Christensen Group Insurance Article

Connect with us
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Search
August 5, 2026

Cyber insurance: A complete guide to coverage, requirements, and underwriting

Through extensive experience in his previous role as an underwriter, Zach has specialties across the liability spectrum. His primary focus at Christensen Group spans Management Liability (Directors & Officers/Employment Practices/Fiduciary/Crime), Cyber Liability, Professional Liability/Errors & Omissions, Social Services/Non-Profit Organizations, Habitational/Multi-Family Housing, and Restaurant/Retail industries.

Ten years ago, buying cyber insurance meant answering a handful of questions and signing an application. Today it means proving to an underwriter that you already run a defensible security program. Carriers have moved from asking what controls you have to asking for evidence that those controls work, and businesses that cannot produce it are seeing higher premiums, reduced limits, or declined submissions.

That underwriting shift is central to the current market. The policy matters, but the underwriting process begins before a quote is issued.

This guide covers what cyber insurance actually covers, what it does not, what it costs, the security controls underwriters now expect, and how to prepare before your next renewal or first application. It is written for business owners, CFOs, and operations leaders, with a section at the end on personal cyber coverage for individuals and families. For additional context, see our breakdown of the 2025 IBM study, which reported a $10.22 million average breach cost among U.S. organizations in its dataset.

In this guide

  • What cyber insurance is, and why general liability coverage may not be enough
  • First-party and third-party coverage explained
  • What cyber insurance covers, coverage by coverage
  • What cyber insurance does not cover
  • Who needs cyber insurance
  • What cyber insurance costs, and what drives your premium
  • Is cyber insurance worth it?
  • Cyber threats affecting insurance underwriting
  • Cyber insurance requirements: ten common underwriting control areas
  • How to prepare for a renewal or a first application
  • How to think about limits
  • Personal cyber insurance for individuals and families

Free download: Cyber Insurance Requirements Checklist

Forty-seven controls across the ten areas underwriters evaluate, plus a self-assessment scoring tool that tells you where you stand in under ten minutes. Download the checklist.

What is cyber insurance?

Cyber insurance is a specialty line designed to cover the financial consequences of a digital incident: data breaches, ransomware, extortion, funds transfer fraud, system damage, and the liability that follows when someone else’s information is exposed on your watch.

It is worth being precise about one thing early, because it is the most common and most expensive misconception in this category. Cyber losses are generally not covered by your general liability policy. Some commercial packages include language that sounds cyber-adjacent, and a few offer a small endorsement, but the limits are nowhere near the cost of a real incident and the covered causes of loss are narrow. If a ransomware event takes your operations offline for a week, a general liability policy is not the thing that responds.

Cyber coverage also differs from most other lines in what it delivers. A well-structured policy is not only a check after the fact. It may give you access to an incident response panel: forensics, breach counsel, notification vendors, negotiators, and public relations support, generally at pre-negotiated rates. For most businesses that service is worth as much as the indemnity, because the first 48 hours of an incident determine how expensive the next six months become.

First-party and third-party coverage

Most standalone cyber policies combine first-party and third-party insuring agreements. Understanding which half responds to which loss is the fastest way to read a quote.

First-party coverage Third-party coverage
Who is harmed Your business Someone else, who then makes a claim against you
What it pays for Your own direct costs to respond to and recover from an incident Your legal liability, defense costs, settlements, and regulatory exposure
Typical triggers Ransomware, system damage, business interruption, funds transfer fraud, data restoration, extortion Breach of customer or employee data, failure to safeguard information, regulatory investigations, media liability
Common gap Waiting periods and sublimits that quietly cap the coverage you thought you bought Limits shared with first-party coverage, so one large event erodes both

Most businesses need both types of protection. Misunderstanding the distinction can create gaps or unexpected limitations when a claim occurs.

What does cyber insurance cover?

Coverage is modular, and terminology varies between carriers. These are the components worth confirming line by line on any quote you receive.

