Cyber insurance can combine cover for the insured business’s own costs, liability to other people and access to incident-response specialists. There is no single standard wording, so the policy schedule, wording, endorsements, proposal answers and any cyber-security conditions must be read together.
This guide sits beneath the main Cyber Insurance UK guide and explains the common cover categories without treating them as automatic or universal.
Quick answer
A cyber policy may cover forensic investigation, incident containment, data restoration, business interruption, breach-response work, privacy and network-security liability, cyber extortion and selected cybercrime losses. Some policies also provide pre-incident risk tools and a 24-hour response line.
The words “may cover” are important. Each category can have its own trigger, excess, waiting period, sub-limit, territorial scope, consent rule and exclusion.
First-party and third-party cover
First-party cover concerns loss or expenditure suffered by the insured organisation. Examples include restoration costs, incident-response fees or lost income during a covered outage.
Third-party cover concerns claims or proceedings brought by customers, employees, clients, regulators or other people. Examples include a privacy claim or an allegation that insecure systems caused another organisation loss.
Some costs do not fit neatly into one label. Legal advice, notification work and communications support can be incident-response benefits rather than compensation for a final liability.
Incident response and forensic investigation
A policy may provide access to an incident manager, forensic investigator, lawyer, data-breach specialist or public-relations adviser. This can be valuable because the business may need technical containment, legal assessment and communications decisions at the same time.
Check:
- whether the insurer must be contacted before a supplier is appointed;
- whether the business may use its usual IT provider;
- whether emergency expenditure can be approved retrospectively;
- which costs fall within a sub-limit;
- whether the panel firm works for the insurer, the insured or both;
- how privilege and confidentiality are handled;
- whether the response service is available for a suspected incident.
A cyber incident plan should include the correct policy contact and an offline copy of the key details. The Business Insurance Documents guide can help organise the schedule, wording and endorsements that control the response.
Data restoration and system recovery
Data-restoration cover may pay reasonable costs to restore or recreate data and software damaged, encrypted, corrupted or deleted by a covered event. It can also contribute to rebuilding systems to their pre-incident state.
Common limitations include:
- no cover for the economic value of the data itself;
- no payment for upgrades or improvements beyond the previous state;
- a requirement to restore from available backups;
- exclusions for unsupported software or known defects;
- limits on hardware replacement;
- proof that the expenditure is necessary and reasonable.
A backup is useful only if it can be restored. Insurers may ask about frequency, isolation, access controls and testing.
Business interruption
Cyber business-interruption cover can address loss of income and increased cost of working when a covered event prevents or reduces normal operations.
The calculation may depend on historic trading, trends, saved expenses and the steps taken to reduce loss. Check:
- the waiting period before cover begins;
- the maximum indemnity period;
- whether partial degradation is enough or a total outage is required;
- whether voluntary shutdown is covered;
- whether interruption at a cloud, payment, hosting or technology supplier is included;
- whether non-IT suppliers are excluded;
- how seasonal or fast-growing businesses prove the expected result.
A short waiting period can still create a material uninsured amount. A dependent-system extension may list or define which suppliers count.
Extra expense and increased cost of working
A business may need temporary hardware, alternative software, overtime, specialist contractors, emergency communications or a replacement supplier. Cover may pay reasonable additional costs incurred to continue or restore operations, but only within the policy’s trigger and approval rules.
The cheapest recovery option is not always the fastest, while the fastest may not be reasonable under the wording. Record why a decision was made and seek insurer consent where required.
Privacy-breach response
A policy may fund legal assessment, notification, mailing, call-centre support, credit monitoring or identity-protection services following a covered personal-data breach.
These services do not transfer the controller’s legal responsibility. The organisation must decide whether the breach is reportable to the ICO and whether affected individuals must be told. Where Article 33 applies, notification is required without undue delay and, where feasible, within 72 hours of awareness.
Not every breach justifies every service. Communication should be accurate, proportionate and coordinated with the legal and forensic facts.
Privacy and network-security liability
Privacy liability may respond to claims alleging unlawful disclosure, loss or misuse of personal or confidential information. Network-security liability may address claims alleging that the insured failed to secure systems, allowed malware to spread or enabled unauthorised access.
The wording may cover defence costs and covered damages. It may restrict:
- liability accepted only under a contract;
- claims between related entities;
- contractual service guarantees;
- intellectual-property disputes;
- deliberate conduct;
- events known before the policy began.
Technology businesses should compare these provisions with professional indemnity cover rather than assume that either policy automatically covers the whole client dispute.
Regulatory investigations and proceedings
Some policies pay legal and expert costs arising from a covered privacy or security investigation. The policy may refer to a regulator, supervisory authority or privacy proceeding.
Cover for a fine or penalty is separate. Payment may be excluded, may depend on whether it is legally insurable, and may be subject to public-policy limits. A page or sales summary that says “regulatory cover” should not be read as a promise that every regulatory amount will be paid.
Cyber extortion and ransomware
Cyber-extortion cover can include specialist response, investigation, negotiation and, where lawful and insured, an extortion payment. It may also address restoration and interruption under other sections.
