photon_photo - stock.adobe.com

Tip

Cyber insurance explained, from selection to post-purchase

Before you sign on the dotted line, make sure you understand what cyber insurance can and can't do -- and what type of policy will do the most for your organization.

Late one night in October 2025, AWS went down, bringing critical services such as Venmo, Slack, Zoom, Ring and many more with it. Shoppers were unable to check out, leaving millions of dollars of abandoned online carts. Workers were unable to communicate and business halted for thousands of companies. The outage ultimately lasted about 15 hours, causing an estimated $38 million to $581 million in insured losses, according to cyber-risk analytics firm CyberCube.

"[N]ot all losses will be insured," cautioned CyberCube. That fact was both a relief to cyber insurers and a stressor for impacted businesses. The incident demonstrated the complexities of systemic risk and how one failure at a single cloud technology provider can cascade through the entire ecosystem. As these far-reaching incidents become increasingly common, cyber insurers have updated their policies to reduce the risk of catastrophic losses, often leaving businesses exposed during incidents when they expected to have coverage.

Cyber insurance is more popular than ever, but the fine print has never been more critical. At one time, organizations could tick the "cyber" checkbox and have reasonable confidence they would be covered in the event of a major cyber-related incident. Today, however, policies include carefully crafted gaps.

To ensure coverage and mitigate risk, businesses must understand the various types of cyber insurance, how to select coverage and the steps to take once a cyber insurance policy is in place.

Know your coverage

Unlike auto insurance, there is no standard form of cyber insurance. Insurers offer a wide variety of products, and often the fine print makes a big difference in an organization's coverage.

Common types of cyber coverage include:

  • Remediation services cover the costs of responding to a potential breach, including recovery support, forensic services, legal fees, call center services, PR services, notification costs, credit monitoring and more. In some cases, the insurer provides a response team rather than simply covering the costs. This service can be invaluable, particularly for smaller organizations lacking a dedicated cybersecurity team.
  • Information security and privacy liability for claims and damages resulting from a data breach or cybersecurity failure. This could include coverage for legal defense and investigative expenses, in addition to claims and damages payable as a result of a data breach or violation of security or privacy-related laws.
  • Regulatory defense and penalties cover costs associated with regulatory action, including fines, penalties, legal fees, investigative costs and more.
  • Business interruption covers lost revenue, and expenses for minimizing the impact of the disruption and services to regain full operability in the event of an operational outage.
  • Media liability protects against claims related to copyright infringement, plagiarism, libel, defamation and other negligent actions resulting from media publication.
  • Cyberextortion covers costs such as ransom negotiation and payment, data decryption and recovery, and investigation in cases of ransomware and exposure extortion.

Cyber insurance policies normally have a list of exclusions, including:

  • Terrorism, acts of war, invasions, riots and revolutions.
  • Failure to maintain a reasonable level of security.
  • Prior acts that occurred before a policy was in effect.
  • Breach of contractual obligations, such as PCI DSS.
  • Damage to physical property.

Why the fine print matters

Insurers have quietly introduced new requirements and exclusions in the fine print, where they can easily be overlooked. For example, a cyber insurance policy might exclude coverage for ransom payments if the insured discloses to an adversary that they have cyber insurance.

Coverage has become particularly complex regarding business interruption losses and the cloud. "Carriers offering coverage for contingent business interruption losses may require an insured to have a written contract with the vendor that is impacted by the supply chain loss," reported cyber insurance broker Gallagher in its "2026 Cyber Insurance Market Outlook."

Additionally, Gallagher advised that buyers "pay attention to time element coverage wording," such as defined waiting periods, since these can significantly affect the value of a claim.

ln a scenario like the AWS outage, the majority of businesses impacted didn't have direct contractual relationships with Amazon but, rather, through a third-party vendor such as Slack or Zoom which, in turn, is dependent upon AWS as a fourth-party supplier. So, if an organization suffers an outage because of a fourth- or fifth-party supplier, the insurer might not cover business interruption losses, either because of a lack of contractual relationship, timing or both.

At the same time, emerging privacy regulations have increased liability. "Pixel-tracking lawsuits" have led to multimillion-dollar settlements, such as the $2.72 million class action payout in Carbone v. Limited Run Games Inc. In these cases, organizations employ a common tracking pixel to support functions such as marketing analytics and often unknowingly violate laws such as the CCPA, the Video Privacy Protection Act, or state and federal wiretapping statutes. After years of huge losses, cyber insurers have adjusted their privacy coverage to protect themselves, often leaving policyholders with big bills.

Selecting coverage

Obtaining the coverage an organization needs requires a methodical selection and review process. Here are some tips:

  • Involve the right people. Get input from people with a variety of skills. This could include legal counsel, IT management, risk management and experienced cybersecurity professionals.
  • Inventory data. To select the right amount and type of insurance coverage, it is necessary to know how much sensitive data is stored, what laws and regulations apply and any contractual obligations.
  • Understand high-risk scenarios. Ideally, it is best to conduct a formal risk assessment at least annually, during which cybersecurity risks are enumerated and prioritized. A risk management plan can help determine what risks the organization intends to transfer.
  • Review existing coverage. Harmonize cyber coverage with existing policies to avoid dual coverage or gaps in coverage whenever possible.
  • Research insurers. Cyber insurance providers are not all created equal. Research the following:
    • Claim denials and lawsuits. Some cyber insurers could be more likely to deny claims than others. Check public records to see if the insurer has a history of court battles.
    • Supplemental resources. Cyber insurers might offer training videos, policy templates, incident response planning guides and other materials.
    • Panels. Review the insurer's cybersecurity attorneys, forensics firms and other vendors.
  • Obtain quotes. Once the groundwork is complete, obtain quotes to evaluate. Insurance agents might have specific recommendations.
  • Compare and select. It might feel like comparing apples to oranges, but an experienced cybersecurity professional, working in conjunction with an insurance agent, can help select the best option. Review the chosen policy in depth prior to purchasing so there are no surprises. Regularly review and adjust cyber insurance coverage as needed.

Next steps after buying cyber insurance

Once signed up for a policy, the work isn't done. Carefully review the new policy to understand the insurer's claims-filing process and requirements. For example, clients might need to report incidents within a specified period to qualify for coverage. Update incident response playbooks to include important details relating to the cyber insurance policy.

Train cybersecurity responders so they know when and how to bring in the insurer. Depending on coverage type, it could be worthwhile to meet proactively with cyber insurance contacts.

Finally, take advantage of the insurer's resources, such as cybersecurity portals and training  opportunities. Share access to these resources within the organization to maximize the value of the policy.

Ultimately, cyber insurers need to protect their bottom line -- and that self-protection can both help organizations reduce risk or hurt them if it results in coverage gaps.

In the AWS outage, what separated the organizations that were covered from those that weren't was policy language negotiated months or years earlier. CISOs need to be informed and have an experienced broker who can help identify important nuances that can have a big impact on the organization's coverage.

Sherri Davidoff, CEO of LMG Security and author, is a recognized expert in cybersecurity and data breach response.

Dig Deeper on Enterprise Risk Management