Ciberriesgo

Cyber insurance for companies: what it covers

Cyber insurance for companies: what it covers
CiberriesgoJul 25, 2026·New Brokers

In brief. Cyber insurance —also called cyber risk insurance— protects the company against the consequences of a cyberattack. It covers two blocks: first-party losses (data and systems restoration, loss of profit from interruption, incident management and cyber extortion) and third-party liability (claims arising from a data breach, legal defence and, where insurable, administrative fines). It is needed by any organisation that processes data or relies on IT systems. Its scope and exclusions are governed by each policy.

What is cyber insurance?

Every company that invoices, produces or provides a service now depends on its IT systems and on the data it manages. When those systems go down —through ransomware, a leak or a fraud— activity stops and legal liability appears immediately. Cyber insurance for companies is the instrument that transfers much of that economic impact to the insurance market.

One terminological point is worth clearing up from the outset: "cyber insurance" and "cyber risk insurance" designate exactly the same cover. "Cyber cover" or "insurance against cyberattacks" are also used. They are not different products, but commercial names for the same line. In this article we use them interchangeably.

Unlike traditional property insurance, cyber cover does not respond solely to material harm. Its value lies in bringing together, within a single programme, the technical response to the incident, business continuity and the legal defence against the claims that follow. It is as much a crisis-management insurance as an indemnity one.

Does your company critically depend on its systems? Request a review of your cyber exposure with no obligation and we will assess which programme fits your activity.

What exactly does cyber risk insurance cover for a company?

A cyber risk policy is structured in two large blocks. The first protects the company itself; the second, its liability towards those who are harmed.

First-party losses. These cover the harm suffered directly by the insured company:

  • Data and systems restoration: the cost of recovering, rebuilding or decontaminating the affected information and infrastructure.
  • Loss of profit from business interruption: the lost earnings during the period in which activity is halted by the incident.
  • Cyber extortion and ransomware: incident management and, where applicable, the response to the ransom demand, under the conditions set out below.
  • Incident management: forensic analysis to determine the origin and scope, notification of those affected and of the supervisory authority, crisis communication to preserve reputation, and 24/7 legal assistance from the first hour.

Third-party liability. This covers the claims of those harmed by the incident:

  • Claims arising from a data breach: compensation to clients, suppliers or third parties whose personal or confidential data has been compromised.
  • Legal defence: the cost of lawyers and proceedings against civil claims and administrative files.
  • Administrative fines: handling and, where legally insurable, cover for the fines imposed by the data protection authority.

In every case, the exact scope of each cover, its limits and sub-limits are governed by the terms of each policy and company. Not all insurers offer the same covers or with the same breadth. This is precisely where comparing the market makes the difference; you will see it in detail in our cover areas for large accounts.

Does cyber insurance cover a ransomware attack and the ransom?

This is the most frequently asked question, and it deserves a careful qualification. Many policies include a cyber-extortion cover, which can be triggered by a ransomware attack. That cover, however, is not the equivalent of an automatic cheque to pay the ransom.

In practice, the cover is usually structured as follows: the insurer makes available a crisis-management team and specialised negotiators, assesses the situation and determines the response. Any eventual payment requires the company's prior authorisation, is subject to the limits arranged and, above all, to the applicable legal restrictions. In certain jurisdictions, payment to certain actors may be prohibited —for example, where the attacker appears on international sanctions lists— and no policy covers an unlawful payment.

That is why the value of the cover lies less in reimbursing the ransom than in the professional management of the incident: restoring systems from backups where feasible, containing the damage and deciding on sound technical and legal grounds. The exact scope depends, once again, on each policy and jurisdiction.

Have you assessed your exposure to ransomware? Let us discuss your situation. We compare the market for you before recommending a structure.

The threats that drive companies to buy cover

Cyber cover is not arranged in the abstract: it responds to a map of concrete and growing threats. The four that most frequently drive the decision are:

  • Ransomware: encryption of the company's systems in exchange for a ransom, with total paralysis of activity until recovery.
  • Data breach or leak: exposure or theft of personal or confidential data, with the ensuing duty to notify and the possible claims of those affected.
  • CEO fraud (BEC): impersonation of an executive or supplier to induce fraudulent transfers, a rising form of social engineering.
  • Business interruption: the failure of systems —the company's own or those of a technology supplier— that halts operations and generates lost earnings.

Reference bodies such as INCIBE in Spain and the European agency ENISA have been pointing out, in their periodic reports, the upward trend of these incidents and their growing sophistication, both in frequency and in impact on the business fabric. We do not handle specific figures here because they vary each year and each report; the relevant message is structural: exposure is growing, not shrinking.

