Do not assume a standard business policy covers every cost caused by a cyber incident. Do not assume it excludes every cyber event either.
Insurance depends on the wording of the policy, its exclusions and the circumstances of the claim. The time to check is before email is compromised, files are locked or customer information is exposed.
Ask what each policy actually covers
Business insurance, professional indemnity and cyber insurance are different products, but names alone do not settle what is covered.
Ask your licenced insurance adviser to explain how the policy responds to events such as:
- an email account used to redirect a payment
- business systems being unavailable
- malicious software affecting devices or files
- loss or disclosure of customer information
- the cost of technical investigation and recovery
- legal advice, notification and communication after an incident
Use examples that match how your business works. A clinic, retailer and construction company may depend on different systems and hold different information.
Read the conditions as well as the cover
A policy may require the business to maintain particular security controls, report an event promptly or obtain approval before engaging a supplier. It may also have limits, waiting periods or exclusions that affect a claim.
Record the answers in writing and keep the policy and contact details somewhere accessible if normal systems are unavailable.
JCPIT Support cannot advise whether an insurance claim will be accepted. That question belongs with your insurer, broker or other licenced adviser.
Understand what an incident can involve
The immediate technical work is only one part of recovery. Staff may be unable to work. Accounts may need to be secured, devices checked and data restored. Customers, advisers or authorities may need to be contacted depending on the incident and the business's obligations.
Map these tasks before choosing cover. This will help the adviser understand the interruption the business is trying to manage.
Insurance does not replace security
Insurance may reduce some financial impact, but it cannot prevent downtime or make a poor backup restore successfully. Basic controls still matter:
- protect important accounts with a second sign-in check
- keep devices and software updated
- restrict administrator access
- train staff to verify payment changes
- maintain and test backups
- document who to contact after an incident
These controls may also be relevant to an insurer's questions or policy conditions. Answer applications accurately and tell the adviser if the setup changes.
Prepare an incident contact list
Keep the policy number and insurer's incident contact process with the business continuity plan. Add the contacts for IT support, banking, legal advice and key business decision makers.
Staff should know who can authorise urgent recovery work. Check whether the insurer requires contact before costs are incurred, except where immediate action is needed to prevent further harm.
Take your current security and backup details to the insurance conversation, not assumptions. If you cannot show which controls are working, contact JCPIT for a security and backup review. We will document the technical gaps for you to discuss with your licenced insurance adviser.