Cyber security insurance – all you need to know

Find out what cyber security insurance is, what a standard policy typically covers (and doesn’t!), and what you should do about insuring your organisation against cyber attacks. 

We all know by now that cyber attacks are a serious threat and we need to be putting measures in place to protect our systems and data. The financial impact of a breach can be huge – and for many, hard to come back from. That’s why cyber security insurance seems to make a lot of sense…

But what is cyber security insurance and what does a typical policy cover?

Most cyber security insurance providers generally cover the immediate costs of falling victim to a cyber attack. However, certain policies will differ depending on the insurer. Security failures, system forensics, data recovery and legal protection are typically all covered by cyber security insurers, as is making financial reparations to customers affected by the incident. 

Ransomware is a common form of malicious software that’s designed to block a user from accessing their systems or data until a sum of money is paid. After an attack like this, standard procedure from your insurance provider would be to underwrite and accept liability for data recovery and forensics. This can help cover the cost of employing professionals to investigate what exactly happened, and how to prevent it happening again.

Some companies actually agree to pay the ransom demanded by the attacker – however, this is something law enforcement advises against. This is because it may be encouraging similar cyber attacks in the future through rewarding the attacker.

BEC (Business Email Compromise) phishing scams are another common form of cyber attack. Some insurance policies will cover money lost in BEC fraud, however it may not always be covered by standard cyber security insurance providers. 

Essentially, organisations should always check they know exactly what they’re signing up for and what would be covered in the event of a cyber attack. The NCSC (National Cyber Security Centre) also recommends checking if your organisation already has some form of cyber insurance as part of an existing policy, such as property insurance.

So what doesn’t cyber security insurance cover?

Reputational damage is a big issue when it comes to cyber attacks, as when clients or potential clients are made aware that a company has had a security breach or attack, they will be less likely to continue or initiate business with said company. However, cyber security insurance providers cannot cover the costs of reputational damage, no matter how significant it may be.

Even if the organisation loses all of its clients, the insurer is not liable to cover the costs. This point relates to the fact that cyber insurance is not the be-all-and-end-all in cyber security. While it is really useful in many cases, it isn’t something that should be used to replace actual cyber security measures.

Think of it like your home insurance: you wouldn’t leave the windows and doors open and unlocked all day when you’re out, just because you have insurance. In fact, if your insurer found out you had left all your windows and doors unlocked, they wouldn’t pay out. The NCSC recommends having fundamental cyber security safeguards in place, such as those certified by Cyber Essentials or Cyber Essentials Plus (see our guide here), which are the cyber security equivalent of ensuring your doors and windows are locked – and they come with cyber security insurance as standard (terms and conditions apply). For organisations managing cyber-related risks to public safety, the Cyber Assessment Framework should be consulted.

In fact, if you’re looking for cyber insurance, the existing measures you have in place to protect your business’ systems and data will have a huge impact on the cost – and may even dictate whether or not you can get insurance at all. This is because no insurer will be looking to cover a business that has no security measures in place. To get cyber insurance, your company’s level of security will be assessed, and typically reassessed every 12 months to make sure the security is being maintained. 

How is cyber security insurance changing, and where might it be going?

Claiming on your insurance is obviously useful if your organisation it hit with a cyber attack. However, it’s a lot more about tackling a symptom rather than addressing the actual issue. And this is a common problem among all forms of insurance.

The whole industry is therefore having to move more towards finding a way to prevent the initial problem and therefore avoid paying out. For example, car insurance companies now rely on black boxes as a way to encourage changes in their customers’ behaviour and calculate the approximate risk of them making a claim.

Similarly to this, cyber security companies are moving the focus more towards the prevention of cyber crime through encouraging clients to have better cyber security. Insurers ultimately want to avoid having to pay out, so having clients who are already fairly well-protected is in their best interest.

Rising excesses

Going forward, cyber security insurers will be increasingly working with clients to insure their cyber security, and educate them on how to avoid breaches. The terms and conditions will also likely become more strict and specified in the future, giving rise to more opportunities for the insurer to avoid a pay-out. The excess will also rise, meaning that even though you have coverage, the insurance provider will only cover a part of the costs, leaving the rest to you.

In fact, this is already starting to happen, because the insurance companies are aware cyber crime is becoming more prevalent as we increasingly depend on technology, and frequent pay-outs to cover the consequences aren’t going to help anyone, or be good for business. Therefore, they’re looking for more ways to avoid them and focus more on cyber attack prevention.

How much does it cost? And if my cyber security is good enough, do I even need it?

According to a recent survey conducted by the government, only 32% of businesses reported being insured against cyber risks, and in 2019, 46% of businesses suffered from a cyber security breach or attack.

Cyber insurance can cost from a few pounds a month depending on the size of your organisation, the level of cover you’re after, the amount of excess you’re willing to pay, and the measures you already have in place.

Obviously these costs can add up, especially for small companies, so it may be tempting to depend  on anti-virus software and other forms of prevention instead. However, according to the NCSC, the average cost of a cyber security breach that resulted in a loss of data or assets is £8,460. Security measures are growing increasingly advanced and sophisticated, but no matter the level of defence, no business can be confident that it’s totally protected from cyber attacks. Small businesses may not see these threats as relevant to them, but as larger corporations become more protected and harder to infiltrate, smaller organisations are finding themselves being targeted more frequently.

So, what should I do?

Cyber security insurance is a sensible measure as part of an overall risk mitigation strategy. However, it should never be used to justify inadequate steps to reduce the likelihood of being the victim of cyber crime in the first place. It should, instead, be a last resort for when you have done all you can reasonably be expected to have done, but still the criminals found a way through.

If you already have measures in place to manage your security and think cyber security insurance is the next best step for you, here are some of the highest rated cyber security insurance providers of 2021 you may like to check out:

However, if you haven’t already got some form of cyber security in place, it’s probably pointless trying to get insured right now. If you want to get an idea of how your organisation’s cyber security is currently, you can find out more with a cyber security audit, and get advice on the best next steps for you to take.