Cover typically includes incident response, notification costs, business interruption, and some liability. For a small business the response support is usually worth more than the indemnity limit.

What these policies actually contain

Cyber cover is a bundle rather than a single thing, and the components differ considerably between insurers.

Most include some combination of incident response costs, the cost of notifying affected people, data restoration, business interruption while systems are down, liability to third parties, and sometimes cover for certain kinds of fraud.

The proportions matter more than the headline limit, since a policy with a large aggregate limit and thin response cover is not what a small business needs.

This is a general description rather than insurance advice. Policy wordings differ substantially and a broker who reads them for a living is the right person to compare specifics.

The response line is the real product

For a business without technical staff, this is the part that changes outcomes.

A compromise discovered on a Saturday morning, with nobody knowing what to do first, is a situation where an hour of competent direction is worth more than a payment months later.

Most policies include a number that connects you to people who handle these routinely: technical responders, and where needed legal and communications support.

They will tell you what to contain, what to preserve, and what your obligations look like, which is exactly the knowledge a small business does not have and cannot acquire during an incident.

When comparing policies, ask what the response arrangement actually is, how you reach it, and whether it is available outside business hours.

What is usually covered

Notification is the one small businesses underestimate. Telling several hundred people properly, with somebody available to answer, is not free even when the incident itself was contained quickly.

What is usually not

Worth knowing before rather than during a claim.

Payment redirection fraud, where somebody is tricked into transferring money, is frequently excluded or covered only under a specific extension, and it is the most likely large loss a small business faces.

Ask about it specifically by name rather than assuming a cyber policy covers it.

Losses arising from unsupported software, unapplied patches, or failure to meet the security conditions in the policy may also be excluded.

And a policy usually will not replace hardware, improve your systems, or cover the reputational effect, which is real and uninsurable.

The conditions you have to actually meet

The part that decides whether a claim is paid, and the part nobody reads at renewal.

Applications now commonly ask about two-factor authentication, backups, patching, and access controls, and the answers become warranties.

Answering yes to two-factor everywhere and then having a claim arise from an account without it is the situation to avoid, and it is easy to fall into when somebody in a hurry completes a form.

Answer accurately even where the accurate answer is worse, and if a condition requires something you do not have, either implement it or tell the insurer.

The application is also a useful audit in its own right: the questions describe what insurers have learned actually causes losses.

A worked example

A five-person firm took a modest policy mainly because a client contract required it.

Eight months later a mailbox was compromised and a fraudulent invoice went to eleven customers.

They called the response line on a Sunday. Within two hours they had been told what to contain, what to preserve, and what their notification position looked like.

The policy covered the forensic work, the notification costs, and a modest amount of the time lost.

The owner's assessment afterwards was that the money was useful and the Sunday phone call was the thing that mattered, because their instinct had been to wipe the mailbox, which would have destroyed the evidence the assessment depended on.

They renewed, and separately added the payment fraud extension, which they had not originally taken.

Whether it is proportionate

An honest answer varies more than the industry suggests.

It is more clearly worth it where you hold a meaningful volume of customer information, where you take payments, where trading stops if systems stop, or where a client contract requires it.

It is less clearly worth it for a sole trader holding a few hundred contact records, with no online transactions, where an incident would be inconvenient rather than existential.

In that second case the same money spent on backups, a password manager, and two-factor buys more risk reduction than a policy does.

Insurance handles the consequence. The basic measures reduce the probability, and for a very small business the probability is usually the better place to spend first.

Questions worth asking a broker

Six, which will produce a more useful comparison than the premium alone.

What does the incident response arrangement consist of, and is it available at any hour.

Is payment redirection fraud covered, and under what extension.

What security conditions am I warranting, and do I currently meet them.

What is the notification period after discovering an incident.

How is business interruption calculated for a business of my size.

And what would you expect this policy not to cover in a typical small business incident.

The counter-case

Cyber cover is sold with a certain amount of alarm, and it is worth resisting the framing.

A policy does not make an incident less likely, does not restore customer confidence, and does not remove your obligations, all of which are occasionally implied.

Premiums have risen and conditions have tightened, so a policy taken three years ago may have materially different requirements at this renewal, which is worth reading rather than renewing automatically.

And an underinsured business with good backups, two-factor, and a tested restore is in a better position than a well-insured one without them.

Take the cover if the exposure justifies it, and do not let it substitute for the measures that prevent the claim.

Deciding

  1. Do the basics first: backups, two-factor, a manager.
  2. Assess your exposure: data held, payments, downtime.
  3. Ask what the response arrangement is, and its hours.
  4. Ask about payment fraud by name.
  5. Answer the application accurately.
  6. Check the conditions you are warranting.
  7. Reread it at renewal rather than rolling it over.

Step three is what separates policies that help a small business from policies that only pay one afterwards.

Asking suppliers for cover is in insurance, contracts and working with suppliers.


Frequently asked questions

What does cyber cover include?

Usually a bundle: incident response, notification costs, data restoration, business interruption, third-party liability, and often extortion. The proportions matter more than the headline limit.

What is the most valuable part for a small business?

The incident response line. An hour of competent direction on a Saturday morning is worth more than a payment months later, particularly to a business with no technical staff.

Is payment redirection fraud covered?

Frequently not, or only under a specific extension. It is the most likely large loss a small business faces, so ask about it by name rather than assuming.

What conditions do I have to meet?

Applications commonly ask about two-factor, backups, patching, and access controls, and the answers become warranties. Answer accurately even where the accurate answer is worse.

Is it worth it for a very small firm?

Less clearly, if you hold a few hundred contacts and take no payments online. The same money on backups, a password manager, and two-factor reduces probability rather than covering consequence.

Should I renew automatically?

No. Premiums have risen and conditions have tightened, so a policy taken three years ago may carry materially different security requirements at this renewal.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Comparing cyber policies on price?

Ask what the incident response arrangement is and whether you can reach it on a Sunday. That is the part that changes outcomes.

Start a Conversation