A cyber policy pays for what the checklists cannot prevent. Read it for the sub-limits and the ‘reasonable security’ condition before buying.
What is usually covered
Funds lost to fraud (often a low sub-limit), business interruption from an attack, data restoration and IT forensics, liability to customers for a data breach, legal costs, ransomware negotiation and — in some policies — the ransom itself.
What is usually excluded
Losses from unpatched known vulnerabilities, from pirated software, from a claim reported late, from social-engineering fraud where no security control was breached (check the wording), and war / state-actor events.
Questions to ask
What is the funds-transfer-fraud sub-limit? Is social engineering covered? What security controls does the policy require (2FA, backups, updates)? What is the reporting window? Is there a 24-hour incident helpline?
Checklist
- ☐Sub-limit for fraud loss understood
- ☐Required security controls in place and documented
- ☐Reporting window and helpline saved in the incident plan
- ☐Policy reviewed at renewal against new risks (UPI, WhatsApp ordering)