Why businesses buy cyber insurance
Cyber incidents affect companies of every size. IBM's Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million and the U.S. average at $11.5 million. The FBI's Internet Crime Complaint Center reported more than $20 billion in losses from complaints filed in 2025, with business email compromise alone accounting for about $3 billion. General liability and property policies typically exclude or sharply limit cyber losses, which is why stand-alone cyber insurance has become a core business coverage.
First-party coverage
- Incident response: breach counsel, forensic investigators and public relations
- Notification and credit monitoring for affected individuals
- Data restoration and system recovery
- Business interruption: lost income and extra expense when systems go down, sometimes including outages at cloud and IT providers (dependent business interruption)
- Cyber extortion: ransomware negotiation and, where lawful, payment
- Social engineering and funds transfer fraud, often with a sublimit
Third-party coverage
Liability sections cover claims that you failed to protect personal or confidential data, transmitted malware or caused a network outage for others; regulatory defense and, where insurable by law, fines; payment card industry assessments; and media liability for content on your website and social media.
Common exclusions
Read exclusions for war and state-backed attacks, failure of power or internet infrastructure, prior known incidents, intentional acts by senior management, bodily injury and property damage, the cost of upgrading systems, and loss of future profits or intellectual property value. Ransomware cover may be subject to coinsurance or lower sublimits, and payments to sanctioned parties are prohibited.
Cyber insurance also overlaps with other lines. Technology companies usually need technology errors and omissions coverage for failures of their products and services, often combined with cyber in one form. Theft of money by employees or outsiders may fall under a commercial crime policy rather than cyber. Small businesses can sometimes add a limited cyber endorsement to a business owners policy, but stand-alone policies generally offer higher limits, broader triggers and access to an incident response team.
What drives the price
Underwriters focus on security controls: multi-factor authentication, endpoint detection and response, offline backups, patching, email filtering, employee training and incident response plans. They also review industry, revenue, volume and type of records held, reliance on technology and vendors, and claims history. Without key controls, coverage may be declined. Our cyber insurance calculator gives an indicative figure.
How to choose and how claims work
| Question | Why it matters |
|---|---|
| Is there a 24/7 breach hotline and panel of vendors? | Fast response limits damage and cost. |
| What is the waiting period for business interruption? | Losses during the first hours may not be paid. |
| Can you use your own lawyers and forensic firm? | Some policies require pre-approved vendors. |
| Are sublimits adequate? | Ransomware and fraud sublimits may be far below the main limit. |
If you suspect an incident, call the insurer's hotline before engaging vendors or paying anyone, preserve logs and evidence, and follow counsel's instructions on notifications.
U.S. and international rules
All 50 states have data breach notification laws with different definitions, deadlines and regulator notices, and public companies face SEC disclosure rules for material cyber incidents. Firms handling data of people in other countries may be subject to laws such as the EU General Data Protection Regulation, and the insurability of regulatory fines varies by country. Multinationals often place local admitted cyber policies under a global program. Polis Re helps you compare insurers and request quotes.