Knowledge Centre

Practical answers to common cyber insurance questions.

Use the category tabs or search across all categories. The answers are general guidance and do not confirm whether a particular incident, system or platform is covered.

Return to the Cyber Advisory Guide

Find an answer

Search the Knowledge Centre

Search by question, business concept, platform, common term or approved misspelling.

Browse by category

Knowledge Centre categories

Category 01

Cyber Insurance Basics and Other Cover

Orientation, suitability and how cyber protection may interact with the wider insurance programme.

Cyber insurance is a form of business insurance intended to support selected financial, operational and liability consequences of cyber incidents. Depending on the policy purchased, it may include incident response, data and system recovery, business interruption, cyber extortion and certain claims involving privacy or network security. It does not replace cybersecurity, business continuity planning or good governance.

A business should consider its dependence on technology, information and external digital services rather than its size or industry label. Relevant indicators include reliance on email, cloud applications, payment platforms, customer or employee information, online services, outsourced IT and systems that are important to revenue or operations.

No. A small retailer, professional firm, distributor, manufacturer or service business can have meaningful cyber exposure even without owning servers or employing an internal IT team. The more useful question is what could stop the business, expose information, create a liability or require specialist response.

Yes. Outsourcing technology does not automatically transfer the financial consequences of an incident. The vendor may have contractual obligations or its own insurance, but your organisation may still face lost income, customer communication, legal duties, recovery costs or claims. The vendor contract and the proposed cyber policy should be reviewed together.

No. Cybersecurity aims to reduce the likelihood and impact of incidents. Cyber insurance is a risk-transfer and response tool for events that fall within the policy. A resilient programme normally combines controls, staff awareness, recovery planning, contractual management and suitable insurance.

They may cover selected consequences, but usually not the entire incident. Property, crime, professional indemnity, directors and officers, public liability and other policies have different triggers and exclusions. A coordinated review is needed rather than assuming either full overlap or no overlap.

Cyber and crime or fidelity insurance can overlap, but the triggers are not the same. Under the two reviewed cyber wordings, a cyber crime extension is limited to direct financial loss from theft of the insured organisation’s money or securities by a third party through malicious use or access of a covered or shared computer system. Employee or contractor theft, fraudulent instructions and social engineering may instead require crime or fidelity protection. Compare both policies, including exclusions, excesses, other-insurance provisions and the sequence in which each policy may respond.

Possibly. For a traditional business, professional indemnity insurance may respond where the allegation arises from professional advice or services. For a technology business, software provider or SaaS company, technology professional liability may be more relevant because it can address claims arising from defects, failures or errors in technology products or services. Privacy and network security allegations may sit under the cyber section. The correct response depends on the business model, allegation and sections purchased.

Common review areas include outsourced systems, payment fraud, business interruption waiting periods, sub-limits, ransomware mechanics, contractual liability, infrastructure outages, regulatory matters, known circumstances, retroactive dates and the cost of using specialists. For technology providers, the review should also confirm whether technology professional liability is purchased alongside cyber protection. The relevant gaps depend on the business model and current insurance programme.

Category 02

Business Interruption and Financial Terms

Practical questions that build on the policy mechanics already introduced in the guide.

Business interruption generally means defined financial loss arising when a qualifying incident disrupts a covered or shared computer system. Under the reviewed cyber-focused wording, the definition centres on lost net profit. The combined technology and cyber wording also includes continuing normal operating and payroll expenses to the extent they are disrupted. Recovery or extra operating costs may instead fall under data and system recovery or another purchased section. It is not the same as every inconvenience, slowdown or outage.

No. The outage usually needs to arise from an event and system that fit the policy wording, continue beyond any waiting period and result in loss that can be supported. An outage caused by electricity, telecommunications, general internet infrastructure or a platform outside the policy definition may be treated differently.

A waiting period is a time threshold that must be exceeded before defined business interruption loss begins to count. It is not a dollar excess. A business that recovers quickly may still incur costs even though the interruption does not pass the policy’s time threshold.

They can. The waiting period addresses time before business interruption loss is recognised. An excess is the amount the business bears for a covered loss. The schedule may apply different mechanics to different insuring agreements or event types.

