Cyber Insurance: What Attorneys Should Advise Their Clients
Why Cyber Insurance Can No Longer Be an Afterthought
Data breaches, ransomware attacks, and business-email-compromise schemes have moved from headline curiosities to routine operational risks. For clients across industries—healthcare, finance, retail, professional services—the question is no longer whether to consider cyber insurance but how to evaluate, negotiate, and actually use a policy when the worst happens.
As trusted advisors, attorneys are increasingly expected to weigh in on coverage decisions, contract language, and incident-response obligations. This guide distills what you need to know to serve those clients well.
Understanding the Core Coverage Components
Cyber policies vary significantly by carrier, but most share a recognizable structure. Help clients evaluate each layer:
First-Party Coverage
This reimburses the policyholder directly for losses the organization suffers:
- Business interruption – Revenue lost when systems go offline
- Data restoration costs – Expenses to rebuild or recover corrupted data
- Ransomware payments and negotiation fees – Some (not all) policies cover extortion payments and the forensic negotiators who manage them
- Notification and credit-monitoring costs – Regulatory and statutory obligations can generate significant expense
- Crisis communications and PR – Reputational damage control after a public incident
Third-Party (Liability) Coverage
This covers claims made against the insured by customers, regulators, or other third parties:
- Privacy liability – Claims alleging unauthorized disclosure of personal information
- Network security liability – Claims that a client's compromised system caused harm to another party
- Regulatory defense and fines – Defense costs (and, where insurable by law, penalties) arising from regulatory investigations
- Media liability – Defamation or intellectual-property claims arising from digital content
Key Policy Terms Attorneys Must Scrutinize
Policy language is where coverage is won or lost. Advise clients to pay close attention to:
Retroactive Dates and Discovery Periods
Many cyber policies are written on a claims-made-and-reported basis. If a breach occurred before the retroactive date or was reported outside the discovery window, coverage may be denied. Counsel clients to confirm that retroactive dates align with when their digital operations began—or at least with the inception of prior coverage.
The "Waiting Period" in Business Interruption
Most BI sub-limits include a retention period (often 8–12 hours) before coverage kicks in. A short outage may never trigger the policy. Clients should understand this threshold and model whether it realistically matches their risk profile.
War and Nation-State Exclusions
Several high-profile coverage disputes have centered on whether a cyberattack constituted an act of "war." Carriers increasingly include nation-state or war exclusions. Advise clients to request manuscript language that narrows this exclusion—or at minimum, to understand exactly what is excluded.
Systems Not Owned or Operated Exclusions
Cloud environments, SaaS platforms, and third-party vendors are where many breaches originate. Some policies exclude losses arising from systems the insured does not own or operate. Clients who rely heavily on third-party technology need explicit confirmation of whether vendor-caused incidents are covered.
Social Engineering and Funds-Transfer Fraud
Business-email-compromise losses—where an employee is tricked into wiring money—are frequently subject to sublimits or separate endorsements. These should never be assumed to be covered under the main limit.
Advising Clients During the Application Process
The underwriting application is a legal document. Misrepresentations, even negligent ones, can void a policy at the worst possible moment. Attorneys should counsel clients to:
- Treat the application as a legal instrument – Review it with the same rigor applied to a contract.
- Conduct a pre-application security audit – Many carriers now ask detailed questions about multi-factor authentication (MFA), endpoint detection, patch management, and data backup practices. Clients should verify their answers with IT before submitting.
- Document security controls – Written policies and logs support both the application and post-incident claims.
- Disclose known vulnerabilities – Failing to disclose a known weakness that later causes a loss is precisely the scenario carriers cite when rescinding policies.
Coordinating Cyber Coverage with Other Policies
Cyber incidents rarely stay neatly inside a single policy silo. Attorneys advising clients on risk management must map how cyber coverage interacts with:
- Commercial general liability (CGL) – Traditional CGL policies often exclude data-related losses. Do not assume CGL fills any gaps.
- Errors and omissions (E&O) – Technology companies and professional-services firms may face cyber-related malpractice claims that straddle E&O and cyber coverage.
- Crime policies – Funds-transfer fraud may be covered under a crime policy, a cyber policy endorsement, or neither; determine which before a loss occurs.
- Directors and officers (D&O) – Regulatory investigations following a breach can generate shareholder derivative actions covered under D&O.
The goal is a coverage map that closes gaps and eliminates costly disputes over which policy applies first.
Post-Incident: What Clients Need to Know Before a Breach Happens
The time to understand a cyber policy is well before an incident occurs. Walk clients through these pre-breach essentials:
- Locate the incident-response hotline number and save it offline – System access may be unavailable during an attack.
- Understand notice obligations – Most policies require prompt (sometimes 24- to 72-hour) notice. Late notice is a routine basis for coverage disputes.
- Know the approved-vendor panel – Many carriers require policyholders to use carrier-approved forensic firms, counsel, and PR consultants. Engaging outside vendors without authorization can jeopardize reimbursement.
- Preserve evidence – Advise clients never to wipe or reimage systems before a forensic team has been authorized, as this can undermine both the claim and any subsequent litigation.
Practical Takeaways for Counsel
Cyber insurance is a contract, and contracts require legal review. Attorneys who help clients select, negotiate, and properly use cyber coverage provide a measurable service that goes well beyond general risk advice. The key is developing enough familiarity with policy structure to ask the right questions—of the broker, the carrier, and the client's own IT team.
The most effective posture is proactive: review policies at renewal, benchmark coverage limits against peer organizations, and ensure that the incident-response plan and the insurance policy reference each other explicitly. When a breach does occur, that groundwork will be the difference between a smooth claim and an expensive coverage dispute.