What it means
A conventional business policy was written for fires, floods and physical injury, and it often excludes or ignores digital losses. Cyber insurance fills that gap.
It splits into first-party cover (the costs your own business bears) and third-party cover (claims made against you by customers, partners or regulators). First-party cover usually pays for forensic investigators, data recovery, public relations support, customer notification and credit monitoring, and business interruption when systems are offline.
Some policies also cover cyber extortion, where criminals demand payment to release locked data. Third-party cover pays for legal defence and settlements when someone sues over exposed personal data.
Premiums depend on the industry, the amount and sensitivity of the data held, revenue, past incidents and the quality of security controls. Insurers often ask detailed questions about practices such as multi-factor authentication, backups, staff training and incident response plans, and weak answers can mean higher premiums, lower limits or a refusal to quote.
Every policy has a limit (the most the insurer will pay), a retention or deductible (the amount the business pays first) and exclusions. Common exclusions include losses from known weaknesses left unfixed, certain acts of war, and improvements to systems after an incident.
Reading the wording on sub-limits matters, because the headline limit may be much lower for specific items such as ransom payments or regulatory fines. The nuance is that insurance transfers some financial risk but does not remove the cause.
Insurers expect controls to be in place, claims can be contested, and the reputational damage that follows a breach is difficult to insure fully. The sensible approach is to treat cover as the last line of defence behind good security.
In practice
Real-world examples.
Example
An online clothing retailer is hit by ransomware that locks its order system for four days. Its policy pays forensic costs and the lost gross profit for the period after a waiting period of 12 hours. The finance team provides sales records to support the claim.
Example
A medical practice loses a laptop holding unencrypted patient records. The policy covers the legal advice, the cost of notifying patients and a year of credit monitoring. Because the practice had not used disk encryption as declared on the application, the insurer reviews whether a reduction applies.
Example
An accounting firm is tricked by a fake email into paying a client's funds to a fraudulent account. The firm finds that its cyber policy covers social engineering only up to a $100,000 sub-limit, well below the amount lost. It negotiates a higher sub-limit at renewal.
Formula
Calculation
Insurer payment = the lower of (loss - retention) and the policy limit; business bears the remainder
Suppose a company suffers a breach with total costs of $900,000, has a retention of $50,000 and a policy limit of $500,000. Loss after retention = 900,000 - 50,000 = $850,000. The insurer pays the lower of $850,000 and $500,000, which is $500,000. The business bears 900,000 - 500,000 = $400,000, made up of the $50,000 retention and $350,000 above the limit.Case study
Seen in the real world.
Tidewell Logistics is an illustrative, fictional freight company with 300 staff. A phishing email gave an attacker access to its booking system, and for six days drivers could not receive job details.
The company's cyber policy had a $2,000,000 limit, a $75,000 retention and a business interruption waiting period of 24 hours. The insurer appointed an incident response firm within hours, which contained the attack and began restoring systems from backups.
Total costs reached $640,000, of which the insurer paid $565,000 after the retention. In the illustrative aftermath, the finance director added multi-factor authentication across the company and used the improved controls to negotiate a lower premium at the next renewal.
Watch out
Common mistakes.
- Assuming a standard business or liability policy already covers cyber losses, when many exclude electronic data and system failures.
- Buying a policy on the headline limit without checking sub-limits for ransom, social engineering and regulatory fines.
- Answering the application questions optimistically, which can give the insurer grounds to dispute a claim later.
Questions
People also ask.
Does cyber insurance pay the ransom?
Some policies cover extortion payments and negotiation costs, but cover varies, legal restrictions can apply and the insurer usually has to be involved before any payment.
Do small businesses need cyber insurance?
Any business that holds customer data, takes payments online or depends on its systems is exposed, and smaller firms often have fewer resources to recover without cover.
How does a business interruption waiting period work?
It is a set number of hours or days after an outage begins before the policy starts covering lost income, so the first part of the downtime is borne by the business.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%