# 18. Cyber Liability Insurance
Cyber insurance used to be a straightforward purchase. Pay a premium, describe your controls, collect if you're breached. The market has matured painfully and significantly since then, mostly because of repeated, expensive losses that forced insurers to get serious about what they're actually covering.
Context: The cyber insurance market has gone through a turbulent evolution:
- Pre-2020: Broadly available, underwriting was light-touch (questionnaires that few insurers verified), premiums were relatively low, coverage was broad.
- 2020-2022: Ransomware losses exploded. Colonial Pipeline, JBS, Kaseya, REvil's attacks on hundreds of organizations. Insurers paid enormous claims and realized they'd underwritten systemic risk, one ransomware campaign could hit hundreds of their customers simultaneously. Premiums jumped 50-200% year-over-year. Underwriting got serious. Exclusions multiplied.
- 2022-2024: Market stabilized as insurers got more rigorous in underwriting (requiring MFA, EDR, backup verification), premiums plateaued for organizations with strong controls, and coverage became more explicitly scoped.
- Current reality (2026): Cyber insurance is available, but the days of light-touch underwriting are over. The controls you have materially affect your premium and your coverage. The policy exclusions are consequential and not always obvious. And the "act of war" exclusion debate, Lloyd's exclusion attempts post-NotPetya attribution, has not been fully resolved in case law.
This topic is structured differently from the others. Instead of purely vendor questions, it combines questions to ask your broker, questions to ask the underwriter/insurer, and questions to ask yourself about whether your program is insurable and at what cost.
The core question for cyber insurance: "Do I understand what I'm actually covered for, what the specific exclusions mean in practice, and what I need to demonstrate to get the coverage my risk profile requires?"
14 Questions to Ask Your Broker, Insurer, and Yourself
1. "What controls will the underwriter require, and which ones will move my premium most significantly if I don't have them?"
Why: Underwriting requirements have converged around a set of controls that insurers consider table stakes. Knowing these before the application process lets you invest where it matters for insurability, not just security. The high-premium drivers are almost universally: MFA on remote access and email, EDR deployment, tested backups, and incident response planning.
Good answer (from broker): A current underwriting requirements matrix with premium impact quantified per control gap. Red flag: Vague guidance that doesn't map controls to specific premium impact.
2. "Walk me through every exclusion in this policy, what it means in plain language and what scenarios it would apply to."
Why: Policy exclusions are where cyber coverage gets complicated. Common ones: "act of war" (triggered by nation-state attribution, legally contested), "unencrypted data" (denies claims for data not encrypted at rest), "prior known conditions" (any vulnerability disclosed before policy inception), "infrastructure failure" (cloud provider outages), "bodily injury" (physical consequences of cyber events, relevant for OT). Insurers write exclusions in deliberately ambiguous language. Know what they mean before you're relying on them.
Good answer: Broker walks through each exclusion with plain-language explanation and real-world examples of when it would apply. Red flag: "The exclusions are standard" without specific explanation.
3. "What is and isn't covered under ransomware, payment, negotiation fees, data recovery, business interruption, regulatory fines, and customer notification?"
Why: Ransomware coverage is almost never all-or-nothing. Different components have different sublimits, different waiting periods, and different conditions. The ransom payment itself may be covered (with conditions including OFAC compliance checks). The IR firm's fees, forensics, notification costs, and business interruption losses are often covered separately with different limits.
Good answer: Specific line-item coverage for each ransomware cost component, sublimits, conditions, and waiting periods (business interruption often has a 6-72 hour waiting period before coverage kicks in). Red flag: "We cover ransomware" without breaking down the components.
4. "What sublimits should I be aware of, coverage categories that have a lower limit than the overall policy?"
Why: A $5M cyber policy with a $250K sublimit on regulatory fines provides near-zero protection if your actual exposure is GDPR or CCPA penalties. Sublimits on social engineering, wire fraud, and first-party losses are commonly much lower than the headline policy limit. Always compare sublimits against your actual risk profile.
Good answer: Complete sublimit schedule mapped against your estimated exposure by category. Red flag: Presenting the headline policy limit without discussing sublimits.
5. "What does the 'act of war' exclusion mean in practice, and how does attribution affect coverage for incidents involving suspected nation-state actors?"
Why: Post-NotPetya, Lloyd's and others attempted to deny claims by attributing the attack to Russia and invoking war exclusions. The legal outcome was mixed. Most policies now have modified war exclusions that require "official government attribution", but what counts, and how fast that attribution comes, matters enormously. If you're in a sector that attracts nation-state attention (critical infrastructure, defense, financial services), this exclusion needs specific discussion.
