# What is Cyber Insurance?

> Cyber insurance is a contract under which an insurer agrees, subject to the policy’s terms, to fund specified losses, liabilities, or response services arising from covered cyber events.

- Canonical URL: https://yellowcube.eu/glossary/cyber-insurance/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Coverage may address the insured organization’s own costs, third-party claims, or both, but triggers, definitions, exclusions, limits, deductibles, waiting periods, territories, and required security practices vary between policies.

Possible cover includes investigation, legal advice, notification, data restoration, business interruption, extortion response, litigation, or regulatory-defense costs. Buyers should model plausible losses, compare coverage with existing policies, and understand the insurer’s notification, consent, evidence, vendor, and claims-handling requirements before an incident occurs.

### Key points

- **Match exposure to wording:** Review named events, affected systems and suppliers, first- and third-party losses, sublimits, exclusions, aggregation, and whether dependent business interruption is included.
- **Validate conditions:** Confirm representations made during underwriting, required safeguards, notice deadlines, cooperation duties, approved responders, consent before costs are incurred, and renewal obligations.
- **Integrate response:** Align policy contacts and insurer-appointed services with incident response, legal privilege, evidence preservation, communications, ransom decisions, suppliers, and continuity plans.
- **Important limitation:** Insurance does not prevent incidents or transfer every financial, operational, legal, or regulatory consequence. Payment depends on the applicable law, policy wording, facts, limits, and compliance with conditions; obtain qualified insurance and legal advice for the actual contract.

### Related terms

[Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Business continuity](<https://yellowcube.eu/glossary/business-continuity/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Ransomware](<https://yellowcube.eu/glossary/ransomware/>)

### Sources

[UK NCSC, Cyber Insurance Guidance](https://www.ncsc.gov.uk/guidance/cyber-insurance-guidance) · [National Association of Insurance Commissioners, Cyber Insurance](https://content.naic.org/sites/default/files/inline-files/cyber-insurance-naic.pdf) · [EIOPA, Supervisory Statements on Exclusions Related to Systemic Events and Non-Affirmative Cyber Exposures](https://www.eiopa.europa.eu/eiopa-publishes-supervisory-statements-exclusions-related-systemic-events-and-management-non-2022-09-22_en)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

