Most firms read their cyber insurance application carefully, because the questions are pointed. Fewer read the policy itself with the same care. That is a risk, because the policy's definitions, sublimits and conditions determine what happens after an incident, and they can surprise people at the worst possible moment.
Policies vary widely between carriers, so treat this as a list of things to look for, not a description of any one policy. Your broker or coverage counsel is the right person to interpret your specific terms.
Start With What Is Covered
Cyber policies usually describe two broad categories.
First-party coverage
This addresses your own costs after an incident. Common items include forensic investigation, data restoration, business interruption, ransom negotiation, notification costs and public relations help. Check whether each is included, and at what limit.
Third-party coverage
This addresses claims others bring against you, such as clients or regulators alleging that your handling of their information caused harm. Look at how defense costs are treated and whether they erode the limit.
Sublimits: The Fine Print Inside the Limit
A policy may advertise a large overall limit while capping specific events at much lower amounts. Ask your broker to list every sublimit in plain terms. Pay particular attention to:
- Social engineering or funds-transfer fraud, which is especially relevant to wire-fraud attempts against firms.
- Ransomware or extortion events.
- Regulatory defense and penalties.
- Business interruption, including waiting periods before coverage begins.
- Dependent business interruption, such as an outage at a cloud vendor you rely on.
Exclusions Worth Understanding
Exclusions describe what the policy will not cover. Read them slowly. Ask about wording related to:
- Failure to maintain security standards. Some policies condition coverage on controls described in the application, such as multi-factor authentication.
- Unencrypted devices. Some carriers treat lost, unencrypted laptops differently.
- War or state-backed activity. Language here varies, and its application to attacks is debated, so ask how it is worded.
- Prior known incidents. Anything you knew about before the policy began may be excluded.
- Contractual liability. Promises made to clients in agreements may not be covered.
- Voluntary payments. Paying a ransom or incurring costs without carrier approval may jeopardize reimbursement.
Conditions and Notice Requirements
Conditions are duties you must meet. They often include prompt notice of an incident, cooperation with the carrier, and use of the carrier's approved vendors for forensics or legal help. Many policies include a hotline to call. Put that number in your incident response plan and on a card in the managing partner's wallet. Calling your regular IT provider first, or hiring your own forensic firm, may create problems if the policy requires pre-approved vendors.
Make the Application and Policy Match Reality
Representations in the application can affect coverage. If you state that multi-factor authentication is enforced everywhere and an exception exists, the answer was inaccurate. Before you sign, have your IT provider verify each technical answer. Keep a copy of the application and the supporting evidence.
Questions to Ask Your Broker
- What are all the sublimits, and which apply to wire fraud?
- How long is the waiting period before business interruption coverage starts?
- Do defense costs reduce the limit?
- Are we required to use specific vendors after an incident?
- Which security controls are conditions of coverage?
- How does the policy interact with our professional liability policy? Gaps and overlaps are common.
- What would we need to show at renewal to keep terms stable?
Coordinate With Other Coverage
Professional liability, crime and general liability policies may each address parts of a cyber event, sometimes with exclusions that point at one another. Review them together, ideally with a broker experienced with law firms.
How Counsel Cyber Helps
Counsel Cyber is not an insurance broker and does not give coverage advice, but we help firms verify the technical controls their policies assume and document them for applications and renewals. If you are preparing for a renewal, we can help you gather accurate evidence.