Business Risk Advisory Guide

Preparing Your Business Before a Cyber Incident Happens

Technology has become an essential part of almost every business. As organisations become more connected, cyber incidents have the potential to disrupt operations, affect customers, interrupt revenue and create unexpected financial obligations. Understanding your cyber risk before an incident occurs helps you make better decisions, strengthen business resilience and evaluate whether cyber insurance forms an appropriate part of your overall risk management strategy.

Understand your exposure. Review your options. Make informed decisions.

Advisory Journey

Understand the risk before reviewing the cover

Follow the six sections to understand your exposure, how cyber insurance may respond, and the questions your business should consider next.

Section 01

Understanding Your Cyber Risk

Cyber exposure begins with understanding how the organisation uses technology and where disruption could affect operations, customers or financial performance.

Most organisations rely on technology to support their daily operations. Email, accounting systems, payment platforms, cloud storage, customer databases and communication tools have become part of everyday business. When these systems become unavailable or are compromised, the consequences often extend beyond the IT department. Operations may be interrupted, customers may be affected, contractual obligations may be delayed and unexpected costs may arise. As businesses continue to embrace digital technologies, cyber risk has become an operational risk that deserves the same level of attention as fire, theft or liability exposures.

  • Unauthorised access to business systems
  • Theft or exposure of confidential information
  • Malware or ransomware attacks
  • Email fraud and social engineering
  • System outages
  • Human error involving sensitive information

Every organisation uses technology in different ways. Understanding how your business depends on technology is an important first step in identifying where cyber disruptions could affect operations, customers or financial performance.

  • Processing customer information
  • Accepting electronic payments
  • Operating online platforms
  • Remote working
  • Cloud-based applications
  • Third-party service providers
  • Connected operational systems
  • Digital supply chains

Cyber incidents can arise from malicious attacks, accidental mistakes or weaknesses in technology and business processes.

  • Ransomware attacks
  • Business email compromise
  • Data breaches
  • Malware infections
  • Phishing attacks
  • Insider mistakes
  • Lost or stolen devices
  • Denial-of-service attacks
  • Unauthorised system access

Recovering from a cyber incident may involve investigation, system restoration, customer communication, legal or regulatory obligations and operational recovery.

  • Operational disruption
  • Loss of income
  • Data restoration
  • Incident investigation
  • Customer notification
  • Regulatory obligations
  • Legal expenses
  • Reputation management
  • Recovery and business continuity activities

Section 02

Understanding Cyber Insurance

This section explains how cyber insurance is structured from a business perspective. Material conditions, limitations and schedule-specific provisions are considered separately in the policy-response sections.

When a cyber incident occurs, business leaders may need to make operational, financial and legal decisions within a very short period. Cyber insurance is designed to form one component of an organisation's broader risk management and response strategy. It complements, but does not replace, cybersecurity controls, business continuity planning and governance.

  • Financial resilience
  • Operational resilience
  • Business continuity
  • Access to specialist support
  • Risk transfer as one element of risk management

Responding to a significant cyber incident often requires coordinated technical, legal, operational and communications support. Depending on the policy purchased and its terms, cyber insurance may assist with activities associated with investigating the incident, restoring operations and managing the wider business response.

  • Incident assessment
  • Technical investigation
  • System restoration
  • Business recovery
  • Legal support
  • Communications support where applicable

Cyber incidents can create losses for the affected business and may also lead to claims from customers, suppliers or other parties. These are commonly referred to as first-party and third-party losses. Understanding these concepts helps businesses compare different policy structures.

  • First-party losses: losses suffered directly by your business.
  • Third-party losses: claims made against your business by others.

No two cyber insurance policies are identical. The policy wording, schedule, endorsements, limits, sub-limits and optional extensions determine how a policy responds. Businesses should review these documents before relying on any particular feature or benefit.

  • Policy wording
  • Policy schedule
  • Limits and sub-limits
  • Endorsements
  • Optional extensions

Every policy contains conditions that influence how and when protection applies. Waiting periods, excesses, coinsurance, exclusions, endorsements and schedule-specific provisions can materially affect the outcome of a claim. These important contractual matters are explained separately in the policy-response sections.

  • Waiting periods
  • Excesses
  • Coinsurance
  • Exclusions
  • Schedule-specific provisions

Section 03

Responding to a Cyber Incident

A cyber incident is a business event. The response requires leadership, coordination and operational resilience rather than technical action alone.

Cyber incidents often begin with unusual events rather than a clear diagnosis. Employees may notice inaccessible systems, unexpected account activity, suspicious emails or reports from customers. Recognising that something is wrong is the first step towards an effective response.

