How Does Cyber Insurance Work? | Travelers Insurance (2024)

By Travelers

4 minutes

Cyber Resources

How Does Cyber Insurance Work? | Travelers Insurance (1)

The cost of dealing with a data breach goes beyond repairing databases, strengthening security procedures or replacing lost laptops. Regulations requiring notifications to affected customers also drive up costs for companies when a data breach compromises personal or confidential data. Traditional business insurance may not be enough to protect companies from cyber crime. But just how does cyber insurance work?

Typically, there are a number of different coverages available. To have the coverage that is right for your company, you and your agent can work together to tailor the coverages based on the specific risks your business faces. Following are some explanations of typical elements of a Travelers cyber insurance policy.

Types of Coverage

What cyber insurance does: Companies have an obligation to keep their customers’ protected health information (PHI) and personally identifiable information (PII) confidential. They may face potential liability if the information is exposed in a data breach. This coverage protects companies for liability to others and reimburses companies for expenses related to a data breach, which could include legal counsel and defense, a digital forensics team, notification costs, crisis communications and setting up a call center and credit monitoring for those affected by the data breach.

Why cyber insurance is important: Many companies store their customers’ confidential information, PHI and PII, as well as confidential corporate information, either for themselves or for another company. For example, an employee benefits company may have personnel records for the employees of dozens of companies it serves, which can mean that a single breach presents the potential for a significant liability.

Third-Party (liability) and First-Party Coverage

What it does: Companies have an obligation to keep their customers’ protected health information (PHI) and personally identifiable information (PII) confidential. They may face potential liability if the information is exposed in a data breach. This coverage protects companies for liability to others and reimburses companies for expenses related to a data breach, which could include legal counsel and defense, a digital forensics team, notification costs, crisis communications and setting up a call center and credit monitoring for those affected by the data breach.

Why it’s important: Many companies store their customers’ confidential information, PHI and PII, as well as confidential corporate information, either for themselves or for another company. For example, an employee benefits company may have personnel records for the employees of dozens of companies it serves, which can mean that a single breach presents the potential for a significant liability.

Worldwide Coverage

What worldwide coverage does: Claims and events can occur anywhere in the world, and notification requirements differ by location. To help fulfill these requirements, policyholders can access Travelers’ network of forensics, crisis communications and legal experts to address claims made or events occurring anywhere in the world.

Why world-wide coverage is important: If a company has a data breach, it must follow the privacy laws that govern where its customers live, not just where it is headquartered. This can be costly, confusing and time-consuming for a company without specialized resources.

Other Coverages

Travelers CyberRisk insurance against cyberattacks also includes betterment coverage. This provides for costs to improve a computer system after a security breach, when improvements are recommended to eliminate vulnerabilities that could lead to further breaches.

Distinct Insuring Agreements (with the ability to set limits and retentions for each insuring agreement)

What it does: Having separate insuring agreements allows companies to be covered for different risks, at different levels. This gives companies more protection as companies can choose to set a higher limit for a specific risk, based on their business’ unique needs.

Why it’s important: There are a number of different ways that cyber crime can affect a company, from e-commerce extortion to funds transfer fraud. Having distinct insuring agreements helps protect against a diverse set of risks.

Extended Reporting Period

What it does: This gives companies more time to detect and report a data breach. It extends the reporting period, typically 90 days, and includes crisis management and security breach expense coverage.

Why it’s important: Given the nature of data breaches, a company might not realize that it suffered a breach until after the end of the cyber policy.

First-Party Coverage for Computer Program and Electronic Data Restoration Expenses

What it does: This coverage reimburses companies for expenses related to recovering from damages to computer programs and electronic data.

Why it’s important: Not all cyber claims are related to an actual data breach. For example, malware downloaded from an email could lead to lost, encrypted or otherwise damaged files, requiring expenses to repair and restore.

Business Interruption Coverage

What it does: This coverage applies to expenses and lost revenue due to a computer virus or denial-of-service attack that impairs a computer system.

Why it’s important: While many companies may have business interruption coverage as part of their property coverage, cyber crimes may not be covered.

Your coverage for security breach remediation and notification expenses would include purchasing an identity fraud insurance policy, credit monitoring services, computer forensics and access to a Breach Coach for advice regarding initial breach response.

Cyber insurance also can help protect you before a breach. Travelers customers have access to risk management services, cyber security experts and other resources to help prevent a data breach. Perhaps just as importantly, having cyber insurance can help prepare your company to respond effectively in the critical hours and days following a data breach.