First-party coverages

  • Incident response and forensics. Investigating what happened, what was accessed, and how to contain it. Usually the first coverage to activate.
  • Business interruption. Lost income and extra expense while your systems are down. Check the waiting period, often 6 to 12 hours, and how the carrier measures loss.
  • Dependent business interruption. Also called contingent business interruption. It may cover lost income and extra expense when a qualifying dependent provider experiences a covered event, subject to policy definitions, waiting periods, and sublimits. This matters as operations move into third-party platforms.
  • Cyber extortion and ransomware. Ransom negotiation, payment where legally permitted and approved under the policy, and restoration costs. Ransom payments may be subject to sanctions restrictions, carrier consent, and a separate sublimit. 
  • Data restoration. Recreating or repairing data and applications that were corrupted or destroyed.
  • Bricking. When an attack renders hardware permanently unusable, bricking coverage pays to replace it. Many policies exclude or sublimit this, and most buyers never ask.
  • Funds transfer fraud. May cover money moved from your accounts through fraudulent instructions. Depending on the program, this protection may appear in a cyber policy, crime policy, or endorsement.
  • Social engineering fraud. An employee is deceived into sending money or credentials voluntarily. This is frequently a separate, low-sublimit coverage rather than part of the base form, and it is one of the most common losses small and mid-sized businesses actually suffer.
  • Invoice manipulation. An attacker in your email system redirects a customer payment. Your customer paid, you never received it, and you may still owe the work. Not all forms include this.
  • Reputational harm. Lost revenue attributable to publicity following an incident, where offered.
  • Breach response and notification. May cover legal analysis, notification, call-center services, credit monitoring, and other direct response costs when personal information is exposed, subject to the policy terms.

Third-party coverages

  • Privacy and network security liability. Claims arising from exposed personal or confidential information, or from your network being used to harm someone else.
  • Regulatory defense and penalties. Investigations and fines under data protection laws, where insurable.
  • PCI fines and assessments. May cover card-brand assessments and related expenses following a payment card breach, where included and insurable. Organizations that accept payment cards should review the applicable terms and sublimits.
  • Media liability. Defamation, copyright, and similar claims arising from your digital content.
  • Notification and privacy liability. Claims alleging that the organization failed to satisfy applicable privacy or notification obligations.

For a look at how these coverages behave in a real event, our case study on the Jaguar Land Rover breach walks through where the costs actually landed.

What cyber insurance does not cover

Exclusions and limiting conditions are among the most important parts of a cyber policy review because they determine when otherwise relevant coverage may not respond.

  • War and hostile acts. Carriers have significantly tightened this language in recent years, particularly around state-sponsored attacks. Because attribution is difficult and slow, the wording of this exclusion matters a great deal. Read it.
  • Prior known incidents and vulnerabilities. Policies commonly exclude incidents or circumstances known before coverage began. How a provision applies to a known vulnerability depends on the policy language, what the applicant disclosed, and whether the issue contributed to the loss.
  • Application inaccuracies and control-related conditions. Applications should be completed accurately and with input from the people responsible for the organization’s technology. A material inaccuracy may jeopardize coverage or affect how a claim is handled, depending on the policy and applicable law.
  • Bodily injury and property damage. These losses are often excluded or limited under cyber forms and may fall under general liability, property, or other policies depending on the facts and policy language. This creates an important gap question for manufacturers and organizations with operational technology.
  • Betterment. The cost of upgrading systems beyond their pre-incident condition. Coverage generally focuses on restoration rather than improvement, although wording and limited betterment provisions vary.
  • Intellectual property and patent claims. Often excluded or addressed outside standard cyber forms, depending on the claim and policy wording.
  • Insider fraud by owners or executives. Dishonest acts by the insured, as distinct from employees deceived by an outsider.

Who needs cyber insurance?

Practically speaking, any business that holds data, moves money, or depends on systems to operate. That is nearly everyone.

The instinct that small businesses are too small to target has it backwards. Attackers are opportunistic and increasingly automated. They are not selecting victims by revenue, they are scanning for exposed systems and weak credentials, and smaller organizations tend to have fewer defenses and no dedicated security staff. A ransomware demand that a large enterprise absorbs as a bad quarter can end a 30-person company.

Some exposures raise the stakes further:

  • You collect personally identifiable information. Names, emails, addresses, and Social Security numbers all qualify, and most businesses collect more than they realize.
  • You handle protected health information, which is materially more valuable to criminals and carries stricter regulatory consequences.
  • You process payment cards, which brings PCI exposure alongside the breach itself.
  • You initiate or approve wire transfers, which is the exposure behind most social engineering losses.
  • You depend on a small number of vendors or platforms, which concentrates dependent business interruption risk.
  • Your contracts require it. Many customers, landlords, and lenders now mandate cyber limits, and certificates of insurance are increasingly checked rather than filed.

Some industries see disproportionate attack volume, including healthcare and human services, energy, hospitality, retail, manufacturing, professional services, and construction. If you operate in one of them, treat your policy review as a scheduled task rather than a renewal formality.

What does cyber insurance cost?

There is no useful average, because premium is driven less by your size than by your controls. Two businesses with identical revenue can receive quotes that differ by a multiple, based entirely on what their security posture looks like to an underwriter.

