Skip to content

Cyber Insurance

Cyber insurance covers a business's losses from a cyber attack or data breach. Roughly half of what it pays for is the business's own response cost, which is why "cyber liability insurance" describes only part of the product, and the policies are deliberately not standardized.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • It has two halves. First-party coverage pays the business's own costs; third-party coverage pays claims other people bring against the business.
  • The first-party half is the one a small business is most likely to use, and it includes forensics, customer notification, legal advice on notification duties, lost income and extortion.
  • Standard property and general liability policies generally do not cover cyber risks, so this is a gap rather than a duplication.
  • The policies are highly customized, which means reading two quotes side by side is the actual work of buying it. There is no standard form to fall back on.
  • It is not the same as identity theft insurance, which is a personal product. This one is bought by the business and pays the business's costs.

Definition

Cyber insurance is coverage a business buys against the financial consequences of a cyber attack or a data breach. The Federal Trade Commission, in guidance it developed with the National Association of Insurance Commissioners, describes it as "one option that can help protect your business against losses resulting from a cyber attack", and frames the buying decision around a single question: "whether you should go with first-party coverage, third-party coverage, or both."

Several names circulate for it. The FTC and NAIC's joint guidance is titled "Cyber Insurance"; NAIC's glossary lists it as "Internet Liability Insurance/Cyber Insurance"; NAIC's small-business page calls it "cyber liability insurance"; and NAIC's consumer guidance elsewhere leads with "cybersecurity insurance", describing "cyber insurance" as the shorter name it is also known by. The regulators' own titled guidance leads with "cyber insurance", which is the name used here, and there is a substantive reason to prefer it: the product is substantially first-party, so calling it liability insurance names only half of what it does.

Advanced Explanation

First-party coverage, which is the half that pays the business's own bills. The FTC describes first-party cyber coverage as protecting "your data, including employee and customer information", and enumerates what it typically reaches:

  • "Legal counsel to determine your notification and regulatory obligations"
  • "Recovery and replacement of lost or stolen data"
  • "Customer notification and call center services"
  • "Lost income due to business interruption"
  • "Crisis management and public relations"
  • "Cyber extortion and fraud"
  • "Forensic services to investigate the breach"
  • "Fees, fines, and penalties related to the cyber incident"

Two items on that list are worth pausing on, because they are the ones businesses do not anticipate. The first is legal counsel to work out what the business is obliged to do: after a breach involving personal information, a business's notification duties depend on where the affected people live and what kind of data was taken, and establishing that is itself a professional exercise before any notice goes out. The second is customer notification and call center services, which for a business with a large customer list is a logistics operation rather than a letter.

Third-party coverage, which is the liability half. The FTC describes it as protecting the business "from liability if a third party brings claims against you", typically including "payments to consumers affected by the breach", "claims and settlement expenses relating to disputes or lawsuits", "losses related to defamation and copyright or trademark infringement", "costs for litigation and responding to regulatory inquiries", and "other settlements, damages, and judgments."

The split matters when buying, because a business's exposure is rarely balanced between the two. A business holding a large volume of customer personal data has a substantial third-party exposure. A business whose operations stop entirely when its systems are encrypted has a substantial first-party one. A business with both, which describes most businesses that take payments and run on software, needs both, and the FTC's framing of the question as "first-party coverage, third-party coverage, or both" is a prompt to decide rather than a menu.

The policies are not standardized, and that is the single most important practical fact about them. NAIC states it directly: "Most commercial property and general liability policies do not cover cyber risks, and cyber insurance policies are highly customized for clients."

The first half of that sentence explains why the coverage is needed at all: it is a gap rather than a duplication of the business's existing policies. The second half explains why buying it is harder than buying anything else on a small business's insurance schedule. A general liability policy or a commercial property policy can be compared largely on limits and deductibles, because the underlying coverage forms are broadly conventional. Two cyber policies at the same limit and the same premium can cover materially different things, and there is no standard form to fall back on when the wordings differ. So the comparison has to be done on the coverage list, and a quote that names a limit and a price without an itemized coverage list is not a quote that can be compared.

