The cyber insurance policy document, and the clauses worth reading before you sign

A cyber insurance policy is two documents that have to be read together. The schedule is a page of limits, excesses and named sections, and it is the part most buyers look at. The wording is where the definitions, conditions and exclusions live, and it is the part that decides claims. A schedule showing a healthy limit against a wording with a condition you cannot satisfy is a policy that will disappoint at exactly the wrong moment.

The schedule tells you the shape, not the substance

Read the section list and the limit beside each one, then look for sub limits, which are where the crime, ransom and business interruption sections are usually capped well below the headline. Check the excess for each section separately. Check whether the limit is in the aggregate for the year or applies to each claim, because a policy that aggregates has already been partly spent after one incident.

Conditions precedent are the clauses that void a claim

A condition precedent to liability has to be satisfied for the insurer to pay at all. In cyber wordings these commonly cover backups, multi factor authentication, patching within a stated period, and verification of changed payment details. They are written into the policy because they were the answers you gave on the proposal form. The practical step is to take the list of conditions to whoever runs the systems and confirm each one is true today, not true in principle.

Definitions do the quiet work

What counts as a computer system, whether data includes paper records, what a cyber event actually means, how business interruption loss is calculated, and what an outsourced service provider is: each of these is defined, and each definition narrows or widens the cover more than any headline. The war and state backed attack definition has changed across the market in recent years and deserves a specific read.

Notification and cooperation clauses

Cyber wordings are strict about telling the insurer quickly, usually before engaging your own consultants. Instructing your own forensic firm on day one and telling the insurer on day four is a common and expensive mistake, because the cost incurred before notification may not be covered and the panel firm may have been cheaper. Put the incident line number somewhere the people who would need it can find it offline.

Questions people ask about cyber insurance policy

What is a condition precedent in a cyber policy?

A requirement that must be met for cover to apply. If it is not met, the insurer can decline the claim even if the loss would otherwise be covered. Backups and multi factor authentication are the usual ones.

Is the policy claims made or occurrence based?

Cyber liability sections are usually claims made, meaning the policy in force when the claim is made responds. First party sections generally respond to events discovered during the period. Check both, because a policy can mix the two.

Can I use my own IT firm to respond?

Sometimes, with the insurer's agreement, and sometimes not at all. Panel arrangements exist because insurers know what the work costs and who does it well. Agreeing the position before an incident is easier than arguing it during one.

What happens if I answered the proposal form wrongly?

It depends whether the misstatement was careless or deliberate and whether it mattered to the underwriting. UK insurance law gives insurers proportionate remedies for a careless misrepresentation and stronger ones for a deliberate one. Correcting an answer voluntarily is always better than leaving it.

Sources

Related answers

See what insurers printCompare by trade