Cyber liability insurance, and who can actually sue you after a breach

Cyber liability insurance is the half of the product that answers to other people. First party cover pays your own recovery bills; liability cover answers the claims that arrive afterwards from the people whose data you held, from clients whose work you disrupted, and from a regulator asking questions. The two halves are usually sold together and it is worth knowing which one you are relying on when you size a limit.

Claims by the people whose data it was

Individuals whose personal data was exposed can claim for the loss and distress caused. Individually these claims are small; collectively, after an incident affecting a large file of clients, patients or tenants, they are the reason the liability limit exists. Firms holding sensitive categories of data, health, financial or children's records, should size this section against the number of records rather than against turnover.

Claims by clients under contract

A business to business client whose own operations were disrupted, or whose data you held as a processor, will look first at the contract. Indemnities, liability caps and required insurance clauses in that contract decide the exposure long before the insurance does. Reading the contract and the policy together is the only way to know whether the limit you bought matches the limit you promised.

Regulatory investigation and the cost of answering

The Information Commissioner can require an explanation, and answering properly takes legal and technical work. That cost is insurable and usually covered; whether a resulting monetary penalty is insurable depends on the law, and the wording will say. For most small firms the investigation is the realistic expense and the penalty is not.

How this differs from professional indemnity

Professional indemnity answers for financial loss caused by your professional work, which can include advice that failed. Cyber liability answers for loss caused by a data or systems event. A single claim can plausibly sit in either, and the two wordings can each point at the other. Holding both from one insurer, or telling each insurer about the other policy, is how that argument is avoided.

Questions people ask about cyber liability insurance

Is cyber liability the same as cyber insurance?

It is the liability half of it. A full cyber policy carries first party costs as well, and for many small businesses those are the more likely claim. A quote titled cyber liability may or may not include them, so check the section list.

Can a client sue me for their downtime?

If the contract makes you liable, yes. This is why the liability cap in your terms matters as much as the policy limit, and why professionally drafted terms are cheaper than the alternative.

Do I need it if I only process data for others?

Processors have direct duties under UK data protection law and are routinely named in claims, so yes. Client contracts also usually require it explicitly.

Is the limit per claim or for the year?

Frequently in the aggregate for the year on cyber wordings, which means one incident can consume it. Check the schedule, and check whether defence costs sit inside the limit.

Sources

Related answers

See what insurers printCompare by trade