Back to Blog
Compliance & Risk Cybersecurity

Cyber Insurance: What It Covers — and What It Doesn't

✍️ Eugene Moore · 📅 August 2026 · ⏱ 6 min read

Cyber insurance won't pay out if you skipped the security basics. Most business owners buy a policy, file it away, and assume they're covered. They're not — or at least not in the way they think.

Insurers have spent the last three years tightening their requirements. What used to be a checkbox application is now a technical audit. And when a claim comes in, the first thing underwriters do is check whether you had the controls you said you had — and whether you actually had them enforced at the time of the incident.

What Voids a Cyber Insurance Claim

These are the most common reasons claims get denied or disputed — and every one of them is preventable:

🔓

No MFA enforced

You checked the box saying MFA was in place. The breach happened through a credential attack. MFA wasn't actually enforced on the compromised account. Claim denied or reduced.

💾

Backups that don't restore

Ransomware hit. Backups existed but had never been tested. Restore failed. The policy covers "restoration costs" — but if you can't restore, there's nothing to reimburse.

🩹

Unpatched known vulnerabilities

Attacker exploited a vulnerability that had a patch available for months. Insurer characterizes it as negligence. Policy excludes "failure to maintain reasonable security standards."

📋

No incident response plan

Breach occurs. No documented response process. You can't demonstrate what you did, when, or who was notified. Claim gets disputed on procedural grounds.

👥

Shared admin credentials

Attacker escalated privileges through a shared admin account. Policy excludes or limits coverage for incidents where access controls weren't segregated.

What Cyber Insurance Actually Covers

When your security controls ARE in place and documented, a well-structured policy covers the costs that most businesses genuinely couldn't absorb on their own:

Forensics and incident response

The cost of identifying how the breach happened, what was accessed, and how to contain it — typically tens of thousands of dollars for even a modest incident.

Legal and regulatory notification costs

Attorney fees, notification letters, credit monitoring for affected individuals, and regulatory filing costs under HIPAA, CT SHIELD, NYDFS, and similar frameworks.

Business interruption losses

Revenue lost during the recovery period — typically calculated against your average daily revenue and capped at a waiting period threshold.

Ransomware extortion payments

The payment itself, if your insurer and legal counsel determine it's the appropriate course of action. Most policies now require insurer approval before payment.

Third-party liability

If client data was exposed in the breach, coverage for claims, settlements, and defense costs from affected parties.

Five Questions to Ask Your Broker

Not all cyber policies are equal. Before you renew or purchase coverage, these questions surface the gaps that most brokers won't volunteer:

1
What security controls does this policy require, and how are they verified at claim time? The answer should be specific — not "reasonable security practices."
2
Is there a sublimit on ransomware payments or social engineering losses? Many policies cap these at a fraction of the overall limit — often $100k on a $1M policy.
3
How is "business interruption" calculated and what's the waiting period before it kicks in? A 12-hour waiting period on a 3-day outage means you absorb the first 12 hours entirely.
4
Does the policy cover incidents originating from a third-party vendor? Supply chain attacks are increasingly common — many policies exclude them by default.
5
What's the claims process, and do I need pre-approval before engaging an incident response firm? Calling the wrong vendor before notifying your insurer can void coverage entirely.

The Bottom Line

Cyber insurance is a meaningful layer of financial protection — but only when it sits on top of a real security posture, not instead of one. The controls that insurers require aren't arbitrary. MFA, tested backups, patch management, access controls — these are the same baseline hygiene that actually prevents incidents from becoming catastrophic.

If your current security posture wouldn't survive an insurer's audit, the answer isn't a better policy. It's fixing the controls first, then getting the right coverage on top of them.

Free Security Posture Review

Moore Technology Consulting can assess whether your current security controls would hold up to an insurer's audit — and close the gaps that would put your claim at risk.

DM us "COMPLY" or schedule a free consultation · (646) 791-2137

← How to Choose the Right MSP CT SHIELD Compliance →
Free Security Posture Review

Would your cyber insurance claim actually pay out?

We'll assess whether your current controls meet insurer requirements — and close the gaps before you need to find out the hard way.