Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Tech News
Tech News

Cyber insurance explained: what policies cover, what they demand, and what they exclude

Cyber insurance transfers some breach costs — but insurers increasingly require MFA, backups, and patching as a condition of coverage, and exclusions for war, prior acts, and unpatched systems are where claims die.

Asha Venkataswamy, · March 27, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Insurance broker reviewing a cyber policy with a small business owner

Cyber insurance covers the financial fallout of security incidents — breach response, legal costs, customer notification, extortion payments, and business interruption — with premiums and terms increasingly tied to the controls an organization can prove. The market has hardened into a simple bargain over the past several years: demonstrate multi-factor authentication, offline backups, and prompt patching, or pay substantially more for substantially less. It is a financial product, not a security program — the policy funds recovery from an incident the controls failed to prevent, and insurers are explicit that they no longer intend to fund incidents the customer declined to prevent.

KAJ News publishes information, not insurance or legal advice; policy terms vary widely and require a licensed broker.

What do first-party and third-party mean here?

Policies split into two halves. First-party coverage pays your own costs: forensics and incident response, data restoration, notification and credit monitoring for affected customers, extortion negotiation and ransom payment where lawful, public relations, and lost income during downtime. Third-party coverage pays when others sue you or regulators investigate: legal defense, settlements, and regulatory fines where insurable by law. Package policies blend both; standalone cyber policies offer far broader terms than the cyber rider bolted onto a general liability policy, which is where small businesses most often discover the gap too late.

What do insurers require before writing coverage?

The application is now effectively a security audit on a form. Standard questions as of the mid-2020s market: MFA on email, remote access, and privileged accounts; offline or immutable backups with a tested restore; endpoint detection or managed detection on servers and workstations; patching cadence for internet-facing systems, with KEV-catalog items on a deadline; a named incident response plan, often with a panel of pre-approved vendors you must use to preserve coverage; and, increasingly, expectations around privileged access management and email filtering. Answering inaccurately is not a victimless shorthand — misrepresentation on applications has become a leading reason insurers deny claims, and carriers routinely verify controls during claims investigations after an incident.

What do policies exclude?

Where claims actually fail:

How much does it cost?

Small businesses commonly see premiums from roughly $1,000 to several thousand dollars annually for seven-figure coverage limits, with pricing driven by revenue, data sensitivity, industry, and the controls checklist; technology and healthcare firms pay more, and rates have swung with the loss cycle since 2020. Retentions — the cyber version of a deductible — have risen sharply, so a small incident may fall entirely inside the deductible. The honest framing: the same controls that qualify you for affordable coverage are the controls that reduce your odds of needing it, which is why brokers and security professionals converge on the same advice — buy the policy after the controls, not instead of them.

What should a small business actually do?

  1. Do the controls first: MFA everywhere, tested offline backups, current patching, endpoint protection, an email filter. This is the application checklist and the incident-prevention checklist simultaneously.
  2. Write the one-page incident plan naming who decides, which panel firms to call, and how the insurer is notified — and put the insurer's claims number in it.
  3. Use a broker who places cyber policies routinely; the exclusions differ enough between carriers that a generalist agent can unknowingly buy a policy full of gaps.
  4. Read the war, ransom, and panel-vendor clauses before signing, not during the incident.

Is cyber insurance worth it for individuals?

Generally not as a standalone product. Personal exposure is mostly covered or absorbed elsewhere — fraud reimbursement through banks and card networks, identity-theft benefits already bundled into many homeowners policies and credit cards, and statutory protections on consumer accounts. The individual's better investment remains the boring list: unique passwords, MFA, credit freezes, and fast breach response. Cyber insurance answers an organizational question — can this balance sheet survive an incident — and for individuals the answer is usually yes without a policy.

Frequently Asked Questions

What does cyber insurance typically cover?
First-party costs of an incident — forensics, notification, credit monitoring, extortion, downtime — plus third-party costs when customers or regulators pursue you. Standalone policies cover far more than cyber riders attached to general liability policies.
Why do insurers require MFA and backups?
Loss data showed most claims involved basic control failures. Insurers now price and condition coverage on multi-factor authentication, tested offline backups, and patching — and claims have been denied where applications overstated the controls in place.
Does cyber insurance pay ransoms?
Many policies cover extortion payments where lawful, but typically require using the insurer's approved response vendors and negotiators. Paying independently, or paying where sanctions are implicated, can void the claim — and regulators discourage payment.
Do individuals need cyber insurance?
Rarely. Consumer fraud protections, card-network reimbursement, and identity-theft benefits already bundled into homeowners policies and credit products cover most personal exposure. Controls and credit freezes beat a policy for individuals.