What does cyber insurance cover?
Two distinct halves. First-party coverage pays your own incident costs: forensics, breach notification, credit monitoring, data restoration, lost income, extortion payments. Third-party coverage defends you when customers sue or regulators act after a breach. The details that decide real payouts are sublimits, social-engineering carve-outs, and whether your application answers — especially about MFA — were accurate.
There is no standard cyber policy — the NAIC notes these policies are highly customized per buyer, which means “what does cyber insurance cover” is really two questions: what the market’s insuring agreements generally offer, and which of them, at what sublimits, your specific policy actually grants. The first half is below; the second half is a schedule-reading exercise this page arms you for.
First-party vs third-party: the structure of every cyber policy
| First-party (your losses) | Third-party (claims against you) | |
|---|---|---|
| Incident response | Forensics, breach counsel, crisis management | — |
| People affected | Notification and credit monitoring for exposed individuals | Lawsuits by customers or partners over the breach |
| Your data and systems | Data restoration and repair costs | — |
| Your revenue | Cyber business interruption — income lost while systems are down | — |
| Extortion | Ransomware response and, where covered, ransom reimbursement | — |
| Regulators | — | Defense of regulatory proceedings; fines and penalties where law permits insuring them |
| Payment cards | — | PCI-related assessments, where granted |
The categories track what the NAIC lists as the losses cyberattacks actually cause — business interruption, data repair, credit monitoring, litigation — split by who bears them first. Whether you need the coverage at all is the prior question; note also that mistakes in technology services you sell belong to tech E&O, a sibling line contracts often demand alongside cyber.
Where full limits quietly shrink
The headline limit is not what most insureds can actually spend. Three places to look:
- Sublimits and coinsurance. Extortion/ransomware coverage frequently carries its own sublimit below the policy limit, sometimes with a coinsurance share you retain. As attacks climbed, insurers cut back — the GAO documented carriers reducing coverage limits for higher-risk sectors like healthcare and education. Read the schedule line by line, not the declarations page total.
- Social engineering and funds-transfer fraud. The most common small-business cyber loss — a spoofed email that walks a wire out the door — is routinely a separate insuring agreement with a much lower sublimit, or lives in a crime policy instead. Buyers assume base cyber covers it; the schedule decides.
- Waiting periods on cyber business interruption. Like property BI, cyber income coverage starts after a waiting period measured in hours; short outages may never clear it.
Ransomware in practice
A ransomware event pulls on multiple insuring agreements at once — extortion, forensics, restoration, and business interruption — which is why claims run large: Aon puts the average global ransomware claim at $713,200 in 2025, up from $374,400 in 2024. Match that number against your extortion sublimit, not your headline limit, and confirm who the approved incident-response and ransom-negotiation vendors are before you need them; using off-panel vendors can complicate an already high-stakes claim.
The application is part of the policy
The sharpest coverage risk in cyber isn’t an exclusion — it’s your own application. In Travelers v. International Control Services (C.D. Ill. 2022), the insured attested to using multifactor authentication, suffered a ransomware attack, and the investigation found MFA protected only its firewall — not its servers or other assets. Travelers sued to rescind, and judgment was entered rescinding the policy: rescission means the policy is treated as never having existed, for the ransomware claim and everything else.
Treat every security attestation — MFA, backups, EDR — as warranty-grade. Have the person who actually administers your systems answer those questions, and if a control lapses mid-term, tell your broker rather than hoping renewal arrives first.
What cyber insurance does not cover
- Bodily injury and property damage — those remain general liability’s domain, even when a system failure causes them.
- Professional mistakes in your product or services — that’s tech E&O, not cyber.
- Fines that can’t legally be insured — insurability of regulatory penalties varies by jurisdiction; policies pay them only “where insurable by law.”
- Losses flowing from controls you attested to but didn’t maintain — per the rescission risk above, this can void the entire policy rather than just one claim.
Questions people actually ask
Does cyber insurance cover ransomware? Generally yes — response costs, restoration, interruption, and often ransom reimbursement — but usually under an extortion sublimit and conditions. It’s the number to check hardest in any quote.
Does cyber insurance cover social engineering or wire fraud? Only if the policy includes that insuring agreement, and typically at a low sublimit. If wires and vendor payments run through your business, this line item matters more than the headline limit.
Does cyber insurance cover regulatory fines? Defense costs commonly; the fines themselves only where the jurisdiction permits insuring them — carriers hedge here because the law genuinely varies.
Does cyber insurance require MFA? Most carriers now condition coverage or pricing on it, and misstating it is worse than lacking it: inaccurate MFA answers have supported full policy rescission.
Sources are linked below. Policies differ materially by carrier — every claim-deciding detail above lives in the schedule of insuring agreements and sublimits, which is the part worth reading twice.
Ask us
Ask publicly The best questions become new pages here — sourced, anonymized, never with your email.
Ask privately Confidential — for a policy-specific read, answered by an editor, never published.
Sources
- NAIC — Cybersecurity (insurance topic) — Regulator association's catalog of cyberattack losses — business interruption, data repair, credit monitoring, litigation costs — and the note that cyber policies are highly customized
- Aon — Cyber and Tech E&O market report — Average global ransomware claim $713,200 in 2025, up from $374,400 in 2024
- Lockton — Travelers v. ICS underscores need to respond carefully to cyber insurance applications — The MFA rescission case: Travelers sued after a ransomware attack revealed ICS's MFA attestation was inaccurate; judgment rescinded the policy — it 'ceases to exist for all purposes'
- U.S. GAO — Cyber insurance: Insurers and policyholders face challenges in an evolving market (GAO-21-477) — Federal audit documenting insurers reducing coverage limits for higher-risk sectors as attacks increased