The NCSC and UK law-enforcement bodies do not encourage, endorse or condone ransom payment. Payment does not guarantee decryption, deletion of stolen data or protection from another demand. Sanctions and other legal restrictions can also make payment unlawful.
Check whether the policy requires immediate contact with a named response firm and whether extortion has a separate limit.
Social engineering and loss of money
A fraudulent email that causes an employee to transfer money can look like a cyber event, but direct loss of funds is not always included. Policies may distinguish:
- computer fraud, where a third party directly manipulates a system;
- funds-transfer fraud;
- invoice manipulation;
- social engineering, where a person is deceived into authorising payment;
- theft from a customer or supplier rather than the insured.
Cover may require a separate extension and may impose verification procedures, call-back controls or a low sub-limit. Compare the cyber policy with crime or fidelity cover.
Multimedia and website liability
Some cyber policies include liability arising from online content, such as defamation, privacy infringement or intellectual-property allegations. The exact definition of media activity and excluded rights matters.
This section should not be treated as a replacement for checking professional-indemnity, media-liability or intellectual-property cover where those risks are central.
Dependent-system and supply-chain cover
A business can be interrupted by a cyber event at a cloud host, software provider, managed-service provider, payment processor or other supplier. Dependent-system cover may respond, but it can be narrow.
Check whether:
- the supplier must be named;
- only IT or cloud providers qualify;
- the supplier must suffer the same type of event covered under the insured’s own policy;
- there is a separate waiting period or limit;
- infrastructure, utility and internet failures are excluded;
- a regional or widespread outage is treated differently.
Supply-chain dependence should be part of the cost and limit review in the Cyber Insurance Costs for SMEs guide.
Common exclusions
The ABI identifies bodily injury and physical property damage as areas commonly excluded from cyber policies. Other common restrictions can concern known events, prior claims, deliberate acts, contractual liability, unsupported technology, failure to maintain controls, war or cyber operations, infrastructure failure and betterment.
Exclusions should be read with definitions and endorsements. An endorsement can restore, narrow or replace wording elsewhere in the policy.
Limits and sub-limits
The main limit may be shared across all claims during the period. Lower sub-limits can apply to:
- cyber extortion;
- social engineering;
- dependent-system interruption;
- breach-response services;
- data restoration;
- regulatory work;
- reward payments;
- reputational-harm loss.
Check whether legal and forensic fees erode the same limit available for interruption or liability. A serious incident can consume response costs before the final business loss or claim is known.
Notification and consent
Notify a suspected incident in accordance with the wording. Do not wait for certainty if the policy requires notice of circumstances, events or claims.
Before admitting liability, promising compensation, paying an extortion demand or appointing an expensive adviser, check the insurer’s consent and cooperation clauses. Preserve logs, emails, invoices, call records and decision notes.
The hypothetical cyber claim scenarios show how these conditions can affect different incidents.
Questions to ask before buying
- Which first-party events are covered?
- Which third-party claims are covered?
- Are social engineering and theft of funds included?
- Which suppliers qualify for dependent-system interruption?
- What are the waiting and indemnity periods?
- Which services use sub-limits?
- Are response and defence costs inside the main limit?
- Which security controls are conditions of cover?
- What happens if a control is temporarily unavailable?
- Which incident-response firms may be used?
- What territorial and jurisdiction limits apply?
- How does the policy interact with PI, crime, property and liability cover?
Next step
Use the main Cyber Insurance UK guide to map the cover against the organisation’s systems and then compare the price factors in Cyber Insurance Costs for SMEs. This is educational information, not a guarantee of cover or personalised advice.
System failure and non-malicious events
Some policies respond only to a malicious or unauthorised cyber event. Others include specified accidental system failure, administrative error or operational outage. This distinction matters where the service stops because of a configuration change, failed update or internal mistake rather than an attacker.
Check the definition of system failure, the waiting period and whether failure at an outsourced provider is included. A broad marketing description of “IT downtime” is not enough.
Reputational harm and lost customers
A limited number of policies include a defined reputational-harm loss, such as a reduction in income after adverse publicity following a covered event. The calculation can be difficult and may use a short indemnity period or low sub-limit.
Ordinary loss of goodwill, future opportunity or speculative customer behaviour may not be covered. Ask how the insurer distinguishes insured loss from wider market or trading changes.
Notification costs and voluntary services
A policy may offer credit monitoring, identity protection or call-centre services. These should be used where proportionate to the incident and approved under the wording. Offering a service before the affected population and risk are understood can create unnecessary cost or confusing communication.
The legal adviser, forensic investigator and communications specialist should coordinate facts so that notifications are consistent. A regulator, customer and insurer should not receive materially conflicting accounts without an explained reason.
Policy documentation check
Before relying on a cover summary, locate:
- the insuring clauses;
- definitions of cyber event, computer system, data and dependent system;
- exclusions;
- security conditions;
- claims and incident-notification clauses;
- the schedule and endorsements;
- sub-limits, excesses and waiting periods;
- territorial and jurisdiction provisions.
Record any explanation supplied by the broker or insurer in writing. The policy itself remains the principal contract.