The factors that move your premium most:

  • Your security controls, especially multi-factor authentication, endpoint detection and response, and tested backups
  • Industry and the sensitivity of the data you hold
  • Revenue and record count, which drive your exposure ceiling
  • Claims history, including incidents you handled without a claim
  • Limits, retention, and which sublimits you buy up
  • Whether your application is complete, specific, and verifiable, since ambiguity gets priced as risk

The practical implication is that premium is partly within your control, which is not true of most lines. Closing two or three control gaps before you go to market often pays for itself in the first renewal. For a closer look at figures for smaller organizations, see our breakdown of small business cyber insurance costs.

Is cyber insurance worth it?

The honest answer is that it depends far less on whether you will have an incident than on what a bad one would do to you.

Run the arithmetic on your own worst realistic week. Take your revenue, assume systems are unavailable for five business days, add the forensics and legal costs, add notification for every record you hold, and add the possibility that a customer or regulator comes after you afterward. For most small and mid-sized businesses that number lands somewhere between uncomfortable and existential, and it dwarfs the annual premium by a wide margin.

Two aspects of the value are commonly missed. The first is the incident response panel. Having a breach counsel, a forensics firm, and a ransom negotiator on call at pre-negotiated rates is worth a great deal at 6 a.m. on the morning you discover the problem, and assembling that team from scratch under pressure is both slower and more expensive. The second is that many businesses now need the coverage contractually. Customers, landlords, and lenders increasingly require specific cyber limits, and certificates are being verified rather than filed.

Where cyber insurance disappoints people is almost never the decision to buy it. It is buying a limit that looks adequate in the aggregate while the coverage that actually responds to your most likely loss sits behind a small sublimit. A policy bought carefully is one of the better values in commercial insurance. A policy bought on price alone tends to reveal that at the worst possible moment.

Cyber threats affecting insurance underwriting

Underwriting questions map directly to loss data. Knowing which attacks are driving claims tells you what you will be asked about, and which coverages you should be checking. What follows focuses on the insurance side of each threat. For the prevention side, including the specific controls and employee procedures that stop these attacks, see our small business guide to cyber security threats and risk mitigation.

Business email compromise and social engineering

Still the most common way money leaves a business. An attacker gets into an email account, watches a transaction develop, then intervenes at the moment of payment with new banking instructions. No malware required, and no technical control stops it on its own.

The defense is procedural. Require verbal callback verification for any new or changed payment instructions, using a phone number you already have on file rather than one supplied in the email. Tell your customers and vendors that this is your policy, so a fraudulent request looks wrong to them too.

Ransomware and double extortion

Many ransomware attacks now combine encryption with data theft and a threat to publish the information. Clean backups can support restoration, but the organization may still face breach-response, notification, regulatory, and liability obligations.

This is why underwriters ask about backup isolation and restoration testing rather than simply whether you have backups, and why extortion sublimits deserve a close look.

AI-enabled impersonation

Synthetic voice and video have moved social engineering past the badly written email. A convincing call from a familiar voice, or a video meeting with someone who looks like your CFO, defeats the instincts most employee training was built around. Verification procedures that depend on recognizing a person no longer hold, which is exactly why callback verification to a known number has become the control that matters.

Credential theft and MFA bypass

Infostealer malware can harvest saved passwords and session tokens, while repeated approval prompts may pressure a user into accepting a fraudulent login. Multi-factor authentication remains one of the most important account-security controls, and phishing-resistant methods or number matching generally provide stronger protection than simple approval prompts.

Third-party and supply chain compromise

Your risk now includes your vendors’ risk. A compromise at a payroll provider, a managed IT firm, or a SaaS platform can halt your operations without anyone touching your network. Underwriters have started asking who your critical vendors are and what security terms your contracts require, and dependent business interruption coverage exists precisely for this scenario.

Phishing, quishing, and the human layer

Phishing remains the most common entry point, and it has moved beyond email into text messages, collaboration tools, and QR codes. A malicious QR code placed over a legitimate one is difficult to spot by design, since the payload is invisible until it is scanned. For underwriting purposes, what matters is that carriers will ask specifically about email filtering, external-sender warnings, DMARC enforcement, and whether you run simulation exercises, so those answers are worth having ready before you apply.

System destruction and bricking

Some attacks are not about money. When an intruder renders hardware permanently unusable, the loss is replacement cost plus the interruption, and standard property forms typically will not respond. Confirm whether your policy includes bricking coverage and at what sublimit.

Distributed and remote work widens most of these exposures. Our guide to preventing cyberattacks on remote employees covers the controls that matter when your network extends into home offices.

