Cyber insurance transfers specified financial consequences of cyber events under a particular policy; it does not transfer the duty to manage cyber risk or guarantee that every incident will be covered. Buyers should map their loss scenarios, validate every application answer, compare definitions and exclusions, and test the notification and claims process before an incident.
There is no universal control checklist, premium or coverage amount. Requirements vary by insurer, jurisdiction, sector, revenue, data, technology, loss history and requested limits. Treat any market benchmark as a starting point for a broker discussion, not a quote or eligibility rule.
Official guidance is also jurisdiction-specific. The UK National Cyber Security Centre (NCSC) advises buyers to check existing cover, combine cybersecurity and insurance or legal expertise, understand incident impacts, examine what a policy covers and excludes, and confirm which services and conditions apply to a claim or renewal. The European Insurance and Occupational Pensions Authority (EIOPA) has separately called for clear insurance terms and attention to exclusions, ambiguous non-affirmative cyber cover and sound underwriting. Those sources inform the review questions below; they do not determine coverage under a particular contract.
Define the exposure before shopping for cover
Build a scenario-based view of potential loss. Consider:
- incident investigation, containment, restoration and specialist advisers;
- business interruption and extra expense;
- data-protection response and legally required notifications;
- liability to customers or other third parties;
- digital fraud and social-engineering losses;
- ransomware and extortion response, subject to law and policy terms;
- dependent-business interruption caused by suppliers; and
- regulatory investigations, where insurable and covered.
Map each scenario to existing insurance, contractual indemnities, reserves and proposed cyber cover. Look for gaps and overlapping clauses rather than assuming a policy title settles coverage.
Evidence underwriters may request
Insurers commonly ask about identity controls, remote access, endpoint and email protection, backups, vulnerability management, security awareness, incident response and supplier dependencies. The exact questions and required evidence belong to the insurer.
Prepare evidence that can be defended:
| Area | Useful evidence |
|---|---|
| Identity | MFA scope, privileged-account inventory, access reviews, exceptions |
| Detection | Logging coverage, alert ownership, escalation records, response metrics |
| Resilience | Backup architecture, immutability or separation, restore-test results |
| Vulnerabilities | Asset inventory, scan coverage, remediation rules, exception approvals |
| Response | Approved plan, current contacts, exercise record, retained specialists |
| Suppliers | Critical-provider register, dependency analysis, contract and exit controls |
Do not answer from a policy document alone. Confirm implementation with system owners and retain the dated evidence used. If an answer is qualified, explain the scope and remediation rather than turning a partial control into an unqualified “yes”. The NCSC cyber insurance guidance cautions that if an organisation claims security measures are in place when they are not, the insurer may not be obliged to pay a claim. The legal consequence still depends on the applicable law, policy wording and facts.
Our cybersecurity services can help validate control evidence and close material gaps before submission.
Read the policy as an operating document
Compare the actual wording, endorsements and schedule. EIOPA's supervisory statements on exclusions and cyber exposures emphasise clear terms and attention to potential ambiguity; they supervise insurer conduct and do not interpret an individual buyer's contract. Have qualified insurance and legal advisers review terms relevant to your facts. Pay particular attention to:
- how “computer system”, “security failure”, “privacy event” and “claim” are defined;
- waiting periods and methods for calculating business interruption;
- sublimits, deductibles or retentions and territorial scope;
- dependent-provider and cloud-service cover;
- ransomware, social engineering and funds-transfer terms;
- prior knowledge, known events and retroactive dates;
- security-control, war, infrastructure and contractual-liability exclusions;
- consent requirements for advisers, costs, settlements or communications; and
- notification channels and deadlines.
Coverage labels are not interchangeable between policies. Ask the broker or insurer to explain how named scenarios would be treated and record the answer.
Connect insurance to incident response
Put policy details in the incident plan without exposing them broadly. The response team should know who can notify the insurer, who can approve expenditure, whether the policy requires consent or use of specified or pre-approved responders, and how to preserve records.
Run a tabletop exercise involving security, legal, privacy, finance, communications, operations, the broker and, when available, insurer-approved responders. Test a realistic timeline from detection through notification, vendor engagement, expense approval, loss measurement and evidence preservation.
NIST SP 800-61 Rev. 3 treats incident response as part of broader cybersecurity risk management. That is a helpful model: insurance supports financial resilience, while governance, protection, detection, response and recovery still require internal ownership.
Renewal checklist
- Reassess systems, data, revenue dependencies and loss scenarios.
- Review acquisitions, new markets, major vendors and material incidents.
- Revalidate application answers with control owners.
- Compare policy wording, not just limits and price.
- Resolve unexplained exclusions, warranties and sublimits.
- Update incident contacts and panel-provider rules.
- Exercise notification and claims evidence.
- Track remediation promises made during underwriting.
This guide intentionally does not publish generic premium ranges, claimed discount percentages or breach-cost averages: they do not establish what a particular organisation will pay or recover.
Sources and review
This guide was substantively reviewed on 8 August 2026. Insurance availability and policy interpretation are jurisdiction- and wording-specific; obtain advice from appropriately licensed insurance and legal professionals.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.