Cyber insurance cover is easiest to understand as two lists. The first is the set of costs the policy will meet, which is broadly consistent across UK insurers. The second is the set of exclusions, which is where wordings differ and where claims are argued. Buyers spend almost all their attention on the first list and almost all their disappointment on the second, so it is worth reading them the other way round.
The covered list, in the order the bills usually arrive
Incident response and forensics. Restoration of data and systems. Business interruption after a waiting period. Notification of affected individuals and the credit or identity monitoring some insurers offer them. Legal and regulatory defence costs. Third party claims by clients and by data subjects. Ransom payment and negotiation, where the section exists and the conditions are met. Public relations support. Funds taken by deception, where a crime section was bought.
Exclusions that regularly surprise buyers
Betterment, meaning the cost of coming back better than you were. Known vulnerabilities that were reported to you and left unpatched. Losses arising before the policy incepted, including an intrusion that began earlier and was discovered later, unless the wording has a retroactive date that reaches back. Contractual penalties and liquidated damages that are not a legal liability. Bodily injury and property damage, which belong to other policies. Deliberate acts by the insured.
The war and state backed attack question
After several large incidents attributed to state actors, the market rewrote its war exclusions, and the drafting is not uniform. Some wordings exclude any attack attributed to a state, some exclude only those with a material impact on essential services, and some require formal attribution before the exclusion bites. For most small businesses this will never be tested, and it is still the clause to compare when two quotes look otherwise identical.
Where cover overlaps with your other policies
A claim can touch professional indemnity where the loss flowed from your professional work, crime where money was taken, and cyber where systems and data were involved. Overlap is not a problem until both insurers point at each other. Buying both from one insurer, or at least telling each about the other, removes most of that risk.
Questions people ask about cyber insurance cover
Does cyber insurance cover ransomware payments?
Many UK wordings include a ransom section, subject to conditions, a sub limit and usually a requirement to use the insurer's negotiator. Some businesses buy the response without the payment. Check whether the section exists at all before assuming it.
Does it cover hardware that was damaged?
Data and software restoration is standard. Physical replacement of hardware is often excluded or limited, because that is what a property or business equipment policy is for.
Is business interruption from a cloud outage covered?
Only if the wording extends to an outsourced service provider, and often with a longer waiting period. This clause has become a common point of difference between quotes.
What is a retroactive date?
The date the cover reaches back to. An intrusion that started before it is not covered even if you discovered it during the policy period, which is why continuity of cover matters when changing insurer.