A cyber insurance policy can remain unchanged while the business behind it changes considerably. New software, outsourced IT, online payment processes, acquisitions, remote working and greater dependence on cloud platforms can all alter the impact of a cyber incident.
That is why reviewing cyber insurance should involve more than checking the premium and headline limit at renewal. The useful questions are whether the policy still reflects how the business operates, whether its limits match realistic losses and whether the conditions could be met if a claim happened tomorrow.
A proper review should cover the exposures, policy wording, limits, security requirements and claims process before cover is renewed.
Start with what has changed in the business
Before looking at the policy, compare the business today with the business that was originally presented to the insurer.
Changes worth identifying include:
- New software or cloud platforms
- Greater use of outsourced IT providers
- New online payment processes
- Remote or hybrid working arrangements
- Acquisitions or changes in company structure
- New locations or overseas operations
- Higher turnover
- Larger volumes of customer or employee data
- Increased reliance on one technology supplier
- New customer portals, apps or connected equipment
Not every change will alter the insurance, but significant changes can affect both the type and scale of the exposure.
A manufacturer that has introduced more connected production systems may now have a much greater interruption risk. A professional services firm using several cloud platforms may be more dependent on third-party availability. A business processing more online payments may face greater exposure to payment fraud.
The starting point should therefore be the current operation, not last year’s policy schedule.
Check exactly who and what is insured
A policy may have been appropriate when it was arranged but become less suitable as the organisation changes.
Check whether the insured entities still match the current company structure. If businesses have been acquired, subsidiaries added or operations reorganised, establish whether they fall within the policy definition of the insured.
The same applies to geographical scope. Businesses that have started trading overseas or dealing with customers in additional territories should check that the policy reflects those activities.
Technology dependency also deserves attention. Establish whether relevant systems are operated internally or supplied by third parties and how the policy treats each.
A current cyber insurance policy should be reviewed against the systems, data and technology dependencies the organisation actually has rather than an outdated description of how it used to operate.
Know what happens when an incident is reported
The quality of cyber cover is not determined solely by the amount that can be claimed.
One of the most important parts of a policy is what happens immediately after an incident.
Check:
- Who must be contacted first
- Whether a 24-hour incident response service is available
- Whether approved forensic, legal or recovery specialists must be used
- Whether insurer approval is needed before costs are incurred
- Whether response costs reduce the main policy limit
- Who within your business has authority to notify the insurer
These points need to be understood before an incident occurs.
If systems are unavailable or sensitive information has been compromised, the business may need technical, legal and operational support quickly. Staff should not be trying to find the policy wording, broker details and notification procedure for the first time during an active incident.
Your internal response plan and insurance arrangements should therefore work together. The people responsible for IT, finance and senior management should know how to access the appropriate claims support if a serious incident occurs.
Test business interruption cover against a realistic shutdown
Business interruption is one of the areas where a headline limit can reveal very little about how useful the protection would actually be.
Consider what would happen if a critical system were unavailable for one day, three days, two weeks or longer.
Then check the policy.
Important points include:
- The waiting period before cover starts
- The maximum indemnity period
- How financial loss is calculated
- Whether increased costs of working are covered
- Whether interruption caused by a technology supplier is included
- Whether supplier-related cover has a separate sub-limit
- How seasonal or rapidly changing revenue would be treated
The amount of time needed to restore technology is not necessarily the same as the amount of time needed to restore the business.
Systems may be functioning again while staff are still dealing with delayed orders, disrupted projects, backlogs or lost customers. Businesses with significant digital dependency should therefore review cyber business interruption insurance against a realistic recovery period rather than assuming that technical restoration means the financial loss has ended.
Do not assume cyber fraud is automatically covered
One of the easiest gaps to miss involves fraudulent payments.
A compromised email account, false supplier instruction or convincing request for an urgent transfer clearly involves technology, but that does not mean every resulting financial loss automatically falls within cyber insurance.
Some cyber policies provide cover for areas such as social engineering or funds transfer fraud. Others may restrict this cover or leave the direct financial loss to a separate policy.
The review should therefore establish what happens if an employee transfers money after receiving a fraudulent instruction.
If the business also has crime insurance, check how the two policies interact. The important issue is not which label is attached to the incident but whether there is a clear route to cover for the loss the business could actually suffer.
Look beyond the headline policy limit
A £1 million cyber policy does not necessarily mean £1 million is available for every type of cyber loss.
