Insurance for digital risks: what to ask your insurer
What cyber and professional insurance typically covers and excludes for a small business, and the questions to ask before relying on a policy.
The short answer
Digital risks are covered, where they are covered at all, by a combination of policies rather than one. Cyber insurance addresses incidents: breaches, ransomware, outages and business interruption, liability to customers for their data, and often the cost of responding. Professional indemnity addresses the work you deliver to others, if you build or advise. General liability addresses the rest and rarely reaches digital incidents. Each policy has conditions, and insurers increasingly require baseline controls, two-factor, tested backups, patching, as conditions of cover, so a claim can be reduced or refused if they lapsed. Insurance transfers financial risk; it does not restore systems or reputation. The controls come first, and the policy backs them. Speak to a broker for your situation; the questions below are what to bring.
What typically sits where
| Risk | Typical policy | Typical conditions and exclusions to check |
|---|---|---|
| Data breach: notification, legal, credit monitoring, liability | Cyber | Controls in place; notification duties; sub-limits |
| Ransomware and extortion | Cyber | Backups; multi-factor; payment restrictions and legal limits |
| Business interruption from an outage or attack | Cyber | Waiting periods; proof of loss; whether third-party outages count |
| Incident response costs: forensics, communications | Cyber | Use of approved responders; prompt notification |
| Payment fraud, invoice redirection | Cyber or crime policy | Often limited; verification procedures required |
| Errors in work delivered to clients | Professional indemnity | Scope of services; contractual liability caps |
| Regulatory fines | Varies and is limited by law in many places | Check what is insurable in your jurisdiction |
| Reputation and lost customers | Largely uninsurable | Prevention and response are the only cover |
Questions for your broker or insurer
- Which of our policies responds to a data breach, a ransomware incident, an outage and an invoice fraud, and how?
- What are the conditions of cover, and which controls must we evidence?
- What is excluded: third-party platform outages, unpatched systems, social engineering, acts by staff?
- What are the notification duties: how quickly, to whom, and what happens if we respond ourselves first?
- What does the policy provide during an incident: hotline, responders, legal, communications?
- What are the limits and sub-limits per risk, and are they adequate for our data and revenue?
- How does the policy interact with our suppliers’ liability and our contracts with clients?
Insurance and controls together
The controls that insurers require are the same ones that prevent the ordinary incidents: two-factor, tested backups kept separately, prompt patching, email authentication, staff awareness, an incident plan. Having them reduces both the likelihood of a claim and the chance of a claim being reduced. Insurance then covers the residual: the incident that happens despite the controls, with its forensics, legal costs and liabilities. Neither replaces the other.
What this means for you
Ask your broker which policies respond to which digital risks, what the conditions and exclusions are, what you must notify and when, and what the insurer provides in an incident. Run the required controls for real, because they prevent incidents and they decide whether claims are paid. Then treat insurance as the backstop for the residual risk, not as the plan.
Frequently asked questions
Does our general business insurance cover a hacked website or a data breach?
Usually not, or only narrowly. Cyber incidents, data breaches, ransomware, business interruption from an outage and liability to customers for their data are typically addressed by cyber insurance, which is a separate policy with its own conditions. Ask your broker directly what your current policies cover for a breach scenario, in writing.
What conditions do cyber insurers impose?
Increasingly, evidence of baseline security: multi-factor authentication on email and remote access, tested backups kept separately, patching within defined times, endpoint protection, staff training, an incident plan. Applications ask about them and claims can be affected if the answers were inaccurate or the controls lapsed. Treat the questionnaire as a checklist of what you must actually have.
What does the insurer provide during an incident?
Many policies include an incident response service: a hotline, forensic investigators, legal advice on notification, communications support, sometimes negotiators. Knowing the number and the conditions before an incident is part of the incident plan. Using your own responders without informing the insurer can affect the claim.