Area of cover · 03

Cyber insurance

A cyber incident sends three bills at once: the cost of stopping, the cost of responding, and the cost of answering to third parties. The policy is built around those three, not around one.

01Overview

What it is

Cyber insurance is not one cover but three bought together. First-party loss answers for what the incident costs you: restoring data and systems, the margin you do not earn while you are not producing, and the payment of an extortion demand if you decide to face it. Third-party liability answers for what is claimed from you afterwards: by clients, suppliers and the people whose data was exposed. And the response services cover the work of the first hours: forensics, legal advice and communication.

In practice, the block used most often is the third. A mid-sized company has no forensic team on call and no data protection law firm available on a Sunday night, and the GDPR clock starts running from the moment you become aware of the incident, not from the moment you decide to act. That immediate access is usually worth more than the policy's indemnity limit.

Request a review of your cover

Speak to a technical adviser: 932 419 400

At a glance

Deadline to notify the authority
72 hours
Maximum GDPR fine
€20m or 4%
Scope
Domestic and international
Broker registered with the DGSFP
J0140

A cyber incident does not generate one cost, it generates three at once, and they arrive at different moments. The first is the stoppage: while the systems are down, the company does not invoice. The second is the response: forensics, legal advice, communication, restoration. The third arrives weeks or months later, when the affected third parties claim. A cyber policy is built around that sequence, which is why it is bought in blocks rather than under a single limit.

What orders those three blocks is not the technology, it is the legal calendar.

The clock is set by the GDPR, not by the insurer

Article 33.1 of the General Data Protection Regulation requires a personal data breach to be notified to the supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to the rights and freedoms of natural persons. Where the risk to data subjects is high, article 34 also requires communicating it to them without undue delay.

That deadline runs from awareness of the incident, not from the decision to act, and drafting the notification requires already knowing what happened and how many people it affects. Which is why the section of the policy used most is not the indemnity, but immediate access to a forensic team and to a specialist law firm.

It is also worth separating two penalty tiers that are commonly conflated. Failing to notify is penalised under article 83.4: up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Breaching the principles of processing or the rights of data subjects falls under article 83.5, which raises the ceiling to €20 million or 4%. The full treatment is in what to do after a data breach.

Why through a broker

As a brokerage registered with the Spanish insurance regulator, the Dirección General de Seguros y Fondos de Pensiones, under reference J0140, New Brokers acts on the client's mandate. In cyber that comes down to two moments.

The first is the underwriting questionnaire. Unlike other classes, here the insurer does not rate on historical claims but on the controls you declare you have, and that declaration becomes part of the contract. Reviewing it with technical judgement before signing avoids the most frequent declinature in the class.

The second is comparing wordings, which in cyber is unusually uneven: the definition of an incident, the real scope of the response service, the time deductible on interruption and the drafting of the cyber warfare exclusion vary so much between carriers that two policies at the same price can cover very different things. The section-by-section comparison is in what cyber insurance covers.

02Covers

What is covered

  • Incident management and response

    Access to a response team from the moment the incident is detected. It is the section used most often and the one that determines the quality of the first forty-eight hours.

  • Forensic investigation

    The technical work that establishes what happened, how they got in, which data was affected and how many people. Without that, the notification the law requires cannot be drafted.

  • Legal advice and regulatory notification

    The legal support needed to decide and document whether the supervisory authority must be notified, and whether the risk to data subjects requires telling them too.

  • Restoration of data and systems

    The cost of rebuilding the information and returning systems to their previous state. It covers restoration, not improvement: anything installed above the prior state is for your own account.

  • Business interruption loss

    The margin you do not earn while operations are down, plus the additional costs incurred to keep working. The deductible here is agreed in hours.

  • Cyber extortion and ransomware

    Managing the extortion, advising on the negotiation and, where the policy provides for it and the applicable law permits, paying the ransom.

  • Data breach liability

    Claims from clients, employees or third parties whose personal data has been compromised, including group actions.

  • Legal defence and administrative fines

    The costs of defending an enforcement procedure and, where they are legally insurable, the fines imposed. Their insurability depends on the jurisdiction.

  • Impersonation fraud and fraudulent transfer

    A payment diverted after someone impersonates a director or a supplier. It is bought as an express section and usually carries its own sub-limit and verification requirements.

  • Crisis communication

    Professional support to hold a consistent message before clients, employees, the media and the authority itself while the incident lasts.

03Limits

Limits and deductible

Deadlines and fines set by the GDPR
Obligation or penaltyWhat the regulation provides
Notification to the supervisory authority (art. 33.1)72 hours from becoming aware
Communication to data subjects (art. 34.1)Without undue delay, where the risk is high
Failure to notify a breach (art. 83.4)Up to €10m or 2% of global turnover
Breach of principles and rights (art. 83.5)Up to €20m or 4% of global turnover
Business interruption deductibleAgreed in hours, not in euros

The deadlines and amounts in this table are those set by the General Data Protection Regulation and operate as a legal obligation and as maximum penalties, not as the terms of any policy. In both penalties the higher of the fixed amount and the percentage applies. The scope of each section, and whether a fine is insurable at all, are governed in every case by the specific conditions of each policy and by the applicable jurisdiction.

