Cyber Insurance: What It Actually Covers (and the Exclusions That Catch Businesses Out)

29/08/2026 11:23 PM
Cyber Insurance: What It Actually Covers (and the Exclusions That Catch Businesses Out)

Cyber Insurance: What It Actually Covers (and the Exclusions That Catch Businesses Out)

Cyber insurance has moved from optional extra to genuine necessity for most businesses handling customer data or relying on digital systems to operate. But policies vary significantly in scope, and several common exclusions catch businesses out precisely when a claim actually matters most.

What a Typical Policy Covers

Most cyber insurance policies address a combination of:

  • First-party costs — your own business's direct costs from an incident, including forensic investigation, data recovery, business interruption, and notification costs under the Notifiable Data Breaches scheme.
  • Third-party liability — claims from customers, suppliers, or other parties affected by a breach involving their data.
  • Cyber extortion — costs associated with ransomware demands, though coverage and conditions here vary considerably between insurers.
  • Regulatory costs — expenses associated with responding to a regulator investigation following a breach.

Where the Exclusions Catch Businesses Out

Failure to maintain "reasonable" security standards. Many policies include a condition that the business maintained reasonable cybersecurity practices — outdated software, unpatched systems, or absent multi-factor authentication can give an insurer grounds to deny a claim after the fact.


Acts of war or state-sponsored attacks. Following some major global ransomware incidents attributed to state actors, insurers have increasingly excluded or limited coverage for attacks attributed to nation-states — a distinction that can be genuinely difficult to establish either way after an incident.


Prior known vulnerabilities. If a vulnerability was known and not remediated before the incident, insurers can deny coverage on the basis the business failed to act on a known risk.


Social engineering and payment redirection scams. Standard cyber policies often exclude or sub-limit coverage for scams where an employee is tricked into authorising a payment — this typically requires a specific endorsement or separate crime insurance.

What to Check on Your Own Policy

  1. Confirm what security standards the policy requires you to maintain, and whether your actual practices meet them.
  2. Check whether social engineering and payment redirection scams are covered, or need a separate endorsement.
  3. Review the sub-limits for specific claim types — a large headline coverage figure can mask much smaller sub-limits for the incidents you're most likely to face.
  4. Confirm notification and reporting timeframes required under the policy, since late reporting of an incident can itself void coverage.


RBizz can connect you with insurance specialists to review your cyber coverage against your actual risk profile — get in touch before renewal.

Contact Us


RBizz Team