Cyber security insurance, and why the name confuses two different purchases

Cyber security insurance is the name a lot of buyers reach for, and it quietly bundles two purchases that have almost nothing in common. One is the security work itself: the software, the patching, the backups, the training. The other is an insurance policy that pays when that work fails. Insurers sell the second and increasingly demand the first before they will quote, which is why the phrase turns up in searches from businesses who are not yet sure which of the two they are shopping for.

Security is what you buy. Insurance is what happens when it fails

Nothing an insurer sells will stop an attack. A policy is a promise about money and about help after the event: the cost of getting the systems back, the cost of telling the people whose data went, the legal bill, the lost trading income, and in most wordings a response team on a telephone number that answers at two in the morning. Security spending changes the odds. Insurance changes what the bad outcome costs you. A business that treats the policy as a substitute for backups has bought the wrong thing, and the wording will usually say so in its conditions.

Insurers now ask what your security looks like before they quote

The questions have hardened over the last few years and they are broadly the same across the market: are backups held separately from the live system and tested, is multi factor authentication turned on for remote access and for email, is there a patching routine, who has administrator rights, and has anyone been trained to spot a fake payment instruction. Answering no is not always a refusal, but it moves the price and it can attach a condition that voids a claim if the control was not actually in place. Cyber Essentials exists partly because insurers wanted a common floor to ask about.

What the policy is actually called on the schedule

Very few UK insurers print the words cyber security insurance on a schedule. The product is usually written as cyber, cyber and data, or cyber liability, and the sections inside it are what matter: first party costs for your own losses, third party liability for the claims made against you, and a crime or funds transfer section that some insurers include and others sell separately. When comparing quotes, compare the section list rather than the product name, because two policies with the same title can leave out completely different things.

Where it sits beside the cover you already have

Most small businesses meet cyber after they have already bought public liability and professional indemnity, and often after being told that neither of those answers for a hacked mailbox. Public liability answers for physical harm. Professional indemnity answers for financial loss caused by your professional work, which can overlap with a cyber claim and just as often does not. Cyber is the section that answers for the incident itself: the ransom demand, the days offline, the notification, the regulator's questions.

Questions people ask about cyber security insurance

Is cyber security insurance the same as cyber insurance?

In practice yes, and the second is what insurers call it. Cyber security insurance is a search phrase rather than a product name, and asking an insurer for it will get you a cyber or cyber and data policy. The thing to check is the section list on the schedule, not the words on the front.

Do I need Cyber Essentials to get cyber insurance?

Not always, but it helps and some schemes require it. Cyber Essentials certifies a set of basic controls, and because insurers were asking about those same controls anyway, holding it shortens the proposal form and can widen who will quote.

Will the policy pay for better security after an attack?

Usually not as a matter of course. Most wordings pay to restore the systems to the state they were in, not to improve them. Some insurers offer a betterment contribution or bundle risk management services, which is worth asking about before you buy rather than after.

Does it cover a mistake by my own staff?

Generally yes for a negligent error such as clicking a phishing link or misdirecting data, which is how a large share of claims arise. A deliberate criminal act by an employee is usually a different section or an exclusion, so read how the wording treats insider acts.

Sources

Related answers

See what insurers printCompare by trade