Back to Glossary

Entry · Insurance

Cyber And Privacy Insurance

Cyber and privacy insurance is a policy that helps a business pay for the costs of a data breach, cyber attack or privacy failure. It typically covers things such as investigation, notifying affected customers, legal fees, regulatory fines where insurable and lost income while systems are down.

It is designed for losses that standard property and liability policies often do not cover.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A conventional business policy was written for fires, floods and physical injury, and it often excludes or ignores digital losses. Cyber insurance fills that gap.

It splits into first-party cover (the costs your own business bears) and third-party cover (claims made against you by customers, partners or regulators). First-party cover usually pays for forensic investigators, data recovery, public relations support, customer notification and credit monitoring, and business interruption when systems are offline.

Some policies also cover cyber extortion, where criminals demand payment to release locked data. Third-party cover pays for legal defence and settlements when someone sues over exposed personal data.

Premiums depend on the industry, the amount and sensitivity of the data held, revenue, past incidents and the quality of security controls. Insurers often ask detailed questions about practices such as multi-factor authentication, backups, staff training and incident response plans, and weak answers can mean higher premiums, lower limits or a refusal to quote.

Every policy has a limit (the most the insurer will pay), a retention or deductible (the amount the business pays first) and exclusions. Common exclusions include losses from known weaknesses left unfixed, certain acts of war, and improvements to systems after an incident.

Reading the wording on sub-limits matters, because the headline limit may be much lower for specific items such as ransom payments or regulatory fines. The nuance is that insurance transfers some financial risk but does not remove the cause.

Insurers expect controls to be in place, claims can be contested, and the reputational damage that follows a breach is difficult to insure fully. The sensible approach is to treat cover as the last line of defence behind good security.

In practice

Real-world examples.

1

Example

An online clothing retailer is hit by ransomware that locks its order system for four days. Its policy pays forensic costs and the lost gross profit for the period after a waiting period of 12 hours. The finance team provides sales records to support the claim.

2

Example

A medical practice loses a laptop holding unencrypted patient records. The policy covers the legal advice, the cost of notifying patients and a year of credit monitoring. Because the practice had not used disk encryption as declared on the application, the insurer reviews whether a reduction applies.

3

Example

An accounting firm is tricked by a fake email into paying a client's funds to a fraudulent account. The firm finds that its cyber policy covers social engineering only up to a $100,000 sub-limit, well below the amount lost. It negotiates a higher sub-limit at renewal.

Formula

Calculation

Insurer payment = the lower of (loss - retention) and the policy limit; business bears the remainder Suppose a company suffers a breach with total costs of $900,000, has a retention of $50,000 and a policy limit of $500,000. Loss after retention = 900,000 - 50,000 = $850,000. The insurer pays the lower of $850,000 and $500,000, which is $500,000. The business bears 900,000 - 500,000 = $400,000, made up of the $50,000 retention and $350,000 above the limit.

Case study

Seen in the real world.

Tidewell Logistics is an illustrative, fictional freight company with 300 staff. A phishing email gave an attacker access to its booking system, and for six days drivers could not receive job details.

The company's cyber policy had a $2,000,000 limit, a $75,000 retention and a business interruption waiting period of 24 hours. The insurer appointed an incident response firm within hours, which contained the attack and began restoring systems from backups.

Total costs reached $640,000, of which the insurer paid $565,000 after the retention. In the illustrative aftermath, the finance director added multi-factor authentication across the company and used the improved controls to negotiate a lower premium at the next renewal.

Watch out

Common mistakes.

  • Assuming a standard business or liability policy already covers cyber losses, when many exclude electronic data and system failures.
  • Buying a policy on the headline limit without checking sub-limits for ransom, social engineering and regulatory fines.
  • Answering the application questions optimistically, which can give the insurer grounds to dispute a claim later.

Questions

People also ask.

Does cyber insurance pay the ransom?

Some policies cover extortion payments and negotiation costs, but cover varies, legal restrictions can apply and the insurer usually has to be involved before any payment.

Do small businesses need cyber insurance?

Any business that holds customer data, takes payments online or depends on its systems is exposed, and smaller firms often have fewer resources to recover without cover.

How does a business interruption waiting period work?

It is a set number of hours or days after an outage begins before the policy starts covering lost income, so the first part of the downtime is borne by the business.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.