First-party and third-party coverage
A cyber policy has two halves that answer different questions: what the incident costs you, and what you owe others.
First-party coverage — your own losses:
- Incident response and forensics. The specialist firm that determines what happened and what data was touched. Usually the first and most immediately useful benefit.
- Notification costs. Legally required notice to affected individuals, plus call centre and credit monitoring.
- Business interruption. Lost income while systems are down, subject to a waiting period measured in hours.
- Data restoration. Rebuilding corrupted or destroyed data and systems.
- Cyber extortion. Ransomware negotiation, and ransom payment where lawful.
- Reputational harm and crisis communications.
Third-party coverage — liability to others: privacy liability for exposing personal data, network security liability where your systems harmed someone else's, regulatory defense and fines where insurable, PCI-DSS assessments and fines from card networks, and media liability for content-related claims.
Not covered, generally: loss of your own intellectual property value, upgrading systems beyond their pre-loss state ("betterment"), physical damage to hardware from a cyber event unless specifically added, and — critically — social engineering fraud, which usually requires a separate endorsement or a crime policy.
What a breach actually costs
IBM's Cost of a Data Breach Report 2025 provides the most widely cited benchmark. It found the average cost of a data breach for U.S. companies rose 9% to an all-time high of $10.22 million, while the global average fell 9% to $4.44 million — the first global decline in five years.
The U.S. figure is roughly 2.3 times the global average, and the U.S. has led the world in breach costs for fifteen consecutive years. IBM attributes the U.S. gap primarily to higher regulatory penalties and to detection and escalation costs.
Two cautions on using these numbers. They are drawn heavily from larger organisations, so they overstate the typical small-business breach substantially. And they are averages across a highly skewed distribution — most incidents cost far less than the mean, while a small number cost vastly more.
For a small business, the realistic exposure is better framed as: forensics and legal counsel measured in tens of thousands, notification costs scaling with the number of records, days or weeks of lost operations, and the possibility of a regulatory inquiry. Any of those alone can exceed an annual cyber premium by an order of magnitude.
The controls questionnaire is the real gate
After the ransomware losses of 2020–2022, insurers repriced and retightened. Cyber underwriting now begins with a controls questionnaire, and certain answers determine whether you can buy the policy at all, not merely what you pay.
The controls insurers most consistently require or heavily credit:
- Multi-factor authentication on email, remote access, VPN and privileged accounts. This is effectively mandatory across the market.
- Offline, immutable or segregated backups, with documented and tested restoration.
- Endpoint detection and response across the estate.
- A patch management process with defined timelines for critical vulnerabilities.
- Email filtering and security awareness training, including phishing simulation.
- Privileged access management and removal of local administrator rights.
- An incident response plan that has actually been exercised.
- Network segmentation, particularly separating backups and critical systems.
Answer this questionnaire accurately. Material misstatements about controls are a rescission risk, and a claim denied for misrepresentation is worse than no policy at all — you paid the premium and carry the loss.
Policy terms that decide whether it pays
Claims-made, with a retroactive date. Cyber is written claims-made. Preserve your retro date across renewals and carrier changes, and never allow a gap.
Waiting period for business interruption. Commonly 6 to 12 hours. An outage shorter than the waiting period produces no payment, and the waiting period is a bigger practical lever than the deductible for most businesses.
Panel provider requirements. Most policies require you to use the insurer's approved forensics, legal and PR firms, or to obtain consent before engaging your own. Calling your usual lawyer first can jeopardise reimbursement. Keep the insurer's incident hotline where your team can find it at 3am.
Dependent business interruption. Covers outages at a vendor you rely on — your cloud host, your payment processor, your managed service provider. Given how concentrated modern dependencies are, this is one of the more valuable extensions and is often sublimited or absent by default.
Sublimits. Ransomware, social engineering, regulatory fines and dependent business interruption frequently carry sublimits well below the policy aggregate. The headline limit is rarely the limit that applies to your actual loss.
War and state-sponsored attack exclusions. Wordings have tightened considerably. Read how the policy defines and attributes state-backed activity, since attribution disputes are the emerging battleground in cyber claims.
Who needs it
Any business that stores personal data, takes card payments, depends on systems for daily operations, holds health or financial information, or has contractual obligations requiring it. In practice, that is nearly every business.
The regulatory backdrop makes it harder to avoid. All fifty states have data breach notification laws with their own definitions and deadlines, several states now have comprehensive consumer privacy statutes, HIPAA governs protected health information, and the FTC pursues unfair and deceptive practices claims over inadequate data security. A multi-state breach can trigger dozens of separate notification obligations simultaneously — which is itself a reason the legal and notification coverage matters more than the ransomware headline.
Frequently asked questions
Sources
Every figure above is drawn from the following publications. Links open on the publisher's own site.
- IBM — Cost of a Data Breach Report 2025
- FTC — Data breach response: a guide for business
- CISA — Cyber Essentials
- NIST — Cybersecurity Framework