Cyber insurance requirements: what underwriters expect

This is where placements succeed or fail. Carriers evaluate roughly ten control areas, and in our experience most organizations fail 25% to 40% of the controls on a current underwriting checklist. The good news is that the gaps are usually specific and fixable, and finding them before you submit is far better than finding them in a declination letter.

Here is what each area covers.

1. Identity and access management

Multi-factor authentication is non-negotiable, and it needs to be on email, VPN and remote access, privileged accounts, and cloud applications. Underwriters also look for unique user IDs with no shared credentials, a real password policy, single sign-on where practical, privileged access management for admin accounts, and least privilege enforced generally.

2. Endpoint security and device protection

Most ransomware losses begin at a compromised endpoint. Expect questions about endpoint detection and response deployed across all servers and workstations, full-disk encryption on laptops, automated anti-malware updates, mobile device management for anything touching corporate data, and automatic screen lockout.

3. Network security

A firewall alone is no longer an answer. Underwriters expect layered defenses: a next-generation firewall with intrusion detection and prevention, network segmentation separating critical assets from general traffic, secure remote access through VPN with multi-factor authentication or a zero trust approach, regular firewall rule reviews, secure configuration standards, and guest Wi-Fi isolated from business systems.

4. Data protection and backups

Backup quality is now one of the most scrutinized areas on the application. Daily or more frequent backups of critical systems, offsite or immutable copies isolated from the network, encryption in transit and at rest, and quarterly restoration testing. Untested backups are treated as no backups, because in practice that is often what they turn out to be. A data classification policy and formal retention and destruction rules round out the area.

5. Patch and vulnerability management

Outdated systems are among the biggest red flags an underwriter can find. Carriers look for a formal patch management program, critical patches applied within 14 to 30 days, automated operating system and application updates, routine internal and external vulnerability scanning, and a current hardware and software asset inventory.

6. Email security and anti-phishing controls

Given that email is the primary vector for business email compromise, expect scrutiny of advanced filtering for phishing, spoofing, and malware, DMARC, DKIM, and SPF implemented and actually enforced, anti-phishing warnings on external senders, and a secure email gateway or cloud email security add-on.

7. Incident response and business continuity

Underwriters want evidence of preparation, not intent. That means a documented incident response plan, a tabletop exercise conducted within the last twelve months, logged incident history and remediation, centralized logging or a SIEM, and a documented and annually tested business continuity and disaster recovery plan.

One practical note from experience: keep a hard copy of your incident response plan somewhere your key people can reach it. We have seen well-built plans stored on a company server or in the cloud become inaccessible during the exact ransomware event they were written for.

8. Security awareness and training

Human behavior remains the least predictable variable in any security program. Annual employee training, routine phishing simulations, documented participation records, and role-based training for privileged users and executives.

9. Vendor and third-party risk management

A weak vendor can jeopardize both your operations and your coverage. Underwriters ask about security assessments for critical vendors, contracts requiring security standards and breach notification, SOC 2 or ISO 27001 certification for key providers, documentation of data sharing and access rights, and an inventory of every vendor with network or data access.

10. Policy, governance, and compliance

Administrative controls need to be documented and current: cybersecurity policies and procedures covering acceptable use, data protection, and remote work; risk assessment reports; compliance documentation for whichever frameworks apply to you, such as NIST, CIS, SOC 2, ISO 27001, HIPAA, or PCI DSS; prior applications and claims history; and records proving you remediated past weaknesses.

Score your readiness in under ten minutes

Our Cyber Insurance Requirements Checklist breaks these ten areas into 47 specific controls with checkboxes, so you can see exactly where the gaps are before an underwriter does. It includes a self-assessment score:

  • 40 to 47: strong underwriting posture
  • 25 to 39: insurable, with improvements recommended
  • 10 to 24: high risk, placement difficulty likely
  • 0 to 9: foundational controls needed before obtaining coverage

Download the free Cyber Insurance Requirements Checklist (PDF)

How to prepare for a renewal or a first application

Treat the application as an underwriting exam you can study for, because that is what it is.

  1. Start 90 to 120 days before your renewal date. Gap remediation takes longer than anyone expects, and a rushed submission gets priced conservatively.
  2. Complete the checklist and application accurately, with input from the people responsible for the organization’s technology. A material inaccuracy may jeopardize coverage or affect how a claim is handled, depending on the policy and applicable law.
  3. Fix the highest-leverage gaps first. Multi-factor authentication everywhere, endpoint detection and response, and tested isolated backups move the needle more than anything else on the list.
  4. Gather your documentation. Policies, training records, tabletop exercise notes, scan results, and vendor certifications. Underwriters increasingly ask for evidence rather than attestations.
  5. Get your IT provider or internal team in the room early. Most application questions are technical, and answers relayed secondhand tend to be vague in ways that cost money.
  6. Review last year’s policy before you market it. Sublimits, waiting periods, and the war exclusion may have changed at the last renewal without anyone flagging it.

