What does a Cyber Insurance Policy Cover? (2024)

What are the five main areas covered under cyber liability?

Not all cyber liability insurance policies are created equal, and cyber insurance coverage can vary between carriers and policies. To adequately protect your organization against digital risks, look for coverage that will make your organization whole if you experience one of the most common cyber events.

Funds transfer fraud coverage can replace or clawback fundsOne of the easier ways to monetize cyber crime is through funds transfer fraud (FTF), which threat actors often perpetuate through social engineering techniques like phishing or business email compromise (BEC). Once criminals have access to your business mailbox, they can manipulate your contacts and modify payment instructions, sometimes without even triggering any security alerts. Funds transfer fraud coverage should cover incidents where a cyber criminal misdirects funds. Coalition's claims team will work with law enforcement and the appropriate financial institutions to attempt to retrieve the funds.

Restoration and remediation of Digital Assets against Cyber Extortion and Ransomware attacksIt has become clear that all organizations are vulnerable to this persistent digital risk of ransomware attacks, and organization size is not a predictor of risk. Paying such an exorbitant $1.8M ransom may prove untenable for many businesses. Cyber extortion coverage can cover the costs of the ransom itself, but policyholders should evaluate the hidden costs of remediating these attacks. In addition to covering the ransom fees, cyber insurance can also cover digital asset restoration to restore critical business data that may have been encrypted, damaged, or deleted during the ransom attack.

If employee or customer information was exposed as a result of the attack additional coverages may apply to the legal and reporting fees that result.

Emerging digital mitigated by Service Fraud and Computer Replacement coverageTwo emerging digital risks include service fraud (cryptojacking) and bricking can be devastating for businesses not covered by a general cyber policy. Cryptojacking occurs when a cyber criminal steals an organization's computing resources to mine cryptocurrency for their benefit. A Service Fraud endorsem*nt covers the direct financial losses a business faces when charged for fraudulent use of cloud-and internet-based services, including Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Network as a Service (NaaS), IP Telephony and more. If devices on your network have seemingly suffered no physical damage, but malware has rendered them unusable, you've been a victim of bricking. There is no way to restore a bricked computer. Computer Replacement coverage will replace all impacted devices.

Network & Info Security Liability & Regulatory Defense & Penalties coverage to mitigate digital vendor riskToday, businesses commonly rely on vendors to store sensitive customer and employee data in the cloud. In many cases, they also rely on these vendors to conduct critical functions, including processing the company's accounts receivable or other essential IT-related activities. Should one of these cloud vendors experience a cyber incident, it can be costly to all businesses that rely upon the vendor's platform. Specifically, companies could be exposed to privacy claims, regulatory fines, and other business interruption costs, including lost income and extra expenses to get their operation back up and running. Even if your third-party vendor has cyber insurance, your contract with them may limit their liability to you. With Network and Information Security Liability (NISL) and Regulatory Defense and Penalties coverage, businesses can transfer your third-party liability risk, mitigating their responsibility in the event of a claim related to one of their vendors. Additionally, cyber insurance policies with Business Interruption and Extra Expense coverage address first-party losses from reliance on cloud vendors.

Bodily Injury and Property coverage help when digital risks become physicalAs digital infrastructure becomes more advanced and integrated into your business operations, the boundary between cyber and physical security has become increasingly blurred. For example, a cyberattack on a medical organization's network could impact the health and safety of patients undergoing treatment by disrupting the connected medical devices. Likewise, a manufacturing company's operations could be shut down entirely if connected machinery is attacked and cannot be accessed, such as in a ransomware attack, or destroyed with malicious commands sent to the machinery, causing it to perform unwanted actions. Unfortunately, general liability (GL) policies typically do not cover physical or non-physical risks resulting from a cyber incident. However, suppose your cyber insurance coverage includes Bodily Injury and Property and Pollution coverage (first and third-party). In that case, your organization can remain protected from digital risks that translate to physical impacts.

What does a Cyber Insurance Policy Cover? (2024)

FAQs

What does a Cyber Insurance Policy Cover? ›

Cyber liability insurance not only covers the cost of recovering from a data breach, but also provides assistance with the lawsuits that often result. Your legal expenses could include attorney's fees, court-ordered judgments, and settlements.

What do cyber insurance policies cover? ›

A cyber insurance policy helps an organization pay for any financial losses they may incur in the event of a cyberattack or data breach. It also helps them cover any costs related to the remediation process, such as paying for the investigation, crisis communication, legal services, and refunds to customers.