Good answer: Explicit policy language quoted and explained, broker's view on current case law, alternative coverage options for nation-state scenarios. Red flag: "Don't worry about that, it's a rare scenario."
6. "How does the insurer verify the controls I'm claiming on my application, and what happens if they find a discrepancy at claim time?"
Why: Cyber insurance fraud and misrepresentation claims are growing. Insurers are increasingly including rights to audit controls as part of policy conditions, and some are denying claims where the claimed controls weren't actually in place at time of loss. If you claim MFA is deployed enterprise-wide and the breach happens through an account without MFA, that's a material misrepresentation issue.
Good answer: Clear insurer verification methodology, what they audit pre-binding vs. post-claim, good-faith standards for discrepancies between claimed and actual controls. Red flag: "The questionnaire is self-attested" (fine now, but what happens at claim time?).
7. "Who does the insurer use for incident response, and can I use my own IR firm if I have a preferred one?"
Why: Most cyber policies include IR services as a benefit, the insurer has panel IR firms they work with. But panel IR firms may not be the best fit for your environment, sector, or incident type. Some policies allow you to use your own IR firm; others require you to use panel firms as a condition of coverage. Knowing this before an incident is critical, switching IR firms mid-incident is not the right time to discover this constraint.
Good answer: Named panel firms, explicit policy language on using non-panel firms, quality of panel firms reviewed independently. Red flag: "You must use our panel firms" without the ability to understand their quality in advance.
8. "What's the claims process, who do I call first, what happens in what order, and what are the documentation requirements I need to preserve from the moment of discovery?"
Why: Cyber claims can be complicated by procedural failures that have nothing to do with the merits of the claim. Failing to notify in time, failing to preserve evidence, making changes to affected systems before forensics are complete, making public statements before involving legal counsel, all can affect claim outcomes. Know the process before you need it.
Good answer: Written claims process document, immediate notification requirements (hours, not days), legal counsel involvement from the start, evidence preservation guidance. Red flag: "Call us when something happens" without a documented procedure.
9. "What's covered under social engineering and wire fraud, specifically BEC losses where an employee was deceived into transferring money?"
Why: Business Email Compromise (BEC) losses are enormous, the FBI reports tens of billions annually. But BEC coverage under cyber policies varies hugely. Some policies cover authorized push payments (where an employee intended to send the money but was deceived). Many don't, treating it as a "voluntary transfer" by the insured. Crime coverage vs. cyber coverage becomes a coverage gap argument insurers love to have.
Good answer: Explicit BEC/social engineering coverage scope, "authorized push payment" language, coordination with crime policy if separate. Red flag: "We cover social engineering" without specifying authorized push payment treatment.
10. "How does this cyber policy interact with my other policies, D&O, E&O, crime, property, general liability? Where are the gaps and overlaps?"
Why: Cyber losses often trigger multiple policy types simultaneously. A ransomware attack that causes business interruption may trigger cyber, property, and business interruption policies. A data breach may trigger cyber and D&O. Regulators are increasingly aware that coverage gaps between policies are where organizations find themselves uninsured after a loss. Your broker should map the interactions.
Good answer: Cross-policy interaction analysis, gap identification, recommendations on coverage alignment. Red flag: Each policy sold and managed separately with no holistic view.
11. "What would disqualify a claim after an incident, what conditions, reporting failures, or coverage exclusions could result in denial?"
Why: Understanding the specific ways a claim could be denied, before you have one, changes how you document controls, manage incidents, and structure communications. Pre-claim denial analysis is a legitimate broker service that most organizations never request.
Good answer: Specific denial scenarios mapped to policy language, documentation practices that preserve coverage, legal counsel guidance on communications. Red flag: "Claims are rarely denied for valid incidents" (technically true; the word "valid" is doing a lot of work).
12. "How do I structure my security program to maximize insurability and minimize premium, and which control investments have the best insurance ROI?"
Why: This is the question most CISOs should be asking their brokers and rarely do. Insurance brokers have visibility into underwriting requirements across the market. A good broker can tell you: "Adding phishing-resistant MFA would reduce your premium by X and improve your insurability tier." This maps security investments to financial outcomes.
Good answer: Specific control-to-premium mapping, current underwriting trends, investment recommendations with estimated premium impact. Red flag: "We'll help you find the best coverage at renewal" without proactive guidance between renewals.
13. "What's the insurer's financial strength, rating, claims-paying history, and exposure to systemic cyber events?"
