Cyber insurance
Insurance for cyber incidents. Read what it actually covers.
Please note: This page explains what a term means. It is general information, not legal, financial, tax or investment advice, and it does not know anything about your business. Before you sign, file or commit to anything, check it with an accountant, a solicitor, or the official guidance we link to.
What it means
Cyber insurance typically covers incident response, data recovery, business interruption, notification costs, and sometimes ransom payments and third-party liability.
Why it matters
The incident response element is often the most valuable part: access to forensics, legal and PR support within hours, at a moment when you do not know who to call.
What it looks like in practice
Insurers increasingly require baseline controls — multi-factor authentication, backups, patching — as a condition, and will check after a claim.\n\nNotification conditions are strict and short.
What to watch out for
Assuming you are covered without checking. Common exclusions include unpatched systems, social engineering losses, and incidents where required controls were absent.
Where to get proper advice
A broker who places cyber specifically. The NCSC has guidance on what to look for.
Where to read more
Last reviewed 2026-08-28 by Fiducia Together · Next review due 2027-08-28
Please note: This page explains what a term means. It is general information, not legal, financial, tax or investment advice, and it does not know anything about your business. Before you sign, file or commit to anything, check it with an accountant, a solicitor, or the official guidance we link to.
Fiducia Together