Cyber insurance covers the financial fallout of security incidents — breach response, legal costs, customer notification, extortion payments, and business interruption — with premiums and terms increasingly tied to the controls an organization can prove. The market has hardened into a simple bargain over the past several years: demonstrate multi-factor authentication, offline backups, and prompt patching, or pay substantially more for substantially less. It is a financial product, not a security program — the policy funds recovery from an incident the controls failed to prevent, and insurers are explicit that they no longer intend to fund incidents the customer declined to prevent.
KAJ News publishes information, not insurance or legal advice; policy terms vary widely and require a licensed broker.
What do first-party and third-party mean here?
Policies split into two halves. First-party coverage pays your own costs: forensics and incident response, data restoration, notification and credit monitoring for affected customers, extortion negotiation and ransom payment where lawful, public relations, and lost income during downtime. Third-party coverage pays when others sue you or regulators investigate: legal defense, settlements, and regulatory fines where insurable by law. Package policies blend both; standalone cyber policies offer far broader terms than the cyber rider bolted onto a general liability policy, which is where small businesses most often discover the gap too late.
What do insurers require before writing coverage?
The application is now effectively a security audit on a form. Standard questions as of the mid-2020s market: MFA on email, remote access, and privileged accounts; offline or immutable backups with a tested restore; endpoint detection or managed detection on servers and workstations; patching cadence for internet-facing systems, with KEV-catalog items on a deadline; a named incident response plan, often with a panel of pre-approved vendors you must use to preserve coverage; and, increasingly, expectations around privileged access management and email filtering. Answering inaccurately is not a victimless shorthand — misrepresentation on applications has become a leading reason insurers deny claims, and carriers routinely verify controls during claims investigations after an incident.
What do policies exclude?
Where claims actually fail:
- War and state-sponsored attacks. The war exclusion, sharpened after the 2017 NotPetya event, can void claims when damage is attributed to hostilities or state actors — a murky line in an era of criminal groups with state tolerance.
- Unmaintained systems. End-of-life software, ignored critical patches, and controls the application claimed but the incident reveals missing.
- Prior acts and known vulnerabilities disclosed or discovered before the policy period.
- Profit lost to reputation beyond defined business-interruption windows, and often crypto theft beyond sub-limits.
- Failure to follow the incident response plan — hiring your own forensic firm instead of the panel vendor, or paying a ransom without the insurer's involvement, can jeopardize the entire claim.
How much does it cost?
Small businesses commonly see premiums from roughly $1,000 to several thousand dollars annually for seven-figure coverage limits, with pricing driven by revenue, data sensitivity, industry, and the controls checklist; technology and healthcare firms pay more, and rates have swung with the loss cycle since 2020. Retentions — the cyber version of a deductible — have risen sharply, so a small incident may fall entirely inside the deductible. The honest framing: the same controls that qualify you for affordable coverage are the controls that reduce your odds of needing it, which is why brokers and security professionals converge on the same advice — buy the policy after the controls, not instead of them.
What should a small business actually do?
- Do the controls first: MFA everywhere, tested offline backups, current patching, endpoint protection, an email filter. This is the application checklist and the incident-prevention checklist simultaneously.
- Write the one-page incident plan naming who decides, which panel firms to call, and how the insurer is notified — and put the insurer's claims number in it.
- Use a broker who places cyber policies routinely; the exclusions differ enough between carriers that a generalist agent can unknowingly buy a policy full of gaps.
- Read the war, ransom, and panel-vendor clauses before signing, not during the incident.
Is cyber insurance worth it for individuals?
Generally not as a standalone product. Personal exposure is mostly covered or absorbed elsewhere — fraud reimbursement through banks and card networks, identity-theft benefits already bundled into many homeowners policies and credit cards, and statutory protections on consumer accounts. The individual's better investment remains the boring list: unique passwords, MFA, credit freezes, and fast breach response. Cyber insurance answers an organizational question — can this balance sheet survive an incident — and for individuals the answer is usually yes without a policy.
For more context, read Why schools are ransomware's favorite target.
For more context, read cybersecurity skills shortage.
For more context, read What NIS2 actually requires, in plain terms.