New cover

Request a proposal and terms

We analyse your activity and your real exposure before approaching the market.

Request a proposal

Existing client

Download your certificate

Your certificates, policies and requests are available in the client area.

Go to the client area
04Scope

What is not covered

The exclusions in a cyber policy concentrate on one point: the insurer accepts the unforeseen incident, not the known weakness left uncorrected.

  • Incidents that exploit known vulnerabilities left unpatched, or systems no longer supported by the manufacturer. This is the exclusion behind most declined claims.

  • Failure to maintain the security measures the insured declared at inception. The underwriting questionnaire forms part of the contract.

  • Wilful or fraudulent acts by the insured itself or by its management.

  • Cyber warfare and acts attributable to a state, with wordings that vary widely between carriers and deserve to be read one by one.

  • Widespread failure of public internet infrastructure or of the electricity supply, unless expressly covered.

  • Improving systems beyond the state they were in before the incident.

  • The lost value of intellectual property or of a misappropriated trade secret, as distinct from the cost of responding to the incident.

  • Reputational harm as a stand-alone concept, where the crisis communication section has not been bought.

  • Fines that the applicable jurisdiction declares uninsurable.

05Use cases

When you will be asked for it

  1. Ransomware that halts production

    Mass encryption leaves the management and plant systems inoperative. The company can restore from backup, but a full restoration will take days and production is stopped.

    What it means

    Three sections operate at once: incident management to contain and decide, restoration of data, and business interruption for the downtime. The time deductible on the last of these determines from what hour the indemnity starts to run.

  2. A breach of client data

    Unauthorised access exposes the personal data of thousands of clients. The scope must be established, the notification decision taken, and the communication prepared within a very short window.

    What it means

    Forensics fixes the facts, legal advice decides and documents the notification, and the liability section answers for the claims that follow. A decision not to notify must also be documented: the absence of any assessment is itself a breach.

  3. Fraudulent transfer through impersonation

    An email imitating a director or a regular supplier persuades the finance department to change bank details and release a payment.

    What it means

    There is no technical intrusion here and no data breach: there is a deception. This loss is only covered if the specific impersonation fraud section has been bought, which the base policy does not include by default.

06Process

How it is arranged

  1. Assessing the digital exposure

    We review what data you process, on how many people, how operationally dependent you are on your systems, and what would happen to turnover if they stopped for a day, for three, or for a week.

  2. Reviewing the underwriting questionnaire

    This is the critical point. What is declared about backups, authentication, network segmentation and patching conditions the cover, and an imprecise declaration turns into a declined claim.

  3. Placement and comparison of wordings

    We compare the definition of an incident, the real scope of the response service, the time deductible on interruption and the drafting of the cyber warfare exclusion, not just the limit and the premium.

  4. Activation and support during an incident

    We give you the alert protocol so the team knows who to call in the first hour, and we represent you before the insurer while the claim is being handled.

How we work
08Common questions

Frequently asked questions

Does cyber insurance cover paying a ransomware demand?

Many policies include a cyber extortion section, covering advice on the negotiation and, where the wording provides for it, payment of the ransom. It is not automatic: it depends on the section having been bought, on following the protocols the insurer requires, and on the payment being lawful under the applicable rules, including international sanctions lists. The precise scope is governed by the specific conditions of each policy.

How long is there to notify a data breach?

Article 33.1 of the General Data Protection Regulation sets a deadline of 72 hours from the moment the controller becomes aware of the security breach, unless it is unlikely to result in a risk to people's rights and freedoms. Where notification is later than that, it must be accompanied by the reasons for the delay. Where the risk to data subjects is high, article 34 also requires telling them without undue delay.

Does the policy cover GDPR fines?

It depends on the jurisdiction and on the wording. Many policies offer cover for administrative fines wherever they are legally insurable, and in every case cover the costs of defending the procedure. Two tiers are worth distinguishing: failing to notify a breach is penalised under article 83.4, up to €10 million or 2% of total worldwide annual turnover; breaching the principles of processing or the rights of data subjects falls under article 83.5, up to €20 million or 4%. In both cases the higher figure applies.

Does NIS2 require buying cyber insurance?

No. Directive (EU) 2022/2555, known as NIS2, does not require insurance to be bought. What it does is raise risk management requirements and reinforce the responsibility of the management bodies of the entities within its scope. That heavier duty on management is what connects cyber risk to the D&O policy.

Why is the questionnaire so detailed?

Because in cyber, underwriting is done on controls rather than on past claims. What you declare about backups, multi-factor authentication, network segmentation and patching becomes part of the contract. An imprecise declaration does more than raise