How Does Cyber Insurance Work? | Travelers Insurance (2024)

FAQs

How does a cyber insurance work? ›

A cyber insurance policy protects organizations from the cost of internet-based threats affecting IT infrastructure, information governance, and information policy, which often are not covered by commercial liability policies and traditional insurance products.

What isn t covered by cyber insurance? ›

Potential future lost profits

But they won't cover profits lost after an incident as a direct or indirect result. Devaluation of affected data, a company's diminished market share, profits lost due to reputation damage—most policies exclude such potential losses.

Does cyber insurance pay out? ›

Cyber insurance covers the liability actions that might be brought against you, arising out of a cyber event (third party loss), such as investigation and defence costs, civil damages, compensation payments to affected parties.

What does cyber crime insurance cover? ›

Your coverage for security breach remediation and notification expenses would include purchasing an identity fraud insurance policy, credit monitoring services, computer forensics and access to a Breach Coach for advice regarding initial breach response. Cyber insurance also can help protect you before a breach.

Is cyber insurance worth the cost? ›

Today, the average cost of cyber claims is substantial, far exceeding the average cost of cyber premiums. And considering the proactive and reactive services on offer, it's clear that cyber insurance is more than worth the money.

What is the average payout for cyber insurance? ›

The average settled cyber claim (where any type of cost has been incurred, excluding zero value losses) is $4.88m. From this we have seen that: Data breaches are the most frequently reported losses and have the largest total amount of costs associated with them.

What is excluded from cyber insurance? ›

Cyber insurance coverage exclusions in an insurance policy can include failure to maintain standards, payment card industry (PCI) fines and assessments, prior acts, acts of war, and more.

How do you qualify for cyber insurance? ›

Strong security controls

That includes protection from internal threats, like careless, malicious or compromised insiders. If you have a remote or hybrid workforce, you may also need to demonstrate that you have people-centric security controls as well as granular policy controls based on risk, context and user role.

What are the problems with cyber security insurance? ›

However, the cyber insurance industry faces significant challenges, including a lack of historical data, a lack of ability to predict the future of cyber risk, the possibility of large cascading loss events, uncertainties among market participants about what is specifically covered under such policies, and legal ...

What is the most common cyber insurance claim? ›

As of late, the most common cyber attacks leading to insurance claims include ransomware, business email compromise, and funds transfer fraud.

Why do cyber insurance claims get rejected? ›

Failure to Document Preventative Measures

Your insurer will want to see tangible evidence, in the form of documentation, regarding the preventative measures you have under way to ward off cyberthreats. To avoid any hassles, you need to have thorough, accurate and updated documentation at all times.

How do I claim cyber insurance? ›

How to claim cyber insurance
  1. Identify the security breach. This is the most important step toward claiming cyber insurance. ...
  2. File a first information report (FIR) ...
  3. Intimate your insurer. ...
  4. Submit requested documentation. ...
  5. Forensic analysis. ...
  6. Settlement.
Nov 8, 2023

What cyber insurance doesn t cover? ›

Also, most cyber liability insurance policies don't cover your business for a decrease in company value. For example, your intellectual information could be stolen through digital crime. Without that information, your company becomes less valuable overall, but insurance providers will not cover that loss of value.

Are cyber insurance claims made? ›

However, many other types of business insurance policies are usually claims-made. For instance, errors and omissions, professional liability, directors and officers liability, employment practices liability and cyber coverage are typically claims-made policies.

Does cyber insurance cover data loss? ›

Cyber coverage offers protection from threats posed by cyberattacks and data breaches — including losses to a company's finances, reputation and operational capabilities.

Why is it difficult to get cyber insurance? ›

Demand, losses, and premiums are all on the rise

The demand for cyber insurance coverage is skyrocketing. At the same time, insurance providers' losses are growing. High demand in combination with high payouts lead to increased premiums. Businesses report premium hikes of 50% and even 100% year over year.

Does cyber insurance make sense? ›

While cyber liability insurance can provide some financial protection in the event of a cyber attack or data breach, it is still not a complete substitute for implementing adequate cybersecurity measures.

References

Top Articles
Latest Posts
Article information

Author: Arielle Torp

Last Updated:

Views: 5532

Rating: 4 / 5 (41 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Arielle Torp

Birthday: 1997-09-20

Address: 87313 Erdman Vista, North Dustinborough, WA 37563

Phone: +97216742823598

Job: Central Technology Officer

Hobby: Taekwondo, Macrame, Foreign language learning, Kite flying, Cooking, Skiing, Computer programming

Introduction: My name is Arielle Torp, I am a comfortable, kind, zealous, lovely, jolly, colorful, adventurous person who loves writing and wants to share my knowledge and understanding with you.