Cyber insurance covers the costs a business faces after a cyber attack or data breach: investigating and containing the incident, restoring systems and data, notifying affected people, defending regulatory action, and the liability to others. With the UK GDPR allowing fines of up to 17.5 million pounds or 4% of worldwide annual turnover for the most serious breaches, and personal data breaches reportable to the ICO within 72 hours, the exposure for even a small business is substantial.
Cyber risk is now a mainstream commercial exposure rather than a niche one. Almost every business holds personal data and depends on IT systems, and a ransomware attack or data breach can bring trading to a halt and trigger legal duties within days.
What does cyber insurance cover?
Cover usually splits into first-party losses, the costs to your own business, and third-party liability, what you owe others. First-party cover includes incident response and forensics, data and system restoration, cyber extortion and ransomware costs, and business interruption from the outage. Third-party cover includes defending and settling claims from customers whose data was exposed, and the costs of regulatory investigations.
How does cyber insurance relate to the UK GDPR and the ICO?
The Information Commissioner’s Office (ICO) regulates data protection in the UK. A personal data breach that meets the risk threshold must be reported to the ICO within 72 hours of the business becoming aware of it. The ICO can impose fines up to a higher maximum of 17.5 million pounds or 4% of worldwide annual turnover, whichever is greater, with a standard maximum of 8.7 million pounds or 2% for lesser breaches. Cyber policies typically help with the cost of managing the breach and defending regulatory action, though fines themselves may not be insurable.
Does cyber insurance cover ransomware?
Most cyber policies respond to ransomware, covering the incident response, system restoration and business interruption, and in some cases the ransom itself, subject to conditions and legal limits. Insurers increasingly require minimum security controls, such as multi-factor authentication and tested backups, as a condition of cover, so the state of your defences affects both price and availability.
Who needs cyber insurance?
Any business that holds personal data, takes payments, or relies on IT to trade, which is almost all of them. The size of the business is not the point: smaller firms are frequently targeted precisely because their defences are weaker, and they are least able to absorb the cost of an incident unaided.
Getting the cover right
Cyber wordings and the security conditions attached to them vary widely, and the right cover depends on your data, systems and how you trade. A broker can match the policy to your exposure and help you meet the controls insurers now expect. To review cyber cover, get a quote or speak to the team.