The calculation follows the policy definition, not simply the fall in sales. It normally compares the financial position the business would have achieved without the incident against the actual result, allowing for supported assumptions and cost savings. Depending on the wording, eligible loss may be limited to net profit or may also include continuing normal operating and payroll expenses. Separate recovery costs should not be combined with business interruption unless the wording allows it. A detailed computation and supporting financial records are required.

Category 03

Data, Privacy and Liability

Questions about information, legal exposure and contractual obligations arising from cyber incidents.

Relevant information can include names, identity details, contact information, payment-related data, account credentials, transaction records and other information that identifies or relates to an individual. The sensitivity, volume, legal obligations and consequences of misuse all matter.

No. Cyber exposure can also involve confidential third-party corporate information, contracts, source code, designs, pricing, credentials and operational data. Passwords or written login credentials can create exposure even when no personal data is involved. Insurance treatment differs: data and system recovery may address restoration of electronic data, privacy liability usually focuses on defined privacy or network security obligations, and technology businesses may need technology professional liability for responsibility connected with their products, services or client information.

Privacy liability generally concerns claims or regulatory proceedings arising from an alleged failure to protect personal information, maintain network security or comply with privacy obligations. Incident-response cover may separately address certain notification, legal and regulatory advisory costs. It is a third-party exposure because a customer, employee, other affected person or regulator may allege that the business caused harm or breached a duty.

Yes. Payroll, identity, medical, banking, performance and contact information may create privacy and operational obligations. A cyber review should include employee information as well as customer information, but the policy treatment depends on the wording and applicable law.

Yes. Service levels, warranties, liquidated damages, refund promises, broad indemnities and other contractual standards can exceed the protection provided by a cyber policy. The reviewed cyber-focused wording contains contractual liability restrictions with limited exceptions. A technology professional liability section may provide selected protection for technology products, services or specified contractual exposures, but only where that section or extension is purchased. Important customer and vendor contracts should be reviewed against the issued schedule and wording.

Category 04

Technology, Payment Platforms and Vendors

Application questions for businesses that depend on cloud services, payments and outsourced technology.

It may. Both reviewed wordings distinguish between systems owned or operated by the business, systems operated solely for its benefit and shared outsourced systems under a written agreement, including cloud hosting, data storage and software-as-a-service. A service should not be assumed to fall within the policy merely because the business uses it. Payment process platforms and wider infrastructure may be classified differently.

It generally means an outsourced computing service operated by a third party for the business under a written contract, such as data hosting, cloud storage, software-as-a-service, platform services, backup or data processing. The term usually excludes wider infrastructure such as general internet, utility or telecommunications networks.

Not automatically. In both reviewed wordings, a financial transaction or payment process platform is defined as Infrastructure, and loss arising from a failure or outage of Infrastructure is excluded. A loss caused solely by PayPal or another payment platform being unavailable would therefore generally not qualify as an outage of a Shared Computer System under these wordings. Separate consequences still require individual review, such as an incident affecting your own covered system, a privacy or network security claim for which your business is legally responsible, or theft under separately purchased crime protection.

The business may still face interruption, recovery costs, customer obligations or claims even when the technical cause sits with a vendor. A vendor-related event may fall within the cyber wording where the service qualifies as a covered computer system operated solely for the business or as a shared computer system under a written agreement. Wider infrastructure is treated differently. Liability involving information handled by a vendor may also depend on whether the business is legally responsible for that vendor. The vendor contract and insurance position should be reviewed with the policy.

A widespread event may be subject to special limits, coinsurance, endorsements or restrictions. The fact that the business itself was affected does not mean the claim will be calculated in the same way as a single-business incident.

Map email, identity access, accounting, payment, customer databases, cloud storage, websites, e-commerce, logistics, production systems, remote access, backup, telecommunications and important service providers. Record the owner, contract, recovery option, acceptable downtime and business consequence for each dependency.

Category 05

Ransomware, Incident Response and Claims

Calm response guidance without turning the FAQ into an insurer-specific claims manual.

Some cyber policies include protection for defined cyber extortion events, incident response, data and system recovery and business interruption. Ransomware-specific sub-limits, coinsurance and excesses may apply. Any extortion payment must be legally allowed and insurable, and it should not be assumed that every ransomware event or payment is covered. The two reviewed wordings also require ransomware to be reported to the appropriate law-enforcement agencies as soon as reasonably practicable.