Why: Cyber insurance is only valuable if the insurer can actually pay claims. In a systemic event (a major vulnerability that simultaneously affects thousands of policyholders across many insurers), insurer concentration risk matters. Insurers are also acquiring reinsurance capacity that limits their exposure, and limits what they can pay, in catastrophic scenarios.
Good answer: AM Best or equivalent rating, reinsurance structure transparency, claims-paying history, historical response to systemic events. Red flag: Coverage from an insurer with a weak balance sheet, concentrated in cyber, with limited reinsurance.
14. "What does renewal look like, how far in advance do we start, what documentation will be required, and what might change about my coverage?"
Why: Cyber insurance renewals have been chaotic as the market evolves. Underwriters want updated evidence of controls, sometimes want to inspect environments, and sometimes change terms significantly based on market conditions rather than your individual risk profile. Starting 90-120 days ahead, with documentation ready, avoids last-minute coverage gaps.
Good answer: Clear renewal timeline, documentation checklist, early warning on potential coverage changes based on market trends. Red flag: Renewal initiated 30 days before expiry (insufficient time to find alternatives if terms worsen).
The Meta-Test
- Q2, Q3, Q4, and Q5 are the coverage reality test. What sounds like comprehensive coverage often has exclusions and sublimits that make it dramatically narrower than the headline suggests. Know what you're actually buying.
- Q6 and Q11 are the claims risk test. Understanding how claims could be denied, before you file one, is the most important pre-incident work your broker can do for you.
- Q12 is the ROI test. Insurance is both a risk transfer mechanism and a lens on which security controls matter most. Use it as both.
Honest Observations
1. Cyber insurance is not a substitute for security controls, it's a residual risk transfer tool.
This seems obvious, but the way some organizations budget for cyber insurance suggests otherwise. The right framing: invest in controls that reduce the probability and severity of incidents; buy insurance to cover the residual risk that good controls don't eliminate.
Buying cyber insurance instead of making security improvements is a losing strategy, underwriters are increasingly sophisticated enough to identify this pattern, and premiums will reflect it. Buying insurance alongside a mature security program transfers the tail risk at significantly better rates.
2. The controls that move insurance premiums most are not always the controls with the highest security ROI.
Underwriters have a model for what reduces their loss exposure. It doesn't perfectly match the model for what reduces your security risk. MFA on remote access dramatically moves insurance premiums because it reduces ransomware frequency. EDR moves premiums because it reduces ransomware severity and dwell time. Backup maturity moves premiums because it reduces ransom payment probability.
Advanced threat hunting, red team exercises, zero trust architecture, these improve your security posture but move insurance premiums less because they're harder for underwriters to verify and model.
The insight: maintain both lenses. Know which investments are security-optimal and which are insurance-optimal. They overlap significantly but not completely.
3. The broker relationship matters more than most organizations realize.
The best cyber insurance brokers do three things most don't: they help you understand your actual coverage before a claim, they advocate for you during a claim dispute, and they provide pre-renewal guidance that shapes your security investment priorities.
An order-taking broker who processes your renewal and files your certificates adds limited value. A strategic broker who brings underwriting intelligence, cross-client benchmarking, and proactive coverage gap analysis is worth a meaningful premium above commodity broker rates.
Interview brokers as rigorously as you interview security vendors.
4. The "act of war" exclusion is unresolved and the risk is real.
The NotPetya litigation produced mixed results. Merck won a favorable ruling against its property insurer. Other cases went differently. The legal framework for what constitutes an "act of war" in the cyber context, and how attribution to nation-state actors triggers or doesn't trigger exclusions, is genuinely unsettled.
If you operate in a sector with significant nation-state threat exposure (energy, financial services, healthcare, critical infrastructure, defense contractors), the war exclusion deserves specific legal counsel review of your policy language. "Standard" language across carriers varies materially.
5. For "regular" mid-market companies, the most impactful pre-renewal actions:
- Verify MFA is deployed enterprise-wide, including remote access, email, admin accounts. This is the single largest premium driver and the most commonly misrepresented control in applications.
- Document your backup and recovery capability, immutable backups, tested recovery, verified RTO/RPO. Underwriters increasingly ask for evidence, not just attestation.
- Get an IR retainer in place, having a named IR firm on retainer (even a small one) demonstrates operational maturity and is increasingly an underwriting preference.
- Review your sublimits, compare your ransomware, BEC, and regulatory fine sublimits against your estimated exposure in each category. Gaps should drive coverage changes at renewal.
- Read the exclusions, actually read them, with your broker, before you renew. It takes two hours and could save a claim denial.