Cyber liability insurance covers the costs a business faces after a data breach, ransomware attack, or other cyber incident — costs that general liability policies typically exclude entirely. For a small business, a single incident (breach notification, forensic investigation, legal fees, and potential fines) can easily exceed what many companies keep in reserve, which is why this has become one of the fastest-growing categories of business insurance.
What a policy actually covers
- First-party costs: breach notification to affected customers, credit monitoring, forensic investigation, and business interruption from downtime.
- Third-party liability: legal defense and settlements if customers or partners sue over a breach involving their data.
- Ransomware response: negotiation support and, depending on the policy, the ransom payment itself — though coverage here varies significantly between insurers.
- Regulatory fines: coverage for fines under data protection law, where insurable by law in your jurisdiction.
Insurers price these policies mainly on the volume and sensitivity of data you handle, your existing security controls, and your industry. A business storing payment card data or health records pays significantly more than one storing only basic contact details. Insurers increasingly require specific controls — multi-factor authentication, encrypted backups, an incident response plan — before offering coverage at all, not just as a discount.
Common gaps that catch businesses out
- Social engineering exclusions: many policies exclude losses from staff being tricked into wiring money, which is treated as a separate "crime" coverage add-on.
- War exclusions: some insurers have added broad exclusions for state-sponsored attacks following high-profile disputes over major incidents, which can leave a gap for certain ransomware groups.
- Prior-knowledge exclusions: a vulnerability you knew about and didn't patch before the policy started is typically not covered.
A practical approach to buying
- Get quotes from at least two brokers who specialize in cyber, not a generalist — pricing and coverage details vary widely between specialist and general insurers.
- Ask specifically what triggers a claim denial, not just what's covered — the exclusions matter more than the headline coverage limit.
- Implement the security baseline insurers expect (MFA, backups, an incident response plan) before shopping, since it materially affects both eligibility and price.
- Review the policy annually — this market changes quickly, and last year's terms are not a reliable guide to this year's.