Cyber insurance can include first-party costs such as incident response, forensics, notification, data restoration, cyber extortion, and business interruption, plus third-party liability and regulatory defense. Coverage, sublimits, waiting periods, and vendor access vary significantly by policy.
Many policies offer ransomware response, recovery, and extortion coverage, subject to consent requirements, sanctions law, security representations, deductibles, and sublimits. The insurer’s breach-response team should be contacted before negotiating or incurring major costs whenever possible.
Funds-transfer fraud and social engineering often require a specific endorsement and may have a separate, lower limit. Verify whether coverage addresses employee deception, fraudulent instructions, invoice manipulation, and both incoming and outgoing payment fraud.
Some policies cover qualifying lost income and extra expense during downtime caused by a covered cyber event, often after a waiting period. Review the restoration period and whether dependent systems, cloud providers, voluntary shutdown, or system failure are included.
Carriers commonly evaluate multifactor authentication, protected backups, endpoint detection, email filtering, patching, employee training, privileged access, vendor controls, and an incident-response plan. Application answers must accurately describe controls that are actually operating.
Expect questions about revenue, industry, records and sensitive data, payment activity, vendors, remote access, cloud services, security controls, prior incidents, and requested limits. Coordinate insurance, IT, and management responses so the application is complete and consistent.