Skip to content

Risk & Insurance

Cyber insurance: what it covers, and what it won't

16 July 2026 · Syprical

Cyber insurance has gone from niche to normal. More businesses are buying it, more clients and contracts are asking whether you have it, and more insurers are getting specific about what they’ll cover. Like any insurance, the value is in the detail, so it’s worth understanding what you’re actually buying before you need it.

What a policy typically covers

Cyber policies usually split into two halves:

  • First-party (losses to your business): incident response and forensics, data recovery, business interruption while you’re down, extortion and ransom handling, and notification costs if personal data is exposed.
  • Third-party (claims against you): legal costs and liability if a breach harms your customers or partners, and regulatory defence.

A good policy also comes with a response panel: pre-vetted incident responders, lawyers, and PR you can call the moment something goes wrong. For many small businesses, that access is worth as much as the payout, because it means you’re not scrambling to find help mid-crisis.

What it often won’t cover

This is where businesses get caught out. Common exclusions and gaps:

  • Poor security hygiene. If you claimed to have controls (like MFA or backups) that weren’t actually in place, insurers can reduce or deny a claim.
  • Known, unpatched vulnerabilities you were warned about and ignored.
  • Insider or fraudulent acts by your own people, depending on the policy.
  • Loss of future revenue or reputation beyond the defined business-interruption terms.
  • Fines that are legally uninsurable in your jurisdiction.

The pattern is clear: insurance is a backstop for bad luck, not a substitute for basic security. Treating it as “we don’t need to bother securing things, we’re insured” is exactly the mindset that gets claims denied.

Insurers now expect you to do the basics

Underwriting has tightened. Increasingly, to get covered (or to get a reasonable premium) you’ll be asked to have controls in place, commonly including:

  • Multi-factor authentication, especially on email and remote access.
  • Tested, isolated backups.
  • Endpoint protection and timely patching.
  • Security awareness for staff.

If that list looks familiar, it’s because it overlaps heavily with the ACSC Essential Eight. In other words, the work that makes you harder to breach is also the work that makes you insurable and cheaper to insure.

How to approach it

  1. Do the basics first. Get MFA, backups, and patching in order. It lowers both your risk and your premium.
  2. Answer the application honestly. Overstating your controls can void the policy when you need it most.
  3. Read the response terms. Who do you call, and how fast can they act?
  4. Match cover to your real exposure. How long could you survive offline, and what would a data breach actually cost you?

Cyber insurance is a sensible layer for most businesses, but it works best sitting on top of genuine security, not instead of it.


Not sure whether your security would stand up to an insurer’s questions, or a real incident? We can get your fundamentals in order and help you answer the application with confidence. Get in touch.

Want help putting this into practice?

Book a free, no-obligation consult and we'll talk through your situation.

Get in touch