17.3 Covering Cyber Losses
Key Takeaways
Cyber exposures include data breaches, ransomware and extortion, business interruption from network outages, funds transfer fraud, and liability for privacy and security failures.
Standard commercial general liability and property forms generally exclude or limit cyber and data losses, so dedicated cyber coverage is needed.
First-party cyber coverages include breach response, data restoration, business interruption, and cyber extortion; third-party coverages include network security and privacy liability, media liability, and regulatory defense.
Most cyber policies are claims-made for liability sections and require insureds to use approved breach-response vendors and meet security controls such as multi-factor authentication.
Underwriters evaluate controls including MFA, backups, endpoint detection, patching, employee training, and incident response planning.
Covering Cyber Losses
Quick Answer: Cyber incidents create both first-party losses, such as breach response costs, data restoration, business interruption, and extortion payments, and third-party liability, such as lawsuits and regulatory actions over privacy or security failures. Traditional CGL and property forms generally exclude or limit these losses, so businesses buy dedicated cyber insurance. Coverage depends heavily on security controls, such as multi-factor authentication, backups, and incident response plans. Insurers use these controls in underwriting and sometimes impose them as conditions.
Why Cyber Needs Its Own Coverage
- Electronic data is not tangible property under the ISO CGL definition of property damage, and the CGL contains exclusions for access or disclosure of confidential information and for electronic data.
- Property forms cover physical damage and provide only small built-in limits for electronic data and interruption of computer operations.
- Crime forms cover certain fraudulent transfers but not breach response or liability.
Cyber insurance was built to fill these gaps.
Common Cyber Coverages
| Category | Coverage | What it pays |
|---|---|---|
| First-party | Breach response | Forensics, legal advice, notification, call centers, credit monitoring, public relations |
| First-party | Data restoration | Restoring or recreating corrupted or destroyed data and software |
| First-party | Business interruption | Lost income and extra expense from a network outage; some policies extend to dependent (vendor) systems |
| First-party | Cyber extortion | Response costs and, where legal, ransom payments |
| First-party | Funds transfer / social engineering | Loss from fraudulent transfers (often sublimited) |
| Third-party | Network security and privacy liability | Defense and damages when a breach harms others |
| Third-party | Media liability | Defamation or infringement in digital content |
| Third-party | Regulatory defense and penalties | Defense of regulatory investigations and fines where insurable by law |
| Third-party | PCI-DSS assessments | Fines and assessments from payment card brands after a card data breach |
Key Policy Features and Conditions
- Claims-made trigger for liability sections, usually with a retroactive date and an extended reporting option
- Incident response panels: Insureds are often required or encouraged to use approved breach coaches, forensic firms, and notification vendors
- Waiting periods for business interruption (a set number of hours before coverage begins)
- Sublimits for social engineering, extortion, and dependent business interruption
- Exclusions commonly include war (with careful definitions for state-sponsored attacks), failure of core infrastructure, prior known incidents, and bodily injury or property damage
- Conditions tied to security controls: Misrepresenting controls such as MFA on the application can jeopardize coverage
Underwriting a Cyber Risk
Underwriters focus on controls that most reduce ransomware and breach losses:
- Multi-factor authentication (MFA) on email, remote access, and privileged accounts
- Secure, tested backups kept offline or immutable
- Endpoint detection and response (EDR) tools
- Patch management for known vulnerabilities
- Employee training on phishing and social engineering
- Incident response plan, tested with tabletop exercises
- Vendor risk management for third parties with network access
Data volume, industry (such as health care, retail, or financial services), revenue, and past incidents also affect pricing and capacity.
"Silent Cyber"
Silent (non-affirmative) cyber refers to cyber losses that might be covered unintentionally under traditional policies that neither clearly include nor exclude them. Insurers and reinsurers have added clarifying exclusions and affirmative grants to property, liability, and other forms so that cyber exposure is priced where it is intended to be covered.
Risk Management Beyond Insurance
- Risk control: MFA, EDR, segmentation, backups, least-privilege access, training
- Contractual transfer: Vendor contracts that allocate breach responsibility and require vendors to carry cyber insurance
- Retention: Deductibles or self-insured retentions sized to the insured's financial strength
Worked Scenario: Ransomware at a Distributor
A distributor's systems are encrypted. Operations stop for six days, and customer data is stolen. Under a cyber policy:
- Breach response pays forensics, legal counsel, and notification to affected customers.
- Business interruption pays lost income after the waiting period.
- Data restoration pays to rebuild systems.
- Cyber extortion responds if a payment is lawful and approved.
- Privacy liability defends later lawsuits from customers whose data was exposed.
If the application stated MFA was in place for remote access and it was not, the insurer may contest coverage. That is why accurate applications matter.
First-Party or Third-Party? A Quick Test
| Situation | First-party or third-party | Typical coverage |
|---|---|---|
| Hiring a forensic firm to find how attackers entered | First-party | Breach response |
| Lost profits while systems are encrypted | First-party | Business interruption (after the waiting period) |
| Restoring corrupted databases | First-party | Data restoration |
| Customers sue for exposure of their personal data | Third-party | Network security and privacy liability |
| A state attorney general investigates the breach | Third-party | Regulatory defense (penalties where insurable) |
| Card brands assess fines after a payment card breach | Third-party | PCI-DSS assessment coverage |
Common Traps
- Assuming the CGL covers data breaches: Electronic data is not tangible property, and the CGL excludes access or disclosure of confidential information.
- Overlooking waiting periods and sublimits: Business interruption, extortion, and social engineering often have their own terms.
- Misstating controls on the application: Inaccurate answers about MFA or backups can jeopardize coverage.
- Choosing vendors without consent: Many policies require using approved response vendors or getting insurer consent first.
A retailer suffers a data breach, and customers sue for exposure of their personal information. Why is the retailer's ISO commercial general liability policy unlikely to respond?
The CGL policy excludes all claims by customers
Electronic data is not tangible property under the CGL, and the CGL contains exclusions for access or disclosure of confidential information
CGL policies cover only intentional acts
The CGL policy responds only to claims made after the policy expires
Which cyber coverage pays for forensic investigators, legal counsel, customer notification, and credit monitoring after a breach?
Media liability
PCI-DSS assessment coverage
Breach response
Dependent business interruption
Which security control do cyber underwriters most commonly treat as essential because it greatly reduces account-takeover and ransomware risk?
Annual financial audits
Increasing the general liability aggregate
Requiring employees to change passwords every week
Multi-factor authentication on email, remote access, and privileged accounts
Sections you finish are checked off in the contents.