17.3 Covering Cyber Losses

Key Takeaways

  • Cyber exposures include data breaches, ransomware and extortion, business interruption from network outages, funds transfer fraud, and liability for privacy and security failures.

  • Standard commercial general liability and property forms generally exclude or limit cyber and data losses, so dedicated cyber coverage is needed.

  • First-party cyber coverages include breach response, data restoration, business interruption, and cyber extortion; third-party coverages include network security and privacy liability, media liability, and regulatory defense.

  • Most cyber policies are claims-made for liability sections and require insureds to use approved breach-response vendors and meet security controls such as multi-factor authentication.

  • Underwriters evaluate controls including MFA, backups, endpoint detection, patching, employee training, and incident response planning.

Last updated: September 2026

Covering Cyber Losses

Quick Answer: Cyber incidents create both first-party losses, such as breach response costs, data restoration, business interruption, and extortion payments, and third-party liability, such as lawsuits and regulatory actions over privacy or security failures. Traditional CGL and property forms generally exclude or limit these losses, so businesses buy dedicated cyber insurance. Coverage depends heavily on security controls, such as multi-factor authentication, backups, and incident response plans. Insurers use these controls in underwriting and sometimes impose them as conditions.

Why Cyber Needs Its Own Coverage

  • Electronic data is not tangible property under the ISO CGL definition of property damage, and the CGL contains exclusions for access or disclosure of confidential information and for electronic data.
  • Property forms cover physical damage and provide only small built-in limits for electronic data and interruption of computer operations.
  • Crime forms cover certain fraudulent transfers but not breach response or liability.

Cyber insurance was built to fill these gaps.

Common Cyber Coverages

CategoryCoverageWhat it pays
First-partyBreach responseForensics, legal advice, notification, call centers, credit monitoring, public relations
First-partyData restorationRestoring or recreating corrupted or destroyed data and software
First-partyBusiness interruptionLost income and extra expense from a network outage; some policies extend to dependent (vendor) systems
First-partyCyber extortionResponse costs and, where legal, ransom payments
First-partyFunds transfer / social engineeringLoss from fraudulent transfers (often sublimited)
Third-partyNetwork security and privacy liabilityDefense and damages when a breach harms others
Third-partyMedia liabilityDefamation or infringement in digital content
Third-partyRegulatory defense and penaltiesDefense of regulatory investigations and fines where insurable by law
Third-partyPCI-DSS assessmentsFines and assessments from payment card brands after a card data breach

Key Policy Features and Conditions

  • Claims-made trigger for liability sections, usually with a retroactive date and an extended reporting option
  • Incident response panels: Insureds are often required or encouraged to use approved breach coaches, forensic firms, and notification vendors
  • Waiting periods for business interruption (a set number of hours before coverage begins)
  • Sublimits for social engineering, extortion, and dependent business interruption
  • Exclusions commonly include war (with careful definitions for state-sponsored attacks), failure of core infrastructure, prior known incidents, and bodily injury or property damage
  • Conditions tied to security controls: Misrepresenting controls such as MFA on the application can jeopardize coverage

Underwriting a Cyber Risk

Underwriters focus on controls that most reduce ransomware and breach losses:

  1. Multi-factor authentication (MFA) on email, remote access, and privileged accounts
  2. Secure, tested backups kept offline or immutable
  3. Endpoint detection and response (EDR) tools
  4. Patch management for known vulnerabilities
  5. Employee training on phishing and social engineering
  6. Incident response plan, tested with tabletop exercises
  7. Vendor risk management for third parties with network access

Data volume, industry (such as health care, retail, or financial services), revenue, and past incidents also affect pricing and capacity.

"Silent Cyber"

Silent (non-affirmative) cyber refers to cyber losses that might be covered unintentionally under traditional policies that neither clearly include nor exclude them. Insurers and reinsurers have added clarifying exclusions and affirmative grants to property, liability, and other forms so that cyber exposure is priced where it is intended to be covered.

Risk Management Beyond Insurance

  • Risk control: MFA, EDR, segmentation, backups, least-privilege access, training
  • Contractual transfer: Vendor contracts that allocate breach responsibility and require vendors to carry cyber insurance
  • Retention: Deductibles or self-insured retentions sized to the insured's financial strength

Worked Scenario: Ransomware at a Distributor

A distributor's systems are encrypted. Operations stop for six days, and customer data is stolen. Under a cyber policy:

  • Breach response pays forensics, legal counsel, and notification to affected customers.
  • Business interruption pays lost income after the waiting period.
  • Data restoration pays to rebuild systems.
  • Cyber extortion responds if a payment is lawful and approved.
  • Privacy liability defends later lawsuits from customers whose data was exposed.

If the application stated MFA was in place for remote access and it was not, the insurer may contest coverage. That is why accurate applications matter.

First-Party or Third-Party? A Quick Test

SituationFirst-party or third-partyTypical coverage
Hiring a forensic firm to find how attackers enteredFirst-partyBreach response
Lost profits while systems are encryptedFirst-partyBusiness interruption (after the waiting period)
Restoring corrupted databasesFirst-partyData restoration
Customers sue for exposure of their personal dataThird-partyNetwork security and privacy liability
A state attorney general investigates the breachThird-partyRegulatory defense (penalties where insurable)
Card brands assess fines after a payment card breachThird-partyPCI-DSS assessment coverage

Common Traps

  • Assuming the CGL covers data breaches: Electronic data is not tangible property, and the CGL excludes access or disclosure of confidential information.
  • Overlooking waiting periods and sublimits: Business interruption, extortion, and social engineering often have their own terms.
  • Misstating controls on the application: Inaccurate answers about MFA or backups can jeopardize coverage.
  • Choosing vendors without consent: Many policies require using approved response vendors or getting insurer consent first.
Loading diagram...
Cyber Coverage Map
Test Your Knowledge

A retailer suffers a data breach, and customers sue for exposure of their personal information. Why is the retailer's ISO commercial general liability policy unlikely to respond?

A

The CGL policy excludes all claims by customers

B

Electronic data is not tangible property under the CGL, and the CGL contains exclusions for access or disclosure of confidential information

C

CGL policies cover only intentional acts

D

The CGL policy responds only to claims made after the policy expires

Test Your Knowledge

Which cyber coverage pays for forensic investigators, legal counsel, customer notification, and credit monitoring after a breach?

A

Media liability

B

PCI-DSS assessment coverage

C

Breach response

D

Dependent business interruption

Test Your Knowledge

Which security control do cyber underwriters most commonly treat as essential because it greatly reduces account-takeover and ransomware risk?

A

Annual financial audits

B

Increasing the general liability aggregate

C

Requiring employees to change passwords every week

D

Multi-factor authentication on email, remote access, and privileged accounts

Sections you finish are checked off in the contents.