← Back to home
← All articles
Specialist lines

Cyber Insurance for Enterprises: Cover, Exclusions and Underwriting

SAIBA Corporate · 13 September 2026 · 7 min read

Cyber is the one policy where the underwriter cares more about your IT controls than your balance sheet. Here is what a mid-size or large enterprise should expect it to cover, what it will not, and how to keep it from sitting unread in a drawer.

What a cyber policy typically covers

Cyber wordings are split into first-party sections (your own losses) and third-party sections (what you owe others). Most enterprise policies include some version of each of the following.

Breach response. The cost of finding out what happened and dealing with it: IT forensics, legal advice on notification duties, notifying affected individuals and regulators, call-centre support, credit or identity monitoring where offered, and crisis communications. This is the section used most often, and the one where the insurer’s panel of vendors matters.

Business interruption. Lost net profit and extra expense while systems are down after a covered event, once a waiting period measured in hours has passed. Some wordings extend to an outage at a cloud or managed service provider you depend on; many do not, or cap it tightly.

Cyber extortion. Ransomware negotiation, the specialist firms who handle it, and the ransom itself where payment is lawful and the insurer has agreed.

Data and system restoration. Rebuilding data and systems to the state they were in before the incident — not to a better one.

Liability. Claims from customers, partners and employees whose data or systems were harmed, plus the cost of defending them.

Regulatory defence. Legal costs of responding to an investigation under data protection law, and penalties where the law allows them to be insured. Whether a fine is insurable varies by country; the wording will usually say “where insurable” and leave it there.

What it usually excludes

Every wording differs, but the same exclusions come up again and again, and the ones below cause the most surprise at claim time.

Unencrypted portable devices and unsupported software are two more exclusions that catch organisations with a long tail of laptops and legacy systems.

How insurers assess the risk: the controls questionnaire

For most lines, the underwriter starts with sums insured and claims history. For cyber, the proposal form is a controls questionnaire, and the answers drive both the premium and whether cover is offered at all. Expect questions on:

Two practical points. First, the questionnaire should be answered by IT security, not by the insurance or finance team guessing on their behalf. Second, the answers form part of the contract. Keep a signed copy with the policy, and treat any control that is switched off or weakened during the year as something the insurer may need to hear about.

Some insurers also scan your internet-facing systems before quoting. Open remote desktop ports and expired certificates get noticed.

Sum insured, sub-limits and retentions

Cyber policies are usually written on an aggregate basis: one limit for the whole year, shared across every section. Inside it sit sub-limits for particular heads of cover, and each claim carries a retention.

A worked example. Say an enterprise buys a ₹25 crore aggregate limit. The wording sets extortion at ₹5 crore, regulatory penalties at ₹5 crore, and business interruption with a 12-hour waiting period. The retention is ₹25 lakh per claim. A ransomware event costing ₹4 crore in forensics and restoration, ₹3 crore in lost profit and a ₹2 crore ransom would use up ₹9 crore of the aggregate after the retention, leaving ₹16 crore for anything else that year.

To size the limit, work from your own numbers rather than a rule of thumb: how many personal records you hold and what notification would cost per record; what an hour of downtime costs by system and how long a full rebuild from backup would take; what a realistic ransom demand looks like for your size and sector; and which customer contracts a breach would trigger.

Sub-limits are where cover quietly falls short. A generous headline limit can hide a business interruption sub-limit that would not cover a week of downtime. It is the same problem as under-insurance on the property side, measured in hours and records instead of square feet.

Coordinating with IT security and the incident response plan

A cyber policy only works if the people running the incident know it exists and what it requires. Most wordings carry conditions that are easy to breach in the first few hours of a crisis.

Call the insurer before you call anyone else. Engaging your own forensics firm or negotiator without the insurer’s consent can void that part of the claim. The hotline exists so you can act within minutes and still be covered.

Write the insurer’s breach hotline and the policy number into the incident response plan itself, on the first page. Decide in advance who is authorised to make that call, and who can approve a ransom payment if it comes to that. Make sure the insurer’s panel forensics and legal firms are known to the security team before an incident, not discovered during one.

Preserve evidence: logs, images of affected machines, the ransom note. The insurer’s forensic firm will need it, and so may a regulator. Keep a running log of costs from hour one; business interruption claims are won or lost on the quality of the records.

Keeping cyber in the same register as everything else

Cyber is often bought outside the usual insurance process: the CIO or CISO sponsors it, the questionnaire lives in IT, and the policy document ends up on someone’s laptop. That causes three predictable problems. The renewal is missed or handled in a rush. Nobody notices that a subsidiary or a newly acquired company falls outside the named insured. And when controls change mid-year, no one connects it to a policy condition.

Treat cyber as one more line in the corporate insurance register, with the same fields as property or liability: insured entities, limit, sub-limits, retention, inception and expiry, conditions precedent, and the controls declared at inception. Put the renewal on the same renewal pipeline as everything else, with a reminder far enough ahead to redo the questionnaire properly. Platforms such as SAIBA Corporate hold cyber alongside every other cover, so finance, risk and IT security are looking at the same policy.

One more habit worth building: when IT security changes something material — a new remote access tool, a different backup approach, a merger that joins two networks — log it against the policy and tell the broker. It is a five-minute task that prevents an argument later.

Frequently asked questions

Does cyber insurance pay the ransom?

Usually, under the extortion section, provided payment is lawful in the relevant jurisdictions and the insurer has approved it in advance. The policy also pays for the negotiator. Most insurers would rather help you restore from backups than pay, and a tested backup regime is the strongest argument in your favour at renewal.

Is cyber insurance mandatory for companies?

Generally no, though some customer contracts and tenders require it, and lenders and boards increasingly expect it. Data protection law imposes duties to protect personal data and to notify breaches; insurance does not remove those duties, but it funds the response and the defence.

How is the cyber premium decided?

Mainly by the quality of your controls, then by turnover, sector, the volume and sensitivity of data held, the limit and retention you choose, and your claims history. Two companies of the same size can see very different premiums depending on whether they have MFA, tested backups and EDR in place.

What if our security controls change during the policy year?

Tell your broker. The questionnaire answers form part of the contract, and an insurer may treat a material weakening of controls as something you should have disclosed. Improvements are worth reporting too; they help at renewal and may support a lower retention or a wider sub-limit.

See your insurance program in one place

SAIBA Corporate turns scattered policies, assets and gaps into one live command centre — registers, cover rules, renewals and claims across every business unit. On your servers or on SAIBA Cloud.

Request a walkthrough →
All articlesFor corporatesFor brokersRequest a walkthrough