  • Unexpected system behaviour
  • Files or systems become unavailable
  • Suspicious emails or account activity
  • Reports from customers or suppliers
  • Unusual operational disruption

Early decisions can influence the outcome of an incident. Businesses should remain calm, preserve evidence where possible, notify appropriate internal stakeholders and activate their incident response arrangements. Avoid making assumptions before the situation has been assessed.

  • Preserve evidence
  • Notify key decision makers
  • Activate response procedures
  • Avoid unnecessary changes to affected systems

A significant cyber incident usually requires coordinated input from multiple business functions. Management, IT, legal, finance, communications and operational teams may all have important roles depending on the nature of the incident.

  • Leadership and governance
  • Technical investigation
  • Legal considerations
  • Operational continuity
  • Stakeholder communication

Once the immediate situation has been stabilised, attention turns to restoring critical business activities safely and efficiently. Recovery should be prioritised according to operational needs and supported by clear communication.

  • Prioritise critical operations
  • Restore services
  • Communicate appropriately
  • Monitor recovery progress

After recovery, organisations should review the incident, understand contributing factors and identify lessons learned.

  • Review the incident
  • Understand contributing factors
  • Identify lessons learned

Organisations should use the lessons from the incident to strengthen future resilience. Insurance arrangements and continuity plans should also be reviewed where appropriate.

  • Control improvements
  • Business continuity review
  • Insurance review
  • Staff awareness

Section 04

How Your Policy Responds

Cyber insurance should not be reviewed by premium and headline limit alone. The practical value of a policy depends on how it responds when an incident happens. Before relying on the cover, a business should understand the conditions that may affect the amount payable, when the policy responds and what needs to be done during a claim.

  • A cyber policy can have different limits for incident response, business interruption, data recovery, cyber extortion, privacy liability and other extensions.
  • A smaller sub-limit may apply even when the headline policy limit looks higher.
  • The practical question is not only whether the policy limit is high enough. It is also which limit applies to this specific type of incident.

Advisory takeaway: Compare the policy by likely claim scenario, not by headline limit alone.

  • The excess may differ depending on the type of cover.
  • For example, one excess may apply to a system operated by the business, while another may apply to a shared or outsourced computer system.
  • This matters because many cyber incidents involve cloud platforms, external service providers or outsourced IT arrangements.

Advisory takeaway: Check the applicable excess for each cover section, not just the general policy excess.

  • A waiting period is not the same as a dollar excess.
  • It is a time threshold. Loss that falls within the waiting period may not be counted as business interruption loss.
  • This is important for businesses that rely heavily on systems but may recover within a short period.

Advisory takeaway: Ask whether the business can absorb the first few hours of disruption, and whether the waiting period matches the business operating reality.

  • Coinsurance means the business must bear the percentage of a covered loss stated in the policy schedule, after the applicable excess, and that portion is uninsured.
  • For some event types, the policy schedule may apply a specific sub-limit, coinsurance percentage and excess.
  • This does not mean there is automatically no cover. It means the amount recoverable may be affected by the event type and the conditions shown in the schedule.

Advisory takeaway: Do not assume all cyber incidents are paid using the same formula. Check whether special event mechanics apply.

  • Some third-party liability covers depend on when the wrongful act happened, when the claim is first made and whether the event falls after the retroactive date.
  • The retroactive date is not always the same as the policy start date.
  • This is especially relevant where the incident, data issue or customer allegation may have started before the current policy period.

Advisory takeaway: Before relying on the policy, review known incidents, prior complaints and the retroactive date shown in the schedule.

  • Cyber claims often move quickly. Technical investigation, legal advice, customer notification, ransom response and business interruption calculations may all depend on early coordination.
  • The policy may require written notice, supporting information and insurer consent for certain expenses.
  • For ransomware, the policy wording requires reporting to the appropriate law enforcement agencies as soon as reasonably practicable.

Advisory takeaway: When something serious happens, notify early, preserve records and seek guidance before committing major costs.

Section 05

Where Cover May Not Respond

Cyber insurance has useful applications, but it is not a blanket protection for every technology, business or contractual loss. This section helps business owners recognise the main areas where cover may not respond, so they can review contracts, systems, controls and other insurance arrangements before an incident occurs.

  • If the business already knew of a wrongful act, claim, demand, proceeding, fact, circumstance or situation before the relevant policy date, the policy may not respond.
  • This is why disclosure matters before purchase and renewal. Known incidents, regulator enquiries, customer complaints or prior notifications should be reviewed before relying on a new policy.
  • The practical question is not only whether a cyber event happened. It is also whether the business already knew, or reasonably could have foreseen, that the issue could lead to a loss.

