Here, we provide a guide for those looking to protect their business from the very real and prevalent cyber risks of today’s digital world, outlining some of the key things to consider when arranging a cyber insurance policy.
So, what is cyber insurance?
Cyber insurance covers the costs and liabilities arising from cyber attacks, data breaches, and other cyber incidents. It can help your business recover from the financial and reputational damage caused by threats such as ransomware, phishing, denial-of-service attacks, and hacking.
Cyber insurance can cover various expenses and losses, such as:
- Data restoration and recovery
- Business interruption and loss of income
- Legal fees and regulatory fines (where legally insurable)
- Customer notification and credit monitoring
- Public relations and crisis management
- Extortion payments and cyber ransom
- Third-party liability and litigation
All policies vary in the cover they provide and the levels of indemnity they offer within those covers. As such, it is important to ensure that you are covered for the areas you need, depending on your attitude to these risks, your business operations, existing IT security and more.
Speaking to an insurance broker who understands the differences between policies and covers will help you navigate this complex area, providing you with the information needed to make an informed decision about your protection.
As with any insurance policy, cyber insurance is not a substitute for cyber security measures, such as firewalls, antivirus software, encryption, and backups; you wouldn’t leave your windows and doors open just because you have home insurance in place, for example. Similarly, cyber insurance should be a complementary tool to help mitigate the residual risks that cannot be eliminated. To understand more about the importance of specialist support in the aftermath of a cyber-attack, read our previous blog here.
Why do you need cyber insurance?
Cyber insurance is not yet a legal requirement in the UK, but it is becoming increasingly important for businesses of all sizes and sectors.
According to the Cyber Security Breaches Survey 2024*, 50% of businesses and around 32% of charities reported having experienced some kind of cyber security breach or attack in the prior 12 months, evidencing the prevalence of cyber crime. When focussing just on higher turnover businesses and charities, it’s reported this prevalence increases further, to 70% for medium businesses, 74% for large businesses and 66% for charities with £500,000 or higher annual income.
Cyber attacks are not only prevalent, as we have seen, but can have devastating consequences for businesses, such as:
- Loss of data and intellectual property – from your client’s personal or financial data, designs, or recipes for products you manufacture or any other kind of vital information that is used to run your business operations. Read our case study here about a haulage firm who fell victim to a cyber-attack due to the leak of their financial information to a fraudster.
- Damage to your reputation and customer trust – naturally, the need to inform customers or suppliers of a breach or cyber incident could have a negative impact on your reputation and may result in a loss of those customers and/or suppliers.
- Disruption to operations and services – if systems are down or data is lost, your business may struggle to operate at its usual pace or capacity, leading to a drop in revenue. Read the case study of how a car parts dealer’s business was severely affected by a ransomware attack here.
- Legal claims and regulatory penalties – you could face claims from various parties if their data is compromised, fail to meet contractual obligations, or incur fines from the ICO or other bodies.
- Increased vulnerability to future attacks – experiencing one attack can make you a prime target for criminals, highlighting the argubaly increasing importance of cyber security and insurance after a successful attack.
While having a cyber policy in place can help you cope with the impacts outlined above and reduce the uncertainty and stress associated with cyber incidents, it can also demonstrate your commitment to cyber security and data protection. This can enhance your credibility and competitiveness in the market, showcasing your business as well-run, reliable and conscientious.
What do you need to consider when arranging your cyber insurance policy?
Cyber insurance policies vary widely in terms of their covers, exclusions, limits, and premiums. Therefore, you need to carefully assess your cyber risk profile and compare different options before choosing a policy that suits your needs and budget. This is ultimately where the assistance of an insurance broker, like McClarrons, can really help – to understand the benefits of each area of cover and the differences between policies.
Here are some factors to consider when arranging your cyber insurance policy:
- Scope of coverage: You need to check which types of cyber incidents and expenses are covered by your policy, and which are not. For example, some policies may not cover social engineering attacks, such as phishing or impersonation, or incidents caused by human error or negligence. Additionally, you should confirm whether your policy covers both first-party and third-party losses, meaning the losses you suffer and the losses you cause to others, such as your suppliers or customers.
- Limit of indemnity: You need to be clear about how much your policy will pay out in the event of a claim, and whether it is adequate to cover your potential losses. You also need to check if your policy has a sub-limit for specific types of expenses, such as extortion payments or legal fees, and if it has an aggregate limit for the entire policy period. An “aggregate” limit essentially means that the limit of cover applies to the whole policy period, i.e. the maximum amount that will be paid out during the policy period. Conversely, an “any one claim” limit means that the limit applies to each individual claim throughout the policy period.
- Excess or deductible: You should also take the time to understand how much you would have to pay out of your own pocket before your policy kicks in for a claim and, ultimately, whether you could afford it. You should also check if your policy has a co-insurance or co-payment clause, which would mean you have to share a percentage of a claim with your insurer.
- Policy period: This may seem obvious but it is important you understand how long your policy lasts, and whether it is renewable or non-renewable. You also need to check if your policy has a retroactive date; if so, this would mean it will only cover incidents that occur after a certain date. You can read more about how retroactive dates work in one of our earlier blog posts. Your policy may also have an extended reporting period, which means it allows you to report incidents that occur even after the policy expires. Again, working with a broker can be particularly invaluable here to ensure you understand all the implications of various nuances within it and how these would apply in the event of a claim.
- Policy conditions: With any insurance policy, you must ensure you understand your obligations and responsibilities under it and the consequences of not complying, which can lead to a claim being declined or your policy being voided entirely. For example, some policies may require you to notify your insurer promptly after a cyber incident, implement specific cybersecurity standards and controls, or cooperate with your insurer during the claims process.
Arranging cyber insurance
Cyber insurance is a specialised and complex product that can require expert advice and guidance so we, naturally, would advise using a broker to arrange this type of insurance in particular, helping you to make decisions around the particular covers and limits that will apply. A broker should be able to help you find and compare different policies from various insurers, and negotiate terms for you, allowing you to feel confident in selecting the right cyber insurance for you and your business. Whichever option you choose, you will need to provide accurate and complete information about your business and your cyber risk exposure, such as:
- The nature and size of your business and your industry sector
- The type and volume of data you collect, store, and process
- The systems and networks you use and how you secure them
- Any cyber incidents you have experienced or anticipate
- Any cyber security policies and procedures you may have in place
In summary…
Cyber insurance is a valuable and essential tool for businesses who want to protect themselves from the growing and evolving cyber threats businesses are experiencing. Cyber insurance is not a one-size-fits-all solution; you need to carefully consider your cyber risk profile and compare different policies before choosing one that meets your needs and insurance budget. It is important, as a final note, that we reiterate that cyber insurance is not a substitute for cyber security measures but a complementary tool that can help you mitigate the residual risks that cannot be eliminated by cyber security practices.
Should you wish to explore your cyber insurance options, please do not hesitate to contact our team at enquiries@mcclarroninsurance.com or by calling on 01653 697055. You can also visit our Cyber Insurance page to learn more.