Data breaches have become increasingly common, and their unpredictable nature makes them difficult to manage. A strong cyber insurance policy is now a vital component of any comprehensive risk management strategy.
With the cyber insurance market expanding, choosing the right policy requires careful consideration. Before you commit, use this checklist to ensure you get the coverage your organization truly needs.
- Identify Your Specific Cyber Risks
The first step is to understand the unique risks your company faces. A bank’s primary concern is the theft of financial data, while a utility company’s biggest risk is the disruption of physical operations through a network attack. Your coverage should be tailored to your business’s specific threat profile.
- Buy Only the Coverage You Need
Insurers offer a wide variety of coverages. Focus on the essentials and decline add-ons that do not apply to your business. If an insurer is unwilling to remove an unreasonable exclusion, ask your broker to find a carrier that will provide the coverage without that limitation.
- Set Appropriate Limits and Sublimits
Choosing the right policy limits is critical. The cost of a single cyber-attack can run into millions of dollars. Work with your broker to compare potential breach costs with available liability limits, using industry benchmarking data to determine an appropriate level of coverage.
- Understand Your Existing Policies
Your current commercial and liability policies may already offer some protection against cyber risks. For instance, some financial institution bonds cover losses from fraudulent electronic fund transfers. Understanding your existing coverage helps you avoid gaps and unnecessary overlaps.
You also don’t want to rely on coverage that doesn’t fully cover all your business’s risks. A knowledgeable broker can help you identify if you need more coverage.
- Scrutinize Policy Exclusions
Coverage is often determined by the exclusions in a policy. Since cyber insurance is a newer product, policy language is not standardized. Be wary of exclusions that seem copied from other forms and do not fit. Negotiate to remove them or seek quotes from other carriers.
- Secure Retroactive Coverage
Many cyber policies only cover breaches that occur after the policy start date. Since breaches can go undetected for months, it is crucial to purchase a policy with the earliest possible retroactive date to ensure you are protected from undiscovered incidents.
- Cover Third-Party Vendor Acts
If you outsource data processing or storage, your cyber policy must provide coverage for claims arising from a vendor’s error or misconduct. Do not assume your vendors’ insurance will fully protect you.
If you have an IT company handling your data and security, ask them what kind of insurance they have in place in case their systems are compromised and inadvertently affect yours. It’s important to consider all other businesses that may handle your company’s data. With this information you can figure out what kind of policy your company needs.
- Evaluate Data Restoration Cost Coverage
A serious breach often requires significant data restoration. Many policies do not automatically cover the cost to replace, upgrade, or maintain a compromised computer system. Ensure your policy covers these expenses to return your business to its pre-breach state.
- Understand the Coverage “Trigger”
Know what event activates your policy. Some are triggered when the loss occurs, while others are triggered when a claim is made against you. Understanding this distinction is essential for providing proper notice to your insurer and filing a successful claim.
Also if you identify a trigger that is relevant to your operations but isn’t covered under your policy, you’ll need to purchase a different one.
- Consider Unencrypted Device and Regulatory Coverage
- Unencrypted Devices: Employees often use personal devices for work. If these are not encrypted, a loss of data from them may not be covered. Ensure your policy includes this protection.
- Regulatory Actions: A data breach can lead to investigations and fines from state or federal agencies. Verify that your policy provides coverage for regulatory actions and legal defense costs.
Make an Informed Decision on Cyber Insurance
Cyber insurance is a dynamic product that evolves with new threats. Being proactive in assessing your risks and carefully evaluating policies is the best way to ensure your coverage aligns with your business needs.
Cyber insurance also hasn’t been around for a long time. Since this is a newer insurance product, careful vetting of policies and insurance companies is paramount. You don’t want to roll the dice during a high-stake situation like a cyber-attack.
Don’t leave your company exposed. If you’re looking for Cyber insurance in Minnesota or Wisconsin contact ONYX Insurance Brokers today for expert guidance. We’ll find you an insurance policy that provides robust, tailored protection.



