Cyber insurance sounds simple: pay a premium, and if you get hacked, the policy pays. In practice it is more like a contract with fine print that decides whether you are covered on your worst day. Many small firms buy a policy, feel covered, and never read what it actually pays for. Then a claim gets denied, and they learn the hard way. This guide explains what these policies usually cover, what they leave out, and how to read one before you sign.
Why small firms carry it
Small and mid-sized businesses are common targets, not rare ones. They hold useful data and often have thinner defenses than large companies. A single breach can bring legal bills, lost work time, and the cost of telling customers what happened. For many firms, one bad incident costs more than years of premiums. Some clients and contracts now require the coverage before they will work with you.
What a policy usually covers
Most policies split into two buckets. The first is your own costs. That can include finding and stopping the breach, restoring lost data, paying for downtime, handling a ransom demand, and managing the public side of a bad week. The second bucket is what you owe other people. If customer data leaks, that can cover legal defense, settlements, and some regulatory fines. Read both buckets. A cheap policy often trims the second one, and that is where the big bills live.
What it often leaves out
Here is where firms get surprised. Most policies will not pay if your security was sloppy. For example, if you claimed to use multi-factor sign-in but did not. They usually exclude problems you already knew about, attacks tied to war or nation-states, and damage from a trusted insider unless you added that cover on purpose. Long-term harm to your reputation and future sales is rarely covered at all. The pattern is simple: insurers pay for accidents, not for skipping basic care.
The catch most people miss
When you apply, you answer questions about your security. Those answers become part of the deal. If you say you enforce multi-factor sign-in on every account and a claim shows you did not, the insurer can deny the claim, right when you need it. So every yes on that form should be something you could prove. This is the single biggest reason claims fall through. Our cyber-insurance renewal checklist lays out the exact controls insurers ask about.
How to read a policy before you buy
Ask what is in each bucket and, more important, what is excluded. Match the payout limits to what a real breach would cost you, not to the cheapest quote. Ask whether the controls you promised are actually turned on across the whole company. And check the renewal terms, because insurers change their requirements every year. This work overlaps with the broader job of IT compliance. If you cannot answer their security questions with confidence, fix that first.
Cyber insurance is a backstop, not a substitute for good security. It pays for accidents, not for neglect. Read both what it covers and what it excludes, match the limits to your real risk, and make sure every control you promised is actually on. The firms that get paid are the ones whose application answers were true.
A few fair questions
How much coverage do we need?
Enough to cover a realistic breach, not just the cheapest quote. Think through legal bills, downtime, and notifying customers, then set your limit against that. A broker who knows your industry can help you size it.
Will insurance replace strong security?
No. It is the opposite. Insurers now require strong security before they will cover you, and they price on it. Good controls lower your premium and keep claims from being denied.
What makes a claim get denied?
Usually an answer on the application that was not true. If you attested to a control you did not have, the insurer can refuse to pay. That is why every promised control should be something you can show.
Want a straight read on whether your policy answers would hold up? Book 15 minutes with Wayne Libonati, President & CEO. Prefer to start on your own? Score your current IT relationship in about 3 minutes.