Risk Management

Check your insurance before a cyber incident

Stressed man reviewing an insurance policy document beside a laptop displaying a ransomware attack warning with a countdown timer

Do not assume a standard business policy covers every cost caused by a cyber incident. Do not assume it excludes every cyber event either.

Insurance depends on the wording of the policy, its exclusions and the circumstances of the claim. The time to check is before email is compromised, files are locked or customer information is exposed.

Ask what each policy actually covers

Business insurance, professional indemnity and cyber insurance are different products, but names alone do not settle what is covered.

Ask your licenced insurance adviser to explain how the policy responds to events such as:

  • an email account used to redirect a payment
  • business systems being unavailable
  • malicious software affecting devices or files
  • loss or disclosure of customer information
  • the cost of technical investigation and recovery
  • legal advice, notification and communication after an incident

Use examples that match how your business works. A clinic, retailer and construction company may depend on different systems and hold different information.

Read the conditions as well as the cover

A policy may require the business to maintain particular security controls, report an event promptly or obtain approval before engaging a supplier. It may also have limits, waiting periods or exclusions that affect a claim.

Record the answers in writing and keep the policy and contact details somewhere accessible if normal systems are unavailable.

JCPIT Support cannot advise whether an insurance claim will be accepted. That question belongs with your insurer, broker or other licenced adviser.

Understand what an incident can involve

The immediate technical work is only one part of recovery. Staff may be unable to work. Accounts may need to be secured, devices checked and data restored. Customers, advisers or authorities may need to be contacted depending on the incident and the business's obligations.

Map these tasks before choosing cover. This will help the adviser understand the interruption the business is trying to manage.

Insurance does not replace security

Insurance may reduce some financial impact, but it cannot prevent downtime or make a poor backup restore successfully. Basic controls still matter:

  • protect important accounts with a second sign-in check
  • keep devices and software updated
  • restrict administrator access
  • train staff to verify payment changes
  • maintain and test backups
  • document who to contact after an incident

These controls may also be relevant to an insurer's questions or policy conditions. Answer applications accurately and tell the adviser if the setup changes.

Prepare an incident contact list

Keep the policy number and insurer's incident contact process with the business continuity plan. Add the contacts for IT support, banking, legal advice and key business decision makers.

Staff should know who can authorise urgent recovery work. Check whether the insurer requires contact before costs are incurred, except where immediate action is needed to prevent further harm.

Take your current security and backup details to the insurance conversation, not assumptions. If you cannot show which controls are working, contact JCPIT for a security and backup review. We will document the technical gaps for you to discuss with your licenced insurance adviser.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
The home office security checklist every boss needs
Next Article →
How to respond to a fake Google review scam