First-party coverage, which is the half that pays the business's own bills. The FTC describes first-party cyber coverage as protecting "your data, including employee and customer information", and enumerates what it typically reaches:
- "Legal counsel to determine your notification and regulatory obligations"
- "Recovery and replacement of lost or stolen data"
- "Customer notification and call center services"
- "Lost income due to business interruption"
- "Crisis management and public relations"
- "Cyber extortion and fraud"
- "Forensic services to investigate the breach"
- "Fees, fines, and penalties related to the cyber incident"
Two items on that list are worth pausing on, because they are the ones businesses do not anticipate. The first is legal counsel to work out what the business is obliged to do: after a breach involving personal information, a business's notification duties depend on where the affected people live and what kind of data was taken, and establishing that is itself a professional exercise before any notice goes out. The second is customer notification and call center services, which for a business with a large customer list is a logistics operation rather than a letter.
Third-party coverage, which is the liability half. The FTC describes it as protecting the business "from liability if a third party brings claims against you", typically including "payments to consumers affected by the breach", "claims and settlement expenses relating to disputes or lawsuits", "losses related to defamation and copyright or trademark infringement", "costs for litigation and responding to regulatory inquiries", and "other settlements, damages, and judgments."
The split matters when buying, because a business's exposure is rarely balanced between the two. A business holding a large volume of customer personal data has a substantial third-party exposure. A business whose operations stop entirely when its systems are encrypted has a substantial first-party one. A business with both, which describes most businesses that take payments and run on software, needs both, and the FTC's framing of the question as "first-party coverage, third-party coverage, or both" is a prompt to decide rather than a menu.
The policies are not standardized, and that is the single most important practical fact about them. NAIC states it directly: "Most commercial property and general liability policies do not cover cyber risks, and cyber insurance policies are highly customized for clients."
The first half of that sentence explains why the coverage is needed at all: it is a gap rather than a duplication of the business's existing policies. The second half explains why buying it is harder than buying anything else on a small business's insurance schedule. A general liability policy or a commercial property policy can be compared largely on limits and deductibles, because the underlying coverage forms are broadly conventional. Two cyber policies at the same limit and the same premium can cover materially different things, and there is no standard form to fall back on when the wordings differ. So the comparison has to be done on the coverage list, and a quote that names a limit and a price without an itemized coverage list is not a quote that can be compared.
The questions the regulators themselves say to ask. The FTC's guidance lists coverages to confirm are present, and they read as a checklist because each is a real gap in some policies:
- "Data breaches (like incidents involving theft of personal information)"
- "Cyber attacks on your data held by vendors and other third parties" - the exposure a business has when its payroll processor or booking platform is breached rather than its own systems
- "Cyber attacks (like breaches of your network)"
- "Cyber attacks that occur anywhere in the world (not only in the United States)"
- "Terrorist acts"
And three questions about the insurer rather than the coverage: whether it will "defend you in a lawsuit or regulatory investigation (look for 'duty to defend' wording)"; whether it will "provide coverage in excess of any other applicable insurance you have"; and whether it will "offer a breach hotline that's available every day of the year at all times." The last of those looks like a service detail and is not: the hours immediately after a breach is discovered are when the forensics and containment decisions get made, and a policy whose response line is closed at the weekend is a slower policy.
Where the coverage sits relative to everything else the business carries. Cyber insurance overlaps less with a business's other policies than owners expect, which is a consequence of the same fact that makes it necessary. A commercial property policy insures physical damage, and encrypted data is not physical damage. A business interruption policy in a standard property program generally pays only when the shutdown follows direct physical damage to property, which a ransomware incident is not. A general liability policy's coverage grant reaches bodily injury and property damage, and a customer's loss from having their data exposed is neither. Crime coverage, which reaches employee theft and forgery, is a different contract again, although some crime forms do reach certain kinds of computer fraud, which is a place where two of a business's policies may both respond or both decline.
The practical consequence is that a business should not assume any of its existing policies picks up part of a cyber loss, and should not assume a cyber policy picks up a loss that is really a property or crime claim. Where two policies might both apply, the FTC's question about excess coverage is the one that determines which pays first.