The questions the regulators themselves say to ask. The FTC's guidance lists coverages to confirm are present, and they read as a checklist because each is a real gap in some policies:

  • "Data breaches (like incidents involving theft of personal information)"
  • "Cyber attacks on your data held by vendors and other third parties" - the exposure a business has when its payroll processor or booking platform is breached rather than its own systems
  • "Cyber attacks (like breaches of your network)"
  • "Cyber attacks that occur anywhere in the world (not only in the United States)"
  • "Terrorist acts"

And three questions about the insurer rather than the coverage: whether it will "defend you in a lawsuit or regulatory investigation (look for 'duty to defend' wording)"; whether it will "provide coverage in excess of any other applicable insurance you have"; and whether it will "offer a breach hotline that's available every day of the year at all times." The last of those looks like a service detail and is not: the hours immediately after a breach is discovered are when the forensics and containment decisions get made, and a policy whose response line is closed at the weekend is a slower policy.

Where the coverage sits relative to everything else the business carries. Cyber insurance overlaps less with a business's other policies than owners expect, which is a consequence of the same fact that makes it necessary. A commercial property policy insures physical damage, and encrypted data is not physical damage. A business interruption policy in a standard property program generally pays only when the shutdown follows direct physical damage to property, which a ransomware incident is not. A general liability policy's coverage grant reaches bodily injury and property damage, and a customer's loss from having their data exposed is neither. Crime coverage, which reaches employee theft and forgery, is a different contract again, although some crime forms do reach certain kinds of computer fraud, which is a place where two of a business's policies may both respond or both decline.

The practical consequence is that a business should not assume any of its existing policies picks up part of a cyber loss, and should not assume a cyber policy picks up a loss that is really a property or crime claim. Where two policies might both apply, the FTC's question about excess coverage is the one that determines which pays first.

How to Remember

First party pays your bills. Third party pays other people's claims. Your property and general liability policies pay neither.

Used in a Sentence

“The dental practice's cyber insurance paid for the forensic investigation, the notification letters to 4,300 patients and the call center that handled their questions after its scheduling vendor was breached.”

How It Works

  1. The business inventories what it holds and what it depends on: customer and employee personal data, payment data, and the systems and vendors that would stop the business if they stopped.
  2. It decides between first-party, third-party, or both, which the FTC frames as the first question to settle with an insurance agent.
  3. It compares the itemized coverage lists, not the limits, because the policies are customized and two identically priced ones can cover different things.
  4. An incident occurs, and the business calls the insurer's breach line before doing anything that might compromise the forensic evidence.
  5. First-party coverage funds the response: forensics to establish what happened, legal advice on notification duties, notification itself, and any business interruption loss.
  6. Third-party coverage responds to what follows: consumer claims, litigation and regulatory inquiries.

A hypothetical shows how unevenly the two halves are used, which is the argument for reading the first-party list carefully. Aldergate Physio, an eight-person clinic, discovers that its appointment-scheduling vendor has been breached and that patient names, dates of birth and contact details for 4,300 patients were exposed.

Its costs, in the order they arrive:

  • Forensic investigation to establish what was taken: $18,000
  • Legal counsel to determine notification obligations across three states: $9,500
  • Notification letters and a call center for six weeks: $21,000
  • Credit monitoring offered to affected patients: $34,000
  • Four days of lost bookings while systems were unavailable: $11,000

That is $93,500, and every line of it is first-party. No patient has sued and no regulator has opened an inquiry, so the third-party half of the policy has not been touched at all.

Two observations follow. The clinic's largest single cost is the one furthest from what people picture when they think about a cyber attack, and the incident did not happen on the clinic's own systems, which is why the FTC's checklist item about "cyber attacks on your data held by vendors and other third parties" is on the list. The dollar figures are illustrative; the distribution between the two halves of the policy is the point.

