revenue alone suggests.
The detail that decides a claim is often a sublimit. Ransomware, social engineering fraud, and regulatory fines are frequently capped below the headline limit, so a policy can look adequate and still leave a gap on the exact event that occurs. Reading the sublimits is where a benchmark against the standard for the risk earns its keep.
Who needs cyber insurance, and when it is required
Any business that holds customer data, takes payments, or depends on connected systems carries cyber exposure, which today is nearly every business. Technology and professional-services firms, healthcare, and retail carry the most, but a contractor or manufacturer with email and a payroll system is exposed too. That is why cyber has moved from a specialty buy to a standard line in most commercial coverage programs.
Cyber is also increasingly contractually required. Enterprise customers, lenders, and vendor agreements now often demand a minimum cyber limit and evidence of coverage on a certificate. Some also ask to be named, though additional-insured status is far less standardized on cyber forms than on general liability. Confirming a required cyber limit on a certificate is a growing part of certificate of insurance tracking.
How to tell if a cyber policy is enough
A cyber limit on its own carries no verdict. The way to tell whether it is enough is to compare the policy against the coverage standard for the same risk, holding the exposure constant, and against any minimum a contract sets, paying close attention to the ransomware and regulatory sublimits. That comparison is a coverage gap analysis.
Advocate benchmarks a cyber policy against the standard for its risk through it's Coverage Gap Analysis, flagging thin limits, low retentions carried for the wrong reason, and sublimit gaps across the program. This is general guidance, not legal or coverage advice. Verify the actual policy, its sublimits, and any contract requirement.
Explore
Keep exploring
FAQ
Frequently asked questions
What is cyber insurance?
Cyber insurance, also called cyber liability insurance, covers a business's financial loss from data breaches, ransomware, and network failures. It has a first-party side that pays the insured's own recovery costs and a third-party side that pays what the business owes others whose data or systems were harmed. Standard general liability and property policies generally exclude this digital risk.
How can I tell if my cyber policy has a coverage gap?
Compare it against the coverage standard for the same risk, holding the exposure constant, and against any contract minimum, with close attention to the ransomware and regulatory sublimits. Advocate benchmarks a cyber policy against that standard through Coverage Gap Analysis, flagging thin limits, mismatched retentions, and sublimit gaps before an incident finds them.
What does cyber insurance cover?
A commercial cyber policy typically covers breach response and notification, data restoration, cyber extortion and ransomware, business interruption from a cyber event, privacy and network liability to third parties, regulatory defense and insurable fines, and media liability. The exact mix and any sublimits vary by insurer and form.
What is the difference between first-party and third-party cyber coverage?
First-party cyber coverage pays the insured's own costs to respond and recover, such as forensics, notification, data restoration, ransomware, and lost income. Third-party coverage pays what the business owes others, such as liability for exposed data, regulatory defense, and media liability. Most commercial policies bundle both, but the balance between them matters.
Show 8 more questionsShow fewer questions
How much does cyber insurance cost?
The premium depends on revenue, the volume and sensitivity of the data held, the industry, the security controls in place, and the limit and retention chosen. Because rates move with the threat environment, a cyber premium is best read against the market for comparable risks rather than in isolation.
What are typical cyber insurance limits?
Limits are usually sized to revenue and data exposure, and many small and mid-size businesses carry limits in the low single-digit millions, with larger or data-heavy firms carrying more. The headline limit is only part of the picture, because ransomware and regulatory sublimits often cap the coverage below it.
What is a retention on a cyber policy?
The retention is the amount the insured pays out of pocket on a covered claim before the policy responds, similar to a deductible. A higher retention lowers the premium but increases what the business absorbs on an incident. Sizing the retention to what the business can comfortably fund is part of getting the policy right.
Does cyber insurance cover ransomware?
Most cyber policies include cyber extortion coverage that can pay ransom negotiation and payment, subject to the policy terms and any sanctions restrictions. Ransomware is frequently written with a sublimit below the headline policy limit, so confirming that sublimit is essential rather than assuming the full limit applies.
What does cyber insurance not cover?
Common exclusions include prior and pending incidents known before the policy started, bodily injury and property damage (which sit on general liability and property), and, on many forms, widespread infrastructure or war-related cyber events. Reading the exclusions and sublimits is how you find the real edges of the coverage.
Is cyber insurance required?
It is not legally mandated for most businesses, but it is increasingly required by contract. Enterprise customers, lenders, and vendor agreements often demand a minimum cyber limit and evidence of coverage on a certificate. Some also ask to be named, though additional-insured status is far less standardized on cyber forms than on general liability.
Who needs cyber insurance?
Any business that holds customer data, takes payments, or relies on connected systems, which is nearly every business today. Technology and professional-services firms, healthcare, and retail carry the most exposure, but any company with email and a payroll system is exposed. It has become a standard line in most commercial programs.
Is cyber insurance the same as technology errors and omissions?
No, though they are often bought together. Cyber covers the loss from breaches and network events. Technology errors and omissions covers a technology company's liability when its product or service fails to perform as promised. A tech firm frequently needs both, and some insurers combine them on one form.
See whether a cyber policy meets the standard for its risk.
14 days of Premium, free. No credit card. Value in 10 seconds.