Cyber liability insurance provides first-party and third-party coverage for losses arising from cyber incidents. First-party coverage includes data breach notification costs, forensic investigation, business interruption from system downtime, ransomware payments, data restoration, and crisis management/PR. Third-party coverage includes regulatory fines and penalties, payment card industry (PCI) assessments, media liability, and network security liability from transmission of malware to third parties.
Any organization that stores, processes, or transmits sensitive data — which today means virtually every business. Industries with heightened exposure include healthcare (HIPAA), financial services (GLBA/SOX), retail (PCI-DSS), education (FERPA), and technology companies. Companies with customer-facing applications, cloud infrastructure, or remote workforces face elevated cyber risk.
Cyber policies are typically claims-made with occurrence-based triggers for first-party coverage. They often include a breach response panel of pre-approved vendors (forensics firms, notification vendors, credit monitoring, legal counsel) that can be activated immediately upon discovery of an incident. Most cyber carriers provide pre-breach services including vulnerability scanning, employee training, and incident response planning.
Cyber limits range from $1M to $10M for mid-market companies, with retentions from $10K to $100K. Ransomware sub-limits and co-insurance provisions are increasingly common. Premium varies significantly by industry, data volume, security posture, and revenue. A mid-market company typically pays $25K-$75K annually for $5M in cyber coverage.
A mid-market healthcare practice experienced a ransomware attack that encrypted patient records and disrupted operations for 12 days. The cyber policy covered $180K in forensic investigation, $95K in notification costs for 45,000 affected patients, $340K in business interruption losses, and $75K in crisis management — totaling $690K in covered costs.