Many organizations buy cyber insurance expecting that, if an attack happens, the policy will cover the damage. Then an incident occurs, and they discover that the policy pays far less than they assumed, or not at all for certain costs. The surprise is rarely about the existence of coverage. It is about the exclusions, sublimits and conditions buried in the policy language.
This article describes common areas where policyholders are surprised. It is general information, not insurance or legal advice. Policies vary widely, so review yours with your broker and counsel.
A policy may advertise a headline limit, such as a seven-figure amount. Within that limit, individual categories of loss may be capped at much lower amounts, and certain events may not be covered at all. The headline number tells you the maximum, not what you will actually recover.
A sublimit is a cap on a specific type of loss within the overall policy. Commonly sublimited items include:
Ransomware or extortion payments and response costs, sometimes with a lower limit or a coinsurance share the policyholder must pay
Business interruption, including limits on how long lost income is covered and a waiting period before coverage begins
Regulatory fines and penalties, often covered only where insurable by law
Social engineering and funds transfer fraud, where an employee is tricked into sending money, frequently with a low sublimit
Notification and credit monitoring costs, which may be limited by number of people or dollar amount
Ask your broker for a list of every sublimit and compare each to a realistic estimate of what that type of loss could cost you.
Some policies exclude or reduce coverage if the insured did not maintain the security measures described in the application, such as multi-factor authentication or regular patching. If your application said MFA was enforced everywhere and it was not, the insurer may dispute the claim.
Many policies include exclusions for acts of war or attacks attributed to nation-states. The wording varies and has been the subject of disputes. Read the language closely and ask how attribution is determined.
Outages of power, internet or cloud providers outside your control may not be covered, or may be limited to dependent business interruption coverage if you have it.
Events that began or were known before the policy start date, or the retroactive date, may be excluded.
Some policies limit coverage if lost devices or data were not encrypted.
Insurers may not pay to upgrade your systems beyond their previous condition. If rebuilding after an attack requires stronger equipment, the difference may be your cost.
Cyber policies often exclude physical harm. In care settings, consider how a technology failure that affects resident safety would be treated, and discuss it with your broker and your general or professional liability carriers.
Notice requirements. You may need to notify the insurer within a short window of discovering an incident, sometimes within days.
Consent before action. Many policies require approval before you hire response firms, negotiate with attackers or make payments.
Panel vendors. Insurers may require you to use their approved incident response and legal firms.
Cooperation duties. You must preserve evidence and provide documentation.
Accuracy of the application. Misstatements, even honest ones, can be grounds for denial.
What are all sublimits and retentions, and how do they apply to a ransomware event?
How long is the waiting period for business interruption, and how is lost income calculated?
Does coverage include dependent business interruption from vendors and cloud providers?
Are regulatory fines covered, and under what conditions?
What security controls does the application assume, and what happens if one lapses?
Do we need insurer approval before engaging a response firm?
Is there coverage for social engineering fraud, and at what limit?
How are acts of war defined?
Insurance applications ask detailed questions about your security practices. Have your IT provider review answers before you sign. Overstating your controls to secure a better rate can backfire when a claim is filed.
Keep a printed copy of your policy and the claims hotline where you can find it if systems are down. Include the insurer in your incident response plan, and run a tabletop exercise that includes calling them.
UnityCare IT helps organizations verify that the controls promised on an insurance application are actually in place and documented. That alignment protects both your security and your coverage.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172