The transfer was authorised by your own staff. That is why the cyber policy may not pay.
Cyber insurance is written for an attack on your systems. A great deal of what actually costs businesses money is not an attack on the systems at all. It is somebody being convincingly asked to do something, and doing it.
Start a quote file Read the short answer firstTricked is not the same as hacked.
Downtime cover starts after a waiting period.
Better than before is generally on you.
What will a cyber insurance policy not pay for?
The common gaps are money sent away by a member of your own staff who was deceived, the cost of improving your systems beyond what they were before the incident, the first hours of downtime that fall inside the waiting period, and losses that flow from a supplier’s outage rather than your own. None of these are unusual events. They are the ordinary shape of a bad week, which is why it is worth knowing before you buy which of them your wording actually answers.
Cyber wordings vary more than almost any other commercial policy, because the product is young and every insurer has written its own. Two policies with the same limit and a similar premium can answer completely different events. Comparing them on price alone is close to meaningless.
Insurers separate an attack on your systems from a deception of your people. A criminal who breaks in, encrypts your files and demands payment is attacking the system. A criminal who emails your bookkeeper from what looks like a supplier’s address, with a plausible reason for a change of bank details, is deceiving a person, and your own staff member then makes the payment willingly. The money is just as gone. But the first is core cyber cover and the second usually sits under a separate insuring agreement called social engineering or fraudulent instruction, often with a much smaller limit and its own conditions about verifying requests by telephone.
Four things to check before you compare two quotes.
Social engineering and fraudulent instruction
Whether it is included at all, what the sub-limit is, and what the policy requires you to have done before paying. Many wordings require a call-back to a previously known number for any change of banking details, and a claim where nobody made that call is a hard one. Put the call-back into your payment process, not just into the policy.
The waiting period on downtime
Business interruption inside a cyber policy usually starts after a stated number of hours rather than immediately. Two policies with identical limits can behave completely differently on an outage that lasts a day. Compare the waiting periods and be honest about how long your business can be down before it hurts.
Betterment and system improvement
The policy restores what you had. If the fix involves moving to a better platform, adding controls you did not have, or replacing hardware that was already at end of life, that improvement is generally your cost. It is a reasonable position and it surprises people, because the incident is usually what finally forces the upgrade.
Your supplier’s outage
When the failure is at a cloud provider, a payment processor or a managed service you depend on, your own systems are fine and you still cannot trade. Some policies extend to dependent business interruption and some do not, and those that do often name the providers or set conditions. Know which of your suppliers your business genuinely cannot function without, then check whether they are covered.
Three incidents that were nothing like the headlines.
The invoice with new bank details
A long-standing supplier’s email account was compromised, and the invoice came from their real address with their real formatting. Accounts paid it. Nothing on the buyer’s network was breached at all, so the core cyber sections never engaged. Whether anything is recovered depends entirely on whether a fraudulent instruction section was bought and what its limit was.
The outage that lasted a shift
Systems were restored the same day, which sounds like a good outcome and was. The interruption fell inside the waiting period, so the lost trading was not covered. The response costs, the forensic work and the legal advice were, and on a short incident those are usually the larger figure anyway. Knowing which parts respond changes how you plan.
The notification nobody budgeted for
The technical incident was small. The obligation to work out whose information was affected, to assess the risk of harm to those people, and to notify them was not. Response costs, legal advice and a breach coach are the sections that carry that work, and they are the sections small businesses are most tempted to trim on price.
The ones that decide which quote you should take.
Does the policy pay a ransom?
Many wordings include an extortion section that can cover a payment and the negotiation around it, subject to conditions and to the law. Whether paying is the right decision is a separate question entirely, and it is one made with the insurer’s incident response team rather than alone. The more useful cover on most files is the restoration and downtime, not the ransom.
Our data is all with a cloud provider. Are we still exposed?
Yes. Using a provider moves where the data sits, not who is responsible for it. Your obligations to the people whose information it is do not transfer with the hosting, and the provider’s own agreement usually limits what they owe you. This is the single most common reason a business concludes it does not need cover and is wrong.
We already have crime cover. Is that the same thing?
Not quite, and the overlap is where arguments happen. Crime policies traditionally answer theft by employees and certain kinds of fraud, cyber policies answer attacks on systems, and deception of a staff member falls awkwardly between the two. Having both without checking how they fit can still leave the gap. Send both wordings and they can be read against each other.
What do insurers want to see before they will quote?
Multi-factor authentication on email and remote access, offline or otherwise separated backups that have been tested, some form of endpoint protection, and a payment process with verification for changes to bank details. These have moved from nice to have to close to mandatory, and having them in place changes both the price and whether cover is available at all.
Is a small business really a target?
Most incidents are not targeted at anyone in particular. They are automated, they find whatever is exposed, and a small firm with a compromised email account is a perfectly good route to somebody else’s money. Being small changes the size of the loss, not the odds of it.
Not the question you had? Send the wording you are being offered through the quote file and you will get a written answer on what it does and does not do, not a sales call.
Compare the wordings, not the premiums.
Send any quote you are holding. You will get a written note on the sub-limits, the waiting period and the sections that actually decide a claim.