A cyber incident does not generate one cost, it generates three at once, and they arrive at different
moments. The first is the stoppage: while the systems are down, the company does not invoice. The
second is the response: forensics, legal advice, communication, restoration. The third arrives weeks
or months later, when the affected third parties claim. A cyber policy is built around that sequence,
which is why it is bought in blocks rather than under a single limit.
What orders those three blocks is not the technology, it is the legal calendar.
The clock is set by the GDPR, not by the insurer
Article 33.1 of the General Data Protection Regulation
requires a personal data breach to be notified to the supervisory authority within 72 hours of
becoming aware of it, unless it is unlikely to result in a risk to the rights and freedoms of natural
persons. Where the risk to data subjects is high, article 34 also requires communicating it to them
without undue delay.
That deadline runs from awareness of the incident, not from the decision to act, and drafting the
notification requires already knowing what happened and how many people it affects. Which is why the
section of the policy used most is not the indemnity, but immediate access to a forensic team and to
a specialist law firm.
It is also worth separating two penalty tiers that are commonly conflated. Failing to notify is
penalised under article 83.4: up to €10 million or 2% of total worldwide annual turnover, whichever
is higher. Breaching the principles of processing or the rights of data subjects falls under article
83.5, which raises the ceiling to €20 million or 4%. The full treatment is in
what to do after a data breach.
Why through a broker
As a brokerage registered with the Spanish insurance regulator, the Dirección General de Seguros y
Fondos de Pensiones, under reference J0140, New Brokers acts on the client's mandate. In cyber that
comes down to two moments.
The first is the underwriting questionnaire. Unlike other classes, here the insurer does not rate on
historical claims but on the controls you declare you have, and that declaration becomes part of the
contract. Reviewing it with technical judgement before signing avoids the most frequent declinature
in the class.
The second is comparing wordings, which in cyber is unusually uneven: the definition of an incident,
the real scope of the response service, the time deductible on interruption and the drafting of the
cyber warfare exclusion vary so much between carriers that two policies at the same price can cover
very different things. The section-by-section comparison is in
what cyber insurance covers.