Insurance for digital risks: what to ask your insurer

What cyber and professional insurance typically covers and excludes for a small business, and the questions to ask before relying on a policy.

3 minread 723words last updated

The short answer

Digital risks are covered, where they are covered at all, by a combination of policies rather than one. Cyber insurance addresses incidents: breaches, ransomware, outages and business interruption, liability to customers for their data, and often the cost of responding. Professional indemnity addresses the work you deliver to others, if you build or advise. General liability addresses the rest and rarely reaches digital incidents. Each policy has conditions, and insurers increasingly require baseline controls, two-factor, tested backups, patching, as conditions of cover, so a claim can be reduced or refused if they lapsed. Insurance transfers financial risk; it does not restore systems or reputation. The controls come first, and the policy backs them. Speak to a broker for your situation; the questions below are what to bring.

What typically sits where

RiskTypical policyTypical conditions and exclusions to check
Data breach: notification, legal, credit monitoring, liabilityCyberControls in place; notification duties; sub-limits
Ransomware and extortionCyberBackups; multi-factor; payment restrictions and legal limits
Business interruption from an outage or attackCyberWaiting periods; proof of loss; whether third-party outages count
Incident response costs: forensics, communicationsCyberUse of approved responders; prompt notification
Payment fraud, invoice redirectionCyber or crime policyOften limited; verification procedures required
Errors in work delivered to clientsProfessional indemnityScope of services; contractual liability caps
Regulatory finesVaries and is limited by law in many placesCheck what is insurable in your jurisdiction
Reputation and lost customersLargely uninsurablePrevention and response are the only cover

Questions for your broker or insurer

  1. Which of our policies responds to a data breach, a ransomware incident, an outage and an invoice fraud, and how?
  2. What are the conditions of cover, and which controls must we evidence?
  3. What is excluded: third-party platform outages, unpatched systems, social engineering, acts by staff?
  4. What are the notification duties: how quickly, to whom, and what happens if we respond ourselves first?
  5. What does the policy provide during an incident: hotline, responders, legal, communications?
  6. What are the limits and sub-limits per risk, and are they adequate for our data and revenue?
  7. How does the policy interact with our suppliers’ liability and our contracts with clients?

Insurance and controls together

The controls that insurers require are the same ones that prevent the ordinary incidents: two-factor, tested backups kept separately, prompt patching, email authentication, staff awareness, an incident plan. Having them reduces both the likelihood of a claim and the chance of a claim being reduced. Insurance then covers the residual: the incident that happens despite the controls, with its forensics, legal costs and liabilities. Neither replaces the other.

What this means for you

Ask your broker which policies respond to which digital risks, what the conditions and exclusions are, what you must notify and when, and what the insurer provides in an incident. Run the required controls for real, because they prevent incidents and they decide whether claims are paid. Then treat insurance as the backstop for the residual risk, not as the plan.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Does our general business insurance cover a hacked website or a data breach?

Usually not, or only narrowly. Cyber incidents, data breaches, ransomware, business interruption from an outage and liability to customers for their data are typically addressed by cyber insurance, which is a separate policy with its own conditions. Ask your broker directly what your current policies cover for a breach scenario, in writing.

What conditions do cyber insurers impose?

Increasingly, evidence of baseline security: multi-factor authentication on email and remote access, tested backups kept separately, patching within defined times, endpoint protection, staff training, an incident plan. Applications ask about them and claims can be affected if the answers were inaccurate or the controls lapsed. Treat the questionnaire as a checklist of what you must actually have.

What does the insurer provide during an incident?

Many policies include an incident response service: a hotline, forensic investigators, legal advice on notification, communications support, sometimes negotiators. Knowing the number and the conditions before an incident is part of the incident plan. Using your own responders without informing the insurer can affect the claim.