Cyber attack insurance is the part of a cyber policy that answers when somebody is actually inside the system. The distinguishing feature of that claim is not its size, it is its speed: decisions about isolating systems, paying or not paying, reporting or not reporting, and telling clients or waiting all have to be made in the first day or two, by people who have never made them before. What the policy buys, before it buys anything else, is somebody who has.
The order of events in a real incident
Detection, usually late and usually by accident. Containment, which means deciding what to switch off while the business is trying to trade. Forensic investigation to establish what was accessed, because the reporting duty depends on the answer. A decision about extortion if a demand exists. Restoration from backups, or the discovery that the backups were on the same network. Then notification, client communication and the regulator. Each stage has a bill attached and the policy is written to meet them in that order.
Why the response panel is the product
A small business cannot retain a forensic firm, a data protection lawyer and a negotiator on a Friday evening at short notice, and would not know which ones to call. The insurer already has them under contract at agreed rates. That is why notifying the insurer before instructing your own consultants is a condition in most wordings and a good idea regardless: the cost is lower and the people are better.
Ransom: the section with the most conditions
Where a ransom section exists it typically requires the insurer's consent, use of the insurer's negotiator, and checks that paying would not breach sanctions. Paying is rarely the fastest route back and is not the default advice from the National Cyber Security Centre. The value of the section is less the money than the negotiation, which frequently buys time and information rather than a key.
What the loss looks like once it settles
For most small businesses the largest single line is not the ransom and not the forensics: it is the trading income lost while the systems were down, and the professional fees around the reporting duty. Both are covered, both are capped by sub limits and a waiting period, and both are the numbers worth sizing before buying rather than after.
Questions people ask about cyber attack insurance
Should I pay a ransom?
The National Cyber Security Centre does not encourage it and payment does not guarantee recovery or silence. Where a policy includes the section, the insurer's negotiator will advise. Sanctions rules can also make payment unlawful depending on who is demanding it.
How quickly do I have to tell my insurer?
Immediately, and before engaging your own consultants where the wording says so. Late notification is one of the most common reasons a cyber claim is reduced.
Will the policy pay if the attack came through a supplier?
Your own costs and your own liability are generally covered, including where the entry point was an outsourced provider. The supplier's own losses are not yours to claim.
Does it cover an attack that started before the policy began?
Usually not, unless the wording carries a retroactive date that reaches back. This is the clause to check when moving insurer.