Small business owners considering the purchase of cyber insurance should know some basic concepts before approaching an insurance broker.  For example, it is important to understand beforehand that standard insurance does not necessarily cover the expenses incurred as a result of a cybersecurity incident.

By way of example:

  • There is no other available coverage for post-breach expenses such as forensics.
  • Coverage for data and other non-physical perils is routinely excluded under Property policies.
  • Ransomware payments are not covered.
  • The “intentional acts” exclusion found in the standard Errors & Omissions policy might eliminate coverage if the breach was caused by an insider.
  • Coverage may be unavailable for acts that are outside the provision of professional services.
  • Liability arising out of the destruction of electronic data is not typically covered under the standard General Liability or Property policies.
  • Direct losses caused by vendors may not be covered under crime policies.
  • Crime policies generally only cover theft of money, securities or other tangible property – not information theft or the destruction of electronic data.

Those insurers who provide cyber coverage directly in their standard policies do so for the right price – which makes a skilled broker a valuable asset when evaluating that pricing.  One key attribute of any cyber insurance should be the technical vendors and legal counsel associated with these carriers.  Because they typically have years of experience handling these incidents and can be rapidly deployed to address most any situation, just having this seasoned access at no cost other than the erosion of a limit oftentimes standing alone justifies buying the coverage.   When it comes to cyber insurance, having some coverage in place – no matter how low a limit or thin a policy, is almost always better than having nothing in place given the old adage:  “It’s not a matter of if, it’s a matter of when.”