Cyber Insurance for Enterprises: Cover, Exclusions and Underwriting
SAIBA Corporate · 13 September 2026 · 7 min read
Cyber is the one policy where the underwriter cares more about your IT controls than your balance sheet. Here is what a mid-size or large enterprise should expect it to cover, what it will not, and how to keep it from sitting unread in a drawer.
What a cyber policy typically covers
Cyber wordings are split into first-party sections (your own losses) and third-party sections (what you owe others). Most enterprise policies include some version of each of the following.
Breach response. The cost of finding out what happened and dealing with it: IT forensics, legal advice on notification duties, notifying affected individuals and regulators, call-centre support, credit or identity monitoring where offered, and crisis communications. This is the section used most often, and the one where the insurer’s panel of vendors matters.
Business interruption. Lost net profit and extra expense while systems are down after a covered event, once a waiting period measured in hours has passed. Some wordings extend to an outage at a cloud or managed service provider you depend on; many do not, or cap it tightly.
Cyber extortion. Ransomware negotiation, the specialist firms who handle it, and the ransom itself where payment is lawful and the insurer has agreed.
Data and system restoration. Rebuilding data and systems to the state they were in before the incident — not to a better one.
Liability. Claims from customers, partners and employees whose data or systems were harmed, plus the cost of defending them.
Regulatory defence. Legal costs of responding to an investigation under data protection law, and penalties where the law allows them to be insured. Whether a fine is insurable varies by country; the wording will usually say “where insurable” and leave it there.
What it usually excludes
Every wording differs, but the same exclusions come up again and again, and the ones below cause the most surprise at claim time.
- War and state-backed attacks. Wordings have tightened here. Read the clause and ask the broker how the insurer decides what counts as state-backed.
- Infrastructure failure. Power cuts, telecom outages and internet backbone failures are generally outside cover.
- Known incidents and prior circumstances. Anything you knew about, or ought to have known about, before inception.
- Failure to maintain declared controls. If you told the underwriter you had multi-factor authentication on all remote access and you did not, expect the claim to be contested.
- Bodily injury and physical damage. These belong to liability and property policies, though the boundary is worth checking if you run operational technology.
- Betterment. The insurer restores what you had; upgrading on the way is at your cost.
- Social engineering and funds-transfer fraud. Often excluded or heavily sub-limited, and sometimes better placed under a crime policy.
Unencrypted portable devices and unsupported software are two more exclusions that catch organisations with a long tail of laptops and legacy systems.
How insurers assess the risk: the controls questionnaire
For most lines, the underwriter starts with sums insured and claims history. For cyber, the proposal form is a controls questionnaire, and the answers drive both the premium and whether cover is offered at all. Expect questions on:
- Multi-factor authentication on remote access, email, cloud administration and privileged accounts
- Backups: how often, whether they are offline or immutable, whether they are segregated from the production network, and when a restore was last tested
- Patching cadence for critical vulnerabilities, and how end-of-life systems are handled
- Endpoint detection and response (EDR) on servers and workstations, and whether anyone watches it around the clock
- Email filtering and protection against spoofed domains
- Privileged access management and network segmentation
- A written incident response plan, and whether it has been exercised
- Security awareness training and phishing simulations
- Oversight of vendors and third parties who connect to your network
Two practical points. First, the questionnaire should be answered by IT security, not by the insurance or finance team guessing on their behalf. Second, the answers form part of the contract. Keep a signed copy with the policy, and treat any control that is switched off or weakened during the year as something the insurer may need to hear about.
Some insurers also scan your internet-facing systems before quoting. Open remote desktop ports and expired certificates get noticed.
Sum insured, sub-limits and retentions
Cyber policies are usually written on an aggregate basis: one limit for the whole year, shared across every section. Inside it sit sub-limits for particular heads of cover, and each claim carries a retention.
A worked example. Say an enterprise buys a ₹25 crore aggregate limit. The wording sets extortion at ₹5 crore, regulatory penalties at ₹5 crore, and business interruption with a 12-hour waiting period. The retention is ₹25 lakh per claim. A ransomware event costing ₹4 crore in forensics and restoration, ₹3 crore in lost profit and a ₹2 crore ransom would use up ₹9 crore of the aggregate after the retention, leaving ₹16 crore for anything else that year.
To size the limit, work from your own numbers rather than a rule of thumb: how many personal records you hold and what notification would cost per record; what an hour of downtime costs by system and how long a full rebuild from backup would take; what a realistic ransom demand looks like for your size and sector; and which customer contracts a breach would trigger.
Sub-limits are where cover quietly falls short. A generous headline limit can hide a business interruption sub-limit that would not cover a week of downtime. It is the same problem as under-insurance on the property side, measured in hours and records instead of square feet.
Coordinating with IT security and the incident response plan
A cyber policy only works if the people running the incident know it exists and what it requires. Most wordings carry conditions that are easy to breach in the first few hours of a crisis.
Write the insurer’s breach hotline and the policy number into the incident response plan itself, on the first page. Decide in advance who is authorised to make that call, and who can approve a ransom payment if it comes to that. Make sure the insurer’s panel forensics and legal firms are known to the security team before an incident, not discovered during one.
Preserve evidence: logs, images of affected machines, the ransom note. The insurer’s forensic firm will need it, and so may a regulator. Keep a running log of costs from hour one; business interruption claims are won or lost on the quality of the records.
Keeping cyber in the same register as everything else
Cyber is often bought outside the usual insurance process: the CIO or CISO sponsors it, the questionnaire lives in IT, and the policy document ends up on someone’s laptop. That causes three predictable problems. The renewal is missed or handled in a rush. Nobody notices that a subsidiary or a newly acquired company falls outside the named insured. And when controls change mid-year, no one connects it to a policy condition.
Treat cyber as one more line in the corporate insurance register, with the same fields as property or liability: insured entities, limit, sub-limits, retention, inception and expiry, conditions precedent, and the controls declared at inception. Put the renewal on the same renewal pipeline as everything else, with a reminder far enough ahead to redo the questionnaire properly. Platforms such as SAIBA Corporate hold cyber alongside every other cover, so finance, risk and IT security are looking at the same policy.
One more habit worth building: when IT security changes something material — a new remote access tool, a different backup approach, a merger that joins two networks — log it against the policy and tell the broker. It is a five-minute task that prevents an argument later.
Frequently asked questions
Does cyber insurance pay the ransom?
Usually, under the extortion section, provided payment is lawful in the relevant jurisdictions and the insurer has approved it in advance. The policy also pays for the negotiator. Most insurers would rather help you restore from backups than pay, and a tested backup regime is the strongest argument in your favour at renewal.
Is cyber insurance mandatory for companies?
Generally no, though some customer contracts and tenders require it, and lenders and boards increasingly expect it. Data protection law imposes duties to protect personal data and to notify breaches; insurance does not remove those duties, but it funds the response and the defence.
How is the cyber premium decided?
Mainly by the quality of your controls, then by turnover, sector, the volume and sensitivity of data held, the limit and retention you choose, and your claims history. Two companies of the same size can see very different premiums depending on whether they have MFA, tested backups and EDR in place.
What if our security controls change during the policy year?
Tell your broker. The questionnaire answers form part of the contract, and an insurer may treat a material weakening of controls as something you should have disclosed. Improvements are worth reporting too; they help at renewal and may support a lower retention or a wider sub-limit.
See your insurance program in one place
SAIBA Corporate turns scattered policies, assets and gaps into one live command centre — registers, cover rules, renewals and claims across every business unit. On your servers or on SAIBA Cloud.
Request a walkthrough →