DLC Tech Solutions - IT Support for Small Business
    Back to Blog

    Cyber Insurance: What It Covers, What It Doesn't, and Why It's Not a Substitute for Security

    Cyber insurance is a legitimate way to manage risk, but it is not a replacement for security. Here is what good policies cover, what they exclude, and how underwriting has shifted.

    25 April 20268 min read

    Cyber insurance has grown significantly as a market over the last five years, and with good reason, the financial exposure from a serious cyber incident is real, and insurance is a legitimate way to manage risk. But there is a version of cyber insurance buying that creates a false sense of security, and it is worth being honest about that.

    What a Good Cyber Insurance Policy Typically Covers

    • Incident response costs. The immediate cost of getting expert help when something goes wrong. This is genuinely valuable, good IR support is expensive and you want it fast.
    • Business interruption. Revenue loss if a cyber incident takes your systems offline. Limits and waiting periods vary significantly between policies.
    • Data breach costs. Notification costs, legal advice, credit monitoring for affected individuals, regulatory defence.
    • Ransomware. Some policies cover ransom payments, though this is a contested area. More usefully, good policies cover response and recovery costs even if you do not pay.
    • Cyber crime / financial fraud. Covers losses from things like BEC fraud. Read this section carefully, the exclusions matter.

    What It Typically Doesn't Cover

    • Pre-existing vulnerabilities. If you had an unpatched known vulnerability and it was exploited, some insurers will push back on claims.
    • Poor security hygiene. Insurers are increasingly asking about controls at the point of underwriting, MFA, patching practices, backups. Misrepresenting your position has consequences.
    • Reputational damage. The financial cost of clients leaving after a breach is not typically covered.
    • Infrastructure improvements. Getting covered for replacing compromised systems is one thing. Funding the upgrade you should have done before is another.

    The Underwriting Shift

    Five years ago, you could get cyber insurance without demonstrating much about your security posture. That has changed. Insurers have paid significant claims and adjusted accordingly.

    Today, underwriters ask about:

    If you are buying a policy without these things in place, you may either get declined, face significant exclusions, or pay considerably more.

    Getting your security basics right does not just reduce your risk. It makes you insurable at a reasonable premium.

    A Framework for Thinking About It

    Insurance and security are not alternatives, they are complements. Security reduces the likelihood and severity of an incident. Insurance provides a financial backstop when something does happen.

    The businesses we see that are best positioned are the ones that have done both, invested in sensible baseline security (Cyber Essentials, MFA, tested backups, staff training) and then bought insurance that is appropriate to their risk and their operations.

    If you have got insurance but have not addressed the basics, you might find the policy does not cover what you assumed. If you have addressed the basics but have not got insurance, one bad incident can still create financial exposure that good security alone cannot fully protect against.

    What to Look For in a Policy

    • Limits that match your actual exposure, think about what a serious incident would actually cost you
    • First-party costs (your own costs) and third-party cover (claims from others)
    • Access to a good incident response team, not just payment, but support
    • And read the exclusions. They are where a lot of the useful detail is.

    Want help getting your security posture insurance ready? Get in touch.

    Stay informed

    Get expert cyber security insights delivered to your inbox.

    Stay Updated

    Subscribe to receive the latest insights on cyber security, compliance, and data protection.