Vehicles, tools and data · Cyber liability

Cyber insurance

Pays the costs of a data breach or cyberattack: investigation, notifying customers, restoring systems, lost income, and claims from people whose data was exposed.

Who it's for
Any business that stores customer data, takes payments, or can't operate without its computers.
Is it required?
No, but some clients and contracts require it.

Covered and not covered

Usually covered

  • Forensic investigation and legal advice after a breach
  • Notifying affected customers and credit monitoring
  • Ransomware response and restoring data
  • Lost income while systems are down
  • Lawsuits and some regulatory fines from exposed data

Usually not covered

  • Money sent to a scammer after a fake invoice or email, unless you added social engineering coverage
  • Improving your security after an attack
  • Losses from known, unfixed security problems
  • Damage to physical equipment

Real-life examples

Ransomware locks your systems for a week.

Usually covered

Pays experts to respond and restore, lost income during the outage, and in many policies, a ransom payment where lawful.

Your bookkeeper wires $40,000 to a fake supplier after a convincing email.

It depends

Only covered if you added social engineering (or funds transfer fraud) coverage, often with a low limit.

Check your own policy

Find these on your policy or declarations page, or ask your agent:

  • Social engineering coverage and its limit
  • Security requirements like multi-factor authentication
  • A 24/7 breach hotline
  • Business interruption waiting period

Not sure where to look? See how to read your policy.