If a control genuinely cannot be implemented in time, say so and explain the compensating control and your timeline. Underwriters respond far better to a specific plan than to a blank field.

How to think about limits

Limit selection is where most businesses guess. A more useful approach is to build from your own numbers rather than from a benchmark.

  • Estimate your record count and the notification cost per record, which is largely mechanical and often the largest single line in a breach.
  • Model a realistic downtime scenario. If your systems were unavailable for a week, what is the revenue impact and what extra expense would you incur?
  • Check your contractual minimums, since a required limit is a floor, not a recommendation.
  • Look at sublimits, not just the aggregate. A $2 million policy with a $100,000 social engineering sublimit is a $100,000 policy against the loss you are most likely to have.
  • Confirm whether first-party and third-party coverage share one limit, because a single large event can otherwise exhaust both.
  • Ask about reinstatement, and whether your limit refreshes if you have a second incident in the same policy period.

Benchmarking against similar businesses in your industry is useful context, and it is something a broker with access to placement data can give you that a comparison site cannot.

Personal cyber insurance for individuals and families

Cyber risk does not stop at the office. Households now run dozens of connected devices, manage finances online, and store years of irreplaceable data on personal machines, and the same criminal economy targets both.

Personal cyber coverage is usually available as an endorsement to a homeowners policy, and some insurers offer it only on higher-value homeowners programs. A smaller number offer standalone policies. If you own a business, hold a public profile, or serve on a board, this coverage is worth a specific conversation rather than an assumption.

What personal cyber coverage typically includes

  • Online fraud. Reimbursement for financial loss from phishing, unauthorized banking, or fraudulent transfers.
  • Identity recovery. The cost of restoring your identity after theft, including credit restoration help, correcting records with banks and agencies, and lost wages spent resolving it.
  • Data restoration. Recovering a device and its data after a malware or virus infection.
  • Cyber extortion. Responding to a ransomware demand on a personal device, including specialist help and restoration.
  • Data breach response. Notification and recovery services if private information entrusted to you is lost or exposed.
  • Cyberbullying. Costs of recovering from harassment or defamation, which can include counseling, legal advice, temporary relocation, and social media monitoring. Some forms also respond if a family member is accused and faces legal action.
  • Online shopping protection. Goods paid for online that arrive damaged or never arrive at all.

Common personal cyber incidents

  • Bank fraud, where a criminal obtains electronic banking credentials and moves funds
  • Identity theft using a Social Security number or card details to commit fraud in your name
  • Data loss from malware arriving through a malicious site, an email attachment, or an infected drive
  • Extortion, where a personal device is compromised and a ransom demanded for restoration, sometimes with a threat to publish
  • Cyberbullying and online harassment, which disproportionately affects children and teenagers

The same fundamentals apply at home as at work: unique passwords managed properly, multi-factor authentication on financial and email accounts, current software, and healthy skepticism toward anything urgent. Coverage handles what those measures do not. Talk with our personal insurance team about adding cyber coverage to your homeowners policy.

Talk with a cyber insurance specialist

The policy form is only one part of the decision. The underwriting submission is where businesses are most likely to identify gaps or encounter limitations, and it is where an experienced broker can add significant value.

Christensen Group’s cyber team includes specialists with underwriting-side experience, which can help us assess how a submission may be viewed before it is sent. We provide pre-application readiness reviews, coverage benchmarking against comparable placements, remediation roadmaps, access to IT and security resources, and practical guidance on improving readiness and insurability. As one of the largest independent brokerages in the Midwest, we can approach multiple carrier markets rather than being limited to one underwriting appetite.

If you have been non-renewed, declined, or hit with an increase you cannot explain, that is a solvable problem and usually a specific one. Get in touch or call (800) 923-4088 to request a cyber insurance readiness assessment, and we will tell you where you stand before your next renewal.

Related reading

This article is intended for general information and is not exhaustive. Coverage terms, conditions, and exclusions vary by carrier and policy form, and nothing here should be construed as legal advice or a representation of coverage. Review your specific policy and consult your broker or legal counsel.

Get the latest insurance articles sent to your inbox

Stay up-to-date with our latest insurance news and information.

Speak with an insurance expert.

Talk with us today