Cyber and data insurance is the name several UK insurers print on the product, and the second word is doing real work. A great deal of what the policy pays for is triggered by personal data leaving the business rather than by a system being damaged, and those costs arrive even when nothing was encrypted, nothing was stolen and the business was trading normally the whole time. Understanding the data half explains most of the premium.
A data incident can cost money without breaking anything
An email sent to the wrong list. A laptop left on a train. A misconfigured folder that was readable for a fortnight. In each case the systems are fine and the obligations are not. Somebody has to establish what was exposed and to whom, decide whether the reporting threshold is met, tell the regulator if it is, tell the individuals if the risk to them is high, and answer what comes back. That is a professional services bill arriving on a short deadline, and it is the core of what the data section buys.
The clock, and why the response service matters more than the limit
The reporting window for a notifiable personal data breach is measured in hours rather than weeks, and the assessment of whether it is notifiable has to happen inside it. A business doing this for the first time, without a lawyer on call, either reports something it did not need to or misses something it did. The panel arrangement behind a cyber and data policy is what compresses that decision into the time available.
Liability to the people whose data it was
Individuals can claim for the distress and loss caused by a breach of their data, and group claims following larger incidents are now a feature of the market. The liability section answers for those claims and for the cost of defending them. For a business holding a large client or patient file, this is the section where a serious limit is worth buying, because the exposure scales with the number of records rather than with the size of the firm.
What the data section does not stretch to
It does not pay to build the data protection compliance the business should already have, and it will not answer for a deliberate misuse of data by the insured. Cover for the cost of a regulator's fine depends on whether the law allows that fine to be insured. The reliable purchase is the investigation, the notification and the defence, not immunity from the outcome.
Questions people ask about cyber and data insurance
Is a data breach the same as a cyber attack?
No. Most notifiable breaches in small firms are mistakes rather than attacks. The policy responds to both, which is why the name carries two words.
When do I have to report a breach to the ICO?
When the breach is likely to result in a risk to people's rights and freedoms, and within the short window the law sets. The Information Commissioner publishes the test and a self assessment tool; an insurer's panel lawyer will usually confirm the judgement.
Does it cover paper records?
Several UK wordings do, which surprises buyers who expect a purely digital product. A lost file of client records is a data incident whatever it was written on. Check the definition of data in the wording.
Do I need this if I hold very little personal data?
The data half matters less and the systems and crime halves may still matter a lot. Size the sections to the business rather than declining the whole product.