Cyber insurance coverage is not one promise, it is a stack of sections that were assembled separately and are still sold separately by some insurers. Two quotes with the same headline limit can differ by everything that matters, because one of them carries a crime section and a real incident response service and the other carries neither. Reading the coverage means reading the list, not the price.
First party: what it costs you to recover
This is the section that pays your own bills. Forensic investigation to work out what happened, specialist help to get systems back, data restoration, and business interruption for the trading income lost while you were down. Business interruption is the one to look at hardest: check the waiting period before it starts to pay, check whether it covers a failure at an outsourced provider, and check how the loss is calculated, because a small business with lumpy revenue can find the formula unhelpful.
Third party: the claims other people make against you
Liability to the people whose personal data was exposed, to clients under contract, and the cost of defending any of it. Regulatory investigation costs sit here or in their own section, and fines sit wherever the law allows them to be insured, which is a question the wording will answer carefully. This is the section that responds when a client says your breach cost them money.
Crime and social engineering: the section most often missing
A transfer made on a fraudulent instruction is not a hack, and a lot of cyber wordings do not pay for it unless a crime or social engineering section has been added. For businesses that pay suppliers or handle client money, this is frequently the largest realistic loss, and it is the section most often absent from a cheap packaged quote. Where it exists it usually carries its own smaller sub limit and its own conditions about verifying changed bank details.
The services wrapper, which is not a section but decides the outcome
Most of the value in a cyber claim arrives in the first day, in the form of people who have done this before. A policy with a twenty four hour incident line, a panel of forensic and legal firms and a pre agreed process behaves completely differently from one that asks you to notify a claim and wait. Ask what the response arrangement actually is before you buy, because it is rarely visible on the schedule.
Questions people ask about cyber insurance coverage
What is not covered by cyber insurance?
Common exclusions are the cost of upgrading systems beyond their previous state, losses from a failure you knew about and did not fix, contractual penalties that are not a legal liability, and acts of war or state backed attack as defined in the wording. Deliberate criminal acts by the insured are always out.
Are regulatory fines covered?
Only where the law permits a fine to be insured, and the wording will be explicit. What is more reliably covered is the cost of the investigation itself, which is often the larger bill for a small business.
Does it cover reputational damage?
Directly, rarely. What is commonly covered is the cost of public relations and customer notification work aimed at limiting the damage. Lost future custom is very hard to insure and most wordings do not attempt it.
How do I compare two quotes with different limits?
Compare the section list first, then the sub limits inside each section, then the aggregate. A headline limit that sits above a crime sub limit a fraction of its size is telling you where the insurer expects to pay.