Advisory takeaway: Keep a clear known-incident record and disclose material circumstances before renewal or placement.

  • A cyber policy may respond to covered privacy, network security or media liability. That does not mean it covers every contractual promise made to customers, vendors or business partners.
  • Contractual liability, liquidated damages, service guarantees, refund obligations and broad indemnities should be reviewed separately from the insurance placement.
  • Some policy forms may contain exceptions, but the starting point should be conservative: do not assume a contract promise is insured simply because it relates to technology or data.

Advisory takeaway: Review important client contracts before assuming cyber insurance will backstop contractual obligations.

  • Cyber policies often distinguish between covered computer systems, shared computer systems and wider infrastructure.
  • A cloud service, outsourced system or hosting provider may need to fit the wording before the policy responds. Broader failures involving utilities, internet infrastructure, DNS, payment platforms, telecommunications or similar third-party infrastructure may be restricted.
  • This matters because many businesses depend on external platforms even when they do not own or operate the underlying infrastructure.

Advisory takeaway: Map critical technology dependencies and check whether each one falls within the policy wording.

  • Cyber insurance is designed for specific cyber and data-related exposures. It should not be used as a substitute for public liability, product liability, property, crime, professional indemnity, employment practices or other cover classes.
  • Some events may involve both cyber and non-cyber issues. For example, a system issue may create operational disruption, but physical damage, bodily injury, product failure or employment disputes may sit outside the cyber policy.
  • The business should match each exposure to the correct policy rather than expecting one cyber policy to cover every consequence.

Advisory takeaway: Use cyber insurance as one part of the risk programme, not as the only protection.

  • This does not mean every serious cyber incident is excluded. The point is that certain large-scale or politically connected events may be treated differently under the policy wording or endorsements.
  • Businesses with international operations, high dependency on critical systems or exposure to global platforms should review the war, sanctions, widespread events and systemic event language carefully.
  • Where the schedule applies special sub-limits, coinsurance or endorsements, the amount recoverable may differ from the headline limit.

Advisory takeaway: For higher dependency businesses, review systemic event wording and endorsements before purchase.

  • Cyber insurance is intended to support covered incidents, not to excuse deliberate misconduct or intentional wrongdoing.
  • Conduct issues may include knowing or wilful breach of duty, criminal or deliberately fraudulent acts, deliberately dishonest omissions, improper personal profit, or intentional wrongful use or collection of personal data.
  • In some wordings, the conduct exclusion may depend on final adjudication or written admission. Even so, businesses should not rely on insurance where governance or conduct is the real issue.

Advisory takeaway: Good governance, documented decisions and proper incident handling protect both the business and the claim position.

Section 06

The NRM Advisory Approach

Understanding your business comes first.

Understanding Your Business Comes First

Before discussing cyber insurance, we first seek to understand how your organisation operates, where disruption could occur and which risks may have the greatest operational, financial or liability impact.

Every organisation is different. A meaningful recommendation begins with understanding the business, not simply comparing insurance products.

NRM Business Cyber Risk Framework
Your Business
  1. Business Technology Operations
  2. Vendors & Business Partners
  3. Countries of Operation
  4. Existing Controls & Recovery Plans
  5. Current Insurance Programme
  6. NRM Advisory Assessment
UnderstandAssessRecommend

How NRM Applies the Framework

Understand

Build an understanding of how the organisation operates, what it depends on and which activities are most critical to maintaining business continuity.

Assess

Identify operational, financial and liability exposures, review existing controls and determine where disruption could have the greatest impact.

Recommend

Only after understanding the business do we advise whether cyber insurance may support the overall risk management strategy and, where appropriate, how it should be structured.

Why This Matters

Cyber insurance is one part of a broader risk management strategy. Understanding the business first allows insurance to be evaluated within the context of operations, technology, contractual obligations and existing risk controls rather than being selected solely on premium or policy limits.

What the Review Will Explore

The review explores which systems, payment platforms and third-party service providers are critical to the business; which customer or business information could create the greatest impact if exposed; how existing insurance may respond to different cyber-related losses; and how cyber cover should be evaluated around the organisation’s actual operations and dependencies.

Start with a Business Cyber Risk Review

Start Your Business Cyber Risk Review

The objective of our review is to help you understand your cyber risk exposures, evaluate existing protection and determine whether cyber insurance forms an appropriate part of your overall risk management strategy.

Start Your Business Cyber Risk Review (opens in a new tab)

A structured business discussion.

Explore the Cyber Advisory Knowledge Centre

Good decisions begin with a better understanding of the business.