Start with the purpose of the coverage
Cyber policies can combine first-party response expenses with third-party liability protection. Coverage varies materially in its treatment of ransomware, social engineering, business interruption, vendors, and security controls.
Accurate schedules and values
Connect this decision to the insured operation, credible loss scenarios, current information, policy wording, and requested protection.
Current operations and contracts
Connect this decision to the insured operation, credible loss scenarios, current information, policy wording, and requested protection.
Loss history and requested terms
Connect this decision to the insured operation, credible loss scenarios, current information, policy wording, and requested protection.
What the policy may help address
Incident response and breach expenses
Confirm covered causes, insured parties, locations, limits, deductibles, conditions, and exclusions in the actual proposal and issued policy.
Network interruption and data restoration
Confirm covered causes, insured parties, locations, limits, deductibles, conditions, and exclusions in the actual proposal and issued policy.
Privacy and network security liability
Confirm covered causes, insured parties, locations, limits, deductibles, conditions, and exclusions in the actual proposal and issued policy.
Details to examine for this decision
- Multifactor authentication, backups, endpoint controls, and staff training
- Waiting periods, sublimits, coinsurance, and vendor-dependent interruption
- Ransomware, funds transfer, regulatory, and contractual exposures
Information to prepare
A complete submission helps distinguish the account and reduces avoidable follow-up. Prepare current records rather than relying on estimates from a prior policy period.
- Security-control and backup details
- Record counts, payment activity, and revenue
- Prior incidents, vendors, and business-continuity procedures
Questions the review should answer
How does the program address multifactor authentication, backups, endpoint controls, and staff training?
Document the answer in the proposal, applicable forms, endorsements, schedules, or written underwriting confirmation. Do not rely only on a certificate or marketing summary.
How does the program address waiting periods, sublimits, coinsurance, and vendor-dependent interruption?
Document the answer in the proposal, applicable forms, endorsements, schedules, or written underwriting confirmation. Do not rely only on a certificate or marketing summary.
How does the program address ransomware, funds transfer, regulatory, and contractual exposures?
Document the answer in the proposal, applicable forms, endorsements, schedules, or written underwriting confirmation. Do not rely only on a certificate or marketing summary.
Frequently asked questions
What should a business prepare for a Cyber Liability quote preparation checklist review?
Useful starting information includes security-control and backup details, record counts, payment activity, and revenue, prior incidents, vendors, and business-continuity procedures. The specialist may request additional details based on the operation and available insurance markets.
Why should Cyber Liability be reviewed separately from other policies?
Cyber policies can combine first-party response expenses with third-party liability protection. Coverage varies materially in its treatment of ransomware, social engineering, business interruption, vendors, and security controls. The policy should also be coordinated with related property, liability, vehicle, people, contract, and continuity exposures.
Coverage descriptions are general and do not amend a policy. Eligibility, availability, limits, deductibles, exclusions, definitions, and terms vary by risk and insurance market. Actual policy documents control.
