Cyber Liability

What Does Cyber Liability Insurance Cover? First-Party, Third-Party, and Where the Gaps Hide

Cyber liability insurance has moved from an exotic add-on to a core management liability line in about a decade, yet it remains the policy business owners understand least. Part of the confusion is structural: a cyber policy is really two policies stitched together. First-party coverage pays your own costs after an incident. Third-party coverage defends you when someone else — a customer, a partner, a regulator — comes after you because of one. Understanding the two sides, and the sublimits and exclusions that live inside each, is the difference between buying real protection and buying a logo for your vendor questionnaires.

The First-Party Side: Your Own Losses

When your systems are compromised, first-party coverage typically funds the response: forensic investigators to determine what happened, legal counsel to steer the response under privilege, notification to affected individuals, credit monitoring, call-center support, and public relations help. It also generally covers restoring data and systems, business interruption income lost while systems are down, and in many policies cyber extortion — ransomware negotiation and, where legally permitted, payment. These response costs arrive fast and grow fast, which is why breach-response access is often the most valuable feature for smaller firms.

The Third-Party Side: Claims Against You

Third-party coverage responds to lawsuits and demands from people whose data you held, businesses whose systems were infected through yours, and banks recovering card-reissuance costs. It typically also addresses regulatory investigations and, subject to insurability rules, fines and penalties under privacy laws. Media liability — claims over website content, defamation, or copyright — is often folded in. For a company that holds customer or employee data of any volume, the third-party side is where the catastrophic numbers live.

The Sublimits That Shrink the Headline Number

A policy advertising a seven-figure limit may cap ransomware at a fraction of it, cap social-engineering fraud lower still, and apply separate retentions per coverage part. Business interruption usually carries a waiting period measured in hours before coverage begins. Read the schedule of sublimits the way you would read the limits themselves — after an incident, the sublimit is the limit.

Social Engineering and Funds Transfer Fraud

The most common cyber loss for small businesses is not a breach at all — it is an employee tricked into wiring money or changing payment instructions. Coverage for this sits awkwardly between cyber and crime policies, and many cyber forms cover it only by endorsement, at a modest sublimit, sometimes with a callback-verification condition attached. If your business pays vendors electronically, confirm exactly where this coverage lives, how much of it you have, and what verification procedures the policy requires you to follow for it to pay.

What Cyber Policies Generally Don't Cover

Common exclusions include bodily injury and property damage (those belong to other lines), prior known incidents, unencrypted portable devices in some forms, contractual penalties beyond what law would impose, and infrastructure failures like widespread internet or utility outages. War exclusions have tightened industry-wide, and their application to state-sponsored attacks is an active area of dispute. Improving your systems after an incident — betterment — is typically your cost, not the insurer's.

What Underwriters Now Require

Cyber underwriting hardened considerably in recent years. Expect questions — sometimes scans — about multi-factor authentication on email and remote access, endpoint detection, tested and segregated backups, patching cadence, and employee training. Weak answers no longer just raise price; they can mean declined applications or coverage carve-backs. The controls underwriters demand are the same ones that prevent incidents, so the application process doubles as a roadmap.

Sizing and Placing the Coverage

Limits should reflect the records you hold, your revenue's dependence on systems, and the contracts you've signed — many client and vendor agreements now specify minimum cyber limits. An independent agent who works the cyber market can compare forms that differ far more than GL policies do, check the sublimits that matter for your operation, and coordinate cyber with your crime and management liability lines so the wire-fraud claim doesn't fall between them. If your cyber policy renewed unchanged for a few years, the market has moved — it's worth a fresh look.

Want this reviewed for your business?

Submit once and we'll bring back up to 10 carrier quotes, with the coverage differences explained in plain English. No obligation.

Get Up to 10 Quotes

General information only. Coverage is governed by the terms of the policy actually issued. This article is not legal advice.