What does cyber crime coverage cover? ›

This coverage protects companies for liability to others and reimburses companies for expenses related to a data breach, which could include legal counsel and defense, a digital forensics team, notification costs, crisis communications and setting up a call center and credit monitoring for those affected by the data ...

What isn t covered by cyber insurance? ›

Potential future lost profits

But they won't cover profits lost after an incident as a direct or indirect result. Devaluation of affected data, a company's diminished market share, profits lost due to reputation damage—most policies exclude such potential losses.

Does cyber insurance cover data breaches? ›

Cyber coverage offers protection from threats posed by cyberattacks and data breaches — including losses to a company's finances, reputation and operational capabilities.

What does a cyber security policy cover? ›

A cybersecurity policy sets the standards of behavior for activities such as the encryption of email attachments and restrictions on the use of social media. Cybersecurity policies are important because cyberattacks and data breaches are potentially costly.

Does cyber insurance cover regulatory fines? ›

Cyber Liability insurance would pay for the defense costs, fines and penalties incurred in an FTC investigation. Small Details like this, make a Big Difference. To learn more about this important coverage, contact your local Society Insurance agent.

What does third party cyber insurance cover? ›

Third-party cyber liability insurance provides liability protection for companies that fail to prevent a data breach or cyberattack at a client's business. This policy covers the legal costs of a cyber liability lawsuit, including any settlements or judgments.

Does cyber insurance cover ransom payments? ›

Cyber insurance is an effective way to reduce cyber risk, protecting against financial loss, business interruption and cyber extortion—with ransomware having the potential to cause all three. As such, a good cyber policy does cover ransomware.

Does cyber liability insurance cover website content? ›

Website Media Content

AmTrust's Cyber Liability policy also includes coverage for Website Media Content Liability.

What is excluded from cyber insurance? ›

Cyber insurance coverage exclusions in an insurance policy can include failure to maintain standards, payment card industry (PCI) fines and assessments, prior acts, acts of war, and more.

Which of the following is a cyber insurance policy least likely to cover? ›

Patent, software and copyright infringement – This is typically covered by intellectual property insurance forms, and not by a cyber policy.

Does cyber insurance cover human error? ›

Cybersecurity insurance policies typically exclude issues that were caused by human error or negligence or could have been prevented. Here are common exclusions: Poor security processes — attacks that occur due to ineffective security processes or poor configuration management.

What does cyber insurance cover? ›

Cyber insurance generally covers your business' liability for a data breach involving sensitive customer information, such as Social Security numbers, credit card numbers, account numbers, driver's license numbers and health records.

What does a cyber crime policy cover? ›

The unit investigates, and prosecutes technology-related crimes in California, including unauthorized intrusions, internet fraud, scams or confidence schemes committed by means of electronic media, money laundering via cryptocurrency or electronic transfer, organized retail crimes involving significant digital evidence ...

Which of the following is typically excluded from cyber insurance coverage? ›

Cyber insurance policies will replace losses in the digital sphere but will not usually cover damage to physical property or bodily injury (death, sickness, disease or physical injury) which results from a cyber incident, as these are often covered by other insurance policies such as property or liability insurance.

Which of the following is excluded in cyber insurance? ›

Fines, Penalties and Sanctions. Cyber insurance will not cover criminal, civil or regulatory fines, penalties or sanctions that your business is legally obliged to pay. Exclusions will vary between insurers so it is important to understand terms and conditions.

What is an example of a cyber insurance claim? ›

A breach of a firm's computer network leads to loss of sensitive customer information. Customers file suit against the firm for the failure to protect their private data. A firm's network security fails to prevent a self-propagating malware from being transmitted from their network to a third party.

What does commercial cyber insurance cover? ›

If your large business is the victim of a cyberattack, cyber liability insurance can help cover: Legal services to help you meet state and federal regulations. Notification expenses to alert affected customers that their personal information was compromised. Extortion paid to recover locked files in a ransomware attack.

References

Top Articles
Latest Posts
Article information

Author: Kimberely Baumbach CPA

Last Updated:

Views: 6478

Rating: 4 / 5 (41 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Kimberely Baumbach CPA

Birthday: 1996-01-14

Address: 8381 Boyce Course, Imeldachester, ND 74681

Phone: +3571286597580

Job: Product Banking Analyst

Hobby: Cosplaying, Inline skating, Amateur radio, Baton twirling, Mountaineering, Flying, Archery

Introduction: My name is Kimberely Baumbach CPA, I am a gorgeous, bright, charming, encouraging, zealous, lively, good person who loves writing and wants to share my knowledge and understanding with you.