Pros and Cons

Pros

  • Covers a category of loss that standard property and general liability policies generally do not reach, so it closes a gap rather than duplicating existing cover.
  • Funds the response, not just the liability. Forensics, legal advice on notification, notification itself and lost income are the costs a small business actually meets.
  • Reaches incidents at vendors as well as at the business's own systems, where the policy is written to.
  • Usually comes with access to specialist responders, which a small business has no other way to reach at the moment it needs them.
  • Buying it forces an inventory of what data the business holds and which systems it cannot operate without, which is useful independently of the policy.

Cons

  • The policies are not standardized, so comparison shopping is a reading exercise rather than a price comparison, and a business without help is poorly placed to do it.
  • Coverage lists vary enough that a gap in one policy may be a covered item in another at the same price, and nothing flags the difference.
  • Overlaps with crime coverage in places, so two policies may both respond or both decline to a computer-fraud loss depending on wordings.
  • Sub-limits are common, particularly on extortion, notification and business interruption, so the headline limit can substantially overstate what is available for the cost the business actually incurs.
  • Insurers increasingly condition coverage on specific security controls, so a business that has not implemented them may find a claim contested or a renewal declined.
  • It does not prevent anything. A policy is a funding source for a response, and the response is cheaper when there was less to respond to.

People Also Asked

Answers to the most frequently asked questions.

What is the difference between first-party and third-party cyber coverage?
First-party coverage pays the business's own costs after an incident. The FTC's list includes "legal counsel to determine your notification and regulatory obligations", "recovery and replacement of lost or stolen data", "customer notification and call center services", "lost income due to business interruption", "cyber extortion and fraud" and "forensic services to investigate the breach". Third-party coverage "generally protects you from liability if a third party brings claims against you", including payments to affected consumers, litigation costs and responses to regulatory inquiries.
Do my other business policies already cover a cyber attack?
Generally not. NAIC states that "most commercial property and general liability policies do not cover cyber risks." The structural reasons are worth knowing: a property policy insures physical damage and encrypted data is not physical damage; standard business interruption coverage usually requires direct physical damage to property to trigger; and a general liability policy's coverage grant reaches bodily injury and property damage, which a customer's data exposure is neither. Crime coverage is a separate contract that may reach some computer fraud.
Why is comparing cyber policies harder than comparing other insurance?
Because there is no standard form. NAIC notes that "cyber insurance policies are highly customized for clients", which means two policies at the same limit and premium can cover materially different things. With a general liability or commercial property policy the underlying wordings are broadly conventional, so limits and deductibles carry most of the comparison. Here the itemized coverage list is the comparison, and a quote that gives only a limit and a price cannot be compared to another one.
Is cyber insurance the same as identity theft insurance?
No. Identity theft insurance is a personal product, usually an endorsement on a homeowners or renters policy, that reimburses an individual's cost of cleaning up after their identity is stolen. Cyber insurance is bought by a business and pays the business's response costs and its liability to others. NAIC's consumer guidance draws the same line, describing cybersecurity insurance as "typically held by businesses."
What should I ask an insurer before buying?
The FTC lists what to confirm the policy includes: data breaches involving theft of personal information, "cyber attacks on your data held by vendors and other third parties", attacks on the business's own network, attacks "that occur anywhere in the world (not only in the United States)", and terrorist acts. It also lists three questions about the insurer: whether it will "defend you in a lawsuit or regulatory investigation (look for 'duty to defend' wording)", whether it will "provide coverage in excess of any other applicable insurance you have", and whether it will "offer a breach hotline that's available every day of the year at all times."

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Federal Trade Commission. "Cyber Insurance" (developed with the National Association of Insurance Commissioners).
  2. National Association of Insurance Commissioners. "Cybersecurity."
  3. National Association of Insurance Commissioners. "Small Business Owners: Property and Casualty Insurance."
  4. National Association of Insurance Commissioners. "Glossary of Insurance Terms."

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor