Cyber Insurance Coverage: What It Pays for After a Hack
What does cyber insurance pay for after ransomware or a data breach? See what's covered, what's not, and how to prepare your small business.
Will Cyber Insurance Actually Pay If We Get Hacked?
Maybe. It depends on what you bought, what the fine print requires you to have in place before the attack, and whether you can prove you had it. A lot of Upstate SC manufacturers and retailers carry a policy, get hit with ransomware, file a claim — and find out the insurer is disputing it line by line. Cyber insurance is real coverage that pays real claims. It's also one of the most misunderstood products a small business buys. The exclusions matter as much as the coverage.
What does a typical policy actually cover?
Most small-business cyber policies bundle a handful of things under one premium:
- Incident response costs, the forensic firm that figures out what happened, contains it, and gets you back running. Usually the biggest line item.
- Ransom negotiation and payment. Many policies will pay a ransom or fund a negotiator, though some carriers are pulling back on this as regulators scrutinize it.
- Data breach notification and credit monitoring. If customer or employee data was exposed, you're legally required to notify people in most states, and that costs money per record.
- Business interruption, lost income while systems are down, sometimes including lost profit from a shut POS system or halted production line.
- Third-party liability. A customer or vendor sues you because their data was compromised through your systems, or because your breach disrupted their supply chain.
- Legal and regulatory defense. Attorneys, and in some cases fines, depending on the industry and state.
That's the sales brochure version. The claim department reads a different document.
What gets a claim denied?
The exclusions are where the real risk sits. This is the part most owners never read until they need to.
Failure to maintain "reasonable security." Almost every policy has a clause requiring you to maintain basic controls, patched systems, multi-factor authentication, endpoint protection, sometimes a written incident response plan. If the attacker got in through an unpatched server or a login with no MFA, the insurer can argue you misrepresented your security posture on the application, and deny the claim on that basis alone.
Social engineering carve-outs. Wire fraud and business email compromise, someone impersonates a vendor and gets your AP clerk to send a payment to the wrong account, are often excluded or capped at a much lower sublimit than the headline policy number. If your biggest cyber risk is actually a spoofed invoice email, not ransomware, read your sublimits carefully.
Acts of war / nation-state exclusions. Several major ransomware groups have suspected ties to state actors. Insurers have used "act of war" language to deny claims tied to attacks attributed to nation-state groups, even against small businesses that were never a specific target.
Unpatched known vulnerabilities. If the forensics firm finds the entry point was a vulnerability that had a patch available for months, some policies treat that as a failure of due diligence, not a covered loss.
Prior knowledge. If you knew about a weakness, an old server nobody replaced, a flagged finding from a previous assessment, and didn't fix it, that's grounds for denial too.
None of this is unique to small companies. It's the same reason larger companies with dedicated security teams still get claims disputed. The difference is a 30-person manufacturer usually doesn't have anyone whose job is to read the policy exclusions against their actual IT environment, until after the incident.
Why is this showing up in supply-chain questionnaires now?
If you supply to Michelin, Cummins, or any of the automotive and aerospace primes in the Upstate, you've probably already seen a security questionnaire asking for proof of cyber insurance, minimum coverage limits, and evidence of specific controls, MFA, endpoint detection, incident response planning. Larger customers are pushing this requirement down their supply chain because their own insurers and auditors are pushing it up to them. A "yes, we have a policy" answer used to be enough. Increasingly it isn't. They want to see the controls that make the policy valid, not just the policy number. If you're filling out one of these questionnaires and aren't sure your answers hold up, it's worth having someone look at both the supply-chain security questionnaire itself and what a real penetration test would find if a customer's auditor asked for one.
What should you actually do about it?
Read the application you signed, not just the policy summary. The insurer's coverage decision after a breach is measured against the answers you gave when you applied. Say "yes, we have MFA everywhere" and that turns out untrue, and that gap is now the insurer's argument for denying you. Go back and verify every "yes" on that application is still accurate today, not when you signed it two years ago.
Get the baseline controls in place before you need the payout, not after. MFA on email and remote access, endpoint protection that's actually monitored, patching on a real schedule, and a written incident response plan are the four things underwriters ask about most. They're also the four things that get claims denied when missing. This is the same baseline that shows up on customer supply-chain questionnaires, fixing it serves both purposes at once.
Know your sublimits, especially for wire fraud. Ask your broker specifically: what's the sublimit for social engineering and funds transfer fraud, separate from the main ransomware coverage? If it's low or absent, decide whether you need a rider.
Understand what "business interruption" actually measures. Some policies pay based on your prior-year revenue; others require you to prove lost profit, which is harder and slower. If your POS system going down for two days is a real dollar number to you, know how the policy calculates that number before you need it. Retailers relying on card terminals should look at this alongside their PCI and POS uptime exposure generally.
If you don't have a plan for the first hour of an incident, that's the gap insurance can't fill. A policy pays for cleanup. It doesn't stop the ransomware from spreading to your second server while you're on hold with the carrier's hotline. Response speed still comes down to whether someone is watching your systems and can act, a managed IT and monitoring question, not an insurance question.
Cyber insurance is worth having. Just don't treat the premium as the whole answer. The controls underneath it are what make the payout real. If you're not sure where your policy and your actual environment disagree, that's a conversation worth having before a claim, not during one, reach out and we'll walk through it with you.