This is not an insurance-only decision. It involves legal, sanctions, operational, ethical and practical considerations, and payment does not guarantee recovery. The reviewed wordings contemplate payment only where it is legally allowed and insurable, contain trade and economic sanctions restrictions and require ransomware to be reported to the appropriate law-enforcement agencies as soon as reasonably practicable. Obtain specialist legal, forensic and incident-response advice and involve the insurer before making any commitment.

Costs may include forensic investigation, incident coordination, legal and regulatory advice, data restoration, system recovery, business interruption analysis, customer notification, credit monitoring and public relations. These amounts may fall under different insuring agreements and should not be treated as one undifferentiated expense category. Which costs are insured depends on the sections purchased, exclusions, limits and policy conditions.

Preserve evidence, contain or isolate affected systems where appropriate, activate the incident-response plan, obtain specialist support and follow the policy’s formal notification route as soon as practicable. Inform NRM or the broker so the response can be coordinated, but ensure notice reaches the insurer in the required manner. The reviewed wordings also require ransomware to be reported to the appropriate law-enforcement agencies as soon as reasonably practicable. Do not negotiate, make payment, admit liability or commit significant costs before checking legal and policy requirements.

Activate the internal incident-response contacts and involve the appropriate IT or security specialists. Inform NRM or the broker promptly and follow the policy’s formal insurer-notification route as soon as practicable. Legal, privacy, communications and senior-management support may also be required depending on the event. The policy and incident-response plan should identify the current contact details and appointment process.

Give notice as soon as practicable once a claim, act, occurrence, incident or circumstance is identified. Forward demands, notices and legal process promptly. Claims-made sections may also contain an outer reporting deadline, particularly after expiry or non-renewal. Early notice allows specialist appointments, consent requirements, evidence preservation and loss documentation to be managed before the business commits major costs.

Sometimes, but prior consent, approved vendors or insurer coordination may be required. Emergency-response extensions can permit limited urgent services or retroactive consent in defined situations, but they do not create a general freedom to appoint any adviser and assume the cost is covered. Confirm the appointment process and panel arrangements before an incident where possible.

Keep a clear incident description, the parties involved, demands or regulatory documents, system logs, forensic reports, emails, notices, contracts, invoices, decisions, recovery actions and communications. Record the timeline, what was done and why. For business interruption, retain a detailed loss computation, the assumptions used and supporting accounting records such as reports, books of account, bills, ledgers, invoices and vouchers.

No. Notification preserves the opportunity for the insurer to review the event. Claim acceptance depends on the facts, the cover purchased, definitions, timing, conditions, exclusions, limits and supporting evidence. NRM can assist with coordination and communication, but the insurer determines the claim under the policy.

Category 06

Policy Conditions and the NRM Review

Questions that preserve policy uncertainty and move the reader towards a structured business discussion.

Cyber policies differ materially. The same business event can be treated differently depending on the affected system, cause, timing, business model, cover purchased, schedule, endorsements and exclusions. A reliable answer requires the actual policy and incident circumstances rather than a general Knowledge Centre answer.

A known circumstance or issue can include an incident, complaint, demand, investigation, error, outage, vulnerability, system problem or other fact known before placement or renewal that senior management or another person identified in the policy knew, or could reasonably foresee, might lead to a claim or loss. Both reviewed wordings contain duty-of-disclosure and prior-knowledge or prior-proceedings provisions. When uncertain, raise the matter during placement or renewal.

The review explores how the organisation operates, which systems, payment platforms and third-party providers are critical, what information creates the greatest impact, how controls and recovery plans work, which current policies may respond and where further review may be needed. It also identifies whether the organisation mainly uses technology or supplies technology products, software or SaaS services, so that a cyber-focused policy or a combined technology professional liability and cyber structure can be considered. It is a structured business discussion, not a coverage promise.

Prepare a simple list of critical systems and providers, the information held, key customer and vendor contracts, recent incidents or concerns, recovery arrangements and the current insurance schedules and wordings. Technology and SaaS businesses should also provide a short description of their products or services, how they are deployed, what client data they handle and any service levels, warranties or indemnities. Perfect documentation is not required. The objective is to build a practical picture of dependencies, responsibilities, consequences and decision priorities.

A structured business discussion

Start Your Business Cyber Risk Review

Explore how your operations, systems, providers, information and current insurance arrangements fit together before deciding what protection may be appropriate.