Specific sections can have lower sub-limits.
Depending on the wording, separate limits may apply to areas such as:
- Social engineering and payment fraud
- Cyber extortion
- Data restoration
- Third-party technology provider failures
- Crisis communications
- Regulatory defence costs
- Incident response services
The review should identify these limits individually and compare them with the potential exposure.
A business particularly concerned about payment fraud, for example, should not rely on a large overall policy limit if the relevant fraud section has substantially less cover.
Excesses and waiting periods should be reviewed in the same way. They need to be considered alongside the size and speed of the losses the business could realistically face.
Read security requirements as carefully as the cover
Cyber policies increasingly sit alongside specific expectations about how the business manages its systems.
These may relate to areas such as:
- Multi-factor authentication
- Software updates
- Backup arrangements
- Remote access
- Privileged user accounts
- Endpoint protection
- Staff awareness
- Incident response procedures
The important point during a review is accuracy.
If the policy or renewal information states that a particular security measure is in place, the business should be able to confirm that this remains true across the relevant systems.
Controls can change without senior management realising. A new application may not use the same authentication process as an older system. A backup arrangement may have changed after an IT migration. An acquired company may operate differently from the rest of the group.
Cyber insurance information should reflect what is actually happening, not what everyone assumes is happening.
Check exclusions and endorsements rather than relying on last year’s wording
Renewing with the same insurer does not remove the need to review the wording.
Look for changes to exclusions, endorsements and definitions rather than concentrating only on price and limit.
Areas that may warrant closer attention include:
- Known incidents or vulnerabilities
- Failure to meet stated security requirements
- Infrastructure or utility failures
- Contractual liabilities
- Acts connected with war or state-backed activity
- Unapproved costs or service providers
- Territorial restrictions
- Prior circumstances
The practical effect will depend on the individual wording, so broad assumptions are risky.
If an exclusion has changed or a new endorsement has been added, establish what it means for the way the business operates before accepting renewal terms.
Check where cyber insurance meets other policies
Cyber incidents do not always fit neatly into one insurance category.
A fraudulent payment may raise questions about cyber and crime insurance. A technology business facing a customer allegation may need to consider both cyber and professional indemnity insurance. An operational outage may raise questions about cyber and conventional business interruption arrangements.
That does not mean the same loss will be recoverable under several policies. The purpose of the review is to understand where each policy is intended to respond and whether there are gaps between them.
This becomes particularly important for businesses with more complex insurance programmes, where similar terminology can appear in different policies without providing identical protection.
Pressure-test the policy with a realistic scenario
One of the simplest ways to assess a cyber policy is to stop reviewing it in the abstract.
Choose a credible incident for the business.
For example, an attacker gains access to an employee’s email account. Payment instructions are altered, sensitive correspondence becomes accessible and malware later prevents staff from using important systems.
Now work through what happens next.
Who is contacted first? Which specialists are appointed? Is the stolen money covered? What happens to lost income while systems are unavailable? Are restoration costs included? Would a third-party data claim be handled? What excesses or sub-limits apply?
The purpose is not to predict the next attack. It is to test whether the policy makes sense when several consequences arise from the same incident.
That exercise can expose weaknesses that are easy to miss when reviewing individual sections separately.
Do not wait until renewal if the risk changes
An annual review is useful, but some business changes justify looking at cyber cover sooner.
These can include:
- Acquiring another company
- Changing a major IT provider
- Moving important systems to the cloud
- Introducing online payments
- Launching a new digital service
- Entering a new territory
- Taking on a contract with significant cyber requirements
- Suffering a cyber incident or near miss
- Significantly increasing the amount or sensitivity of data held
Waiting until the next renewal can leave the insurance arrangement based on information that no longer reflects the business.
What a useful cyber insurance review should establish
By the end of the review, the business should have clear answers to a few practical questions.
Does the policy reflect the business as it operates today? Are the most financially damaging cyber scenarios covered at sensible limits? Are important areas restricted by sub-limits? Does the business understand the notification process? Are security declarations accurate? Are technology suppliers properly considered? Do other insurance policies leave any gaps?
If those answers are unclear, the review has identified something worth resolving.
Cyber insurance should not simply be renewed because the policy existed last year. Technology, suppliers, operations and cyber exposure change. The insurance needs to keep pace with them.
The purpose of reviewing cover is straightforward: understand how the business could realistically be affected, then make sure the policy, limits, conditions and claims process still match that risk.