What the policy actually covers

Cyber insurance typically pays out for costs incurred after an incident: legal fees, regulatory notification costs, ransom payments in some cases, forensic investigation costs, and some portion of lost revenue during downtime. These are real costs, and having coverage for them is genuinely useful.

The breach still happens, the ransomware still locks your systems, your clients' data is still exposed, and the policy reimburses some of the financial fallout but without undoing any of the damage that caused it.

The costs that do not appear on any invoice

Here is what tends to blindside business owners who assumed they were covered: the financial settlement is the easy part to quantify, whereas the damage to client relationships is not.

When a business suffers a serious breach, client data that has been exposed cannot be unexposed. The trust that took years to build does not come back because the legal bills got paid. Some businesses never recover their client base after a serious incident, regardless of what the insurer covered. The phone calls you have to make to clients telling them their information was compromised are not something any policy reimburses, and neither is the client who quietly moves their business elsewhere because they no longer feel safe with you.

The fine print that catches businesses out

There is another layer most business owners do not discover until it is too late: insurers have conditions, and if those conditions have not been met, the claim can be declined. Before they pay out, insurers want to see evidence of reasonable security practices such as multi-factor authentication, patched and up-to-date systems, documented backup processes, and staff awareness training. If some of these are absent, the policy may not pay what the business owner expected.

This means a business that treated insurance as a substitute for security can end up with neither.

What security actually looks like

The practices that satisfy insurers are not complicated, but neither are they optional: multi-factor authentication on all accounts; regular, tested backups stored separately from the main network; software and systems kept up to date; staff who know how to recognise a phishing attempt. These are not expensive to implement relative to the cost of a breach, and they are the difference between an incident that is manageable and one that is not.

Insurance belongs at the end of that list, as a financial backstop for a worst-case scenario that good security practices make far less likely.

Let's talk about where your business actually stands

The right question is not whether you have a policy but whether your business could survive the incident itself, separate from whether the claim gets paid. If the answer is uncertain, that is worth a conversation. Get in touch and we can walk through what a genuine security baseline looks like for a business like yours.