What does it not cover? Common exclusions

Like any insurance, cyber risk cover has limits. Knowing them in advance avoids false expectations at the worst moment. Among the most common exclusions are:

  • Unpatched systems or known, uncorrected vulnerabilities: if the incident exploits a security weakness the company was aware of and failed to address, cover may be affected.
  • Wilful acts of the insured itself: fraud or intentional conduct by the company or its senior staff falls outside the cover.
  • Cyber warfare and acts of State: attacks attributable to warlike operations or to States are usually excluded, although the treatment of these clauses —and their nuances— is the subject of intense evolution in the market.
  • Reputational harm without specific cover: loss of brand value is only covered to the extent that the policy includes an express crisis-management and communication cover.

The detail of each exclusion is governed by the terms of each policy. Reading the wording with technical judgement —and negotiating the removal or qualification of certain exclusions— is part of an independent broker's work.

YMYL note. There is no standard cyber risk policy nor identical cover across companies. The real scope depends on the specific wording and on your company's profile. We assess your case before recommending a route.

Which companies need cyber insurance?

The short answer: any organisation that processes personal data or relies on IT systems to operate. That is, almost all of them. There are, however, profiles with a particularly high exposure:

  • E-commerce and digital retail: they manage large volumes of client data and payment methods.
  • Healthcare and clinics: they process special-category data and are a frequent target of ransomware.
  • Industry with OT environments: the convergence of information and operational technology exposes production chains.
  • Professional services: firms, engineering practices and consultancies hold confidential third-party information.
  • Multinationals and large accounts: because of their attack surface and their cross-border liability.

It is worth noting that cyber insurance is not mandatory by law as a general rule. What has changed the framework is the NIS2 Directive (EU 2022/2555), which raises cybersecurity requirements for entities considered essential and important in certain sectors. NIS2 does not impose arranging insurance, but it does reinforce management's liability and risk-management obligations, a context in which cyber cover fits naturally.

That liability of directors and officers connects with another line: a poorly managed cyber incident can lead to claims against senior managers, covered by D&O insurance. And the duty to notify a leak is governed by data protection law, which we address in our guide on data breaches and the GDPR.

The role of an independent broker

Cyber risk is probably the line where covers, exclusions and each insurer's appetite vary the most. Two policies with the same name can offer very different protection. This is where an independent broker adds value: it does not sell a specific product but compares the market for you, negotiates the wording and sizes the limits according to your real exposure.

We work under the client's mandate, with access to the whole market —including London and Lloyd's, very active in cyber risk— and with defence at your side in the event of a claim. You will find where this line fits within our full range of cover areas for large accounts.

Does your company lack a cyber programme or doubt how far it reaches? Request an analysis of your exposure. We compare the market for you.

Frequently asked questions

Is cyber insurance mandatory? The law does not require it as a general rule. The GDPR and the NIS2 Directive do so indirectly, raising companies' liability and security requirements for certain sectors. In practice it is arranged as a risk-management tool, not by legal obligation. The exact scope is governed by each policy.

Does cyber insurance cover the ransom payment in a ransomware attack? Some policies include a cyber-extortion cover, which may extend to incident management and, where legally permissible, the payment itself. It is subject to conditions, the insurer's prior authorisation and limits, and the payment may face legal restrictions depending on the jurisdiction. It is governed by each policy.

Does it cover GDPR fines? Only where administrative fines are legally insurable. The policy usually covers legal defence and the handling of the sanction proceedings; the insurability of the fine itself depends on the jurisdiction and the terms of each contract.

Do only large companies need it? No. Any company that processes personal data or relies on IT systems is exposed to a cyberattack. What changes with size and sector is how the programme is sized: limits, sub-limits and covers are adjusted to each company's exposure profile.

Sources and regulations

  • Regulation (EU) 2016/679 (GDPR) — General Data Protection Regulation.
  • Spain's Organic Law 3/2018 of 5 December (LOPDGDD) — protection of personal data and safeguarding of digital rights.
  • Spanish Data Protection Agency (AEPD) — supervisory authority for data protection.
  • Directive (EU) 2022/2555 (NIS2) — measures for a high common level of cybersecurity across the Union.
  • National Cybersecurity Institute (INCIBE) — technical reference and threat analysis.

New Brokers is an independent insurance broker registered with the DGSFP under code J0140. This content is for guidance only and does not constitute binding advice; cover, guarantees and terms are governed by each policy and company. We work under the client's mandate, with access to the whole market —including Lloyd's— and defence in the event of a claim.

Do you need to protect your company against a cyberattack? Request an analysis of your cyber exposure. We compare the market for you.

Related articles

Let's talk

Does your insurance programme cover this risk?

As an independent brokerage, we analyse your current portfolio and advise you with no obligation, with access to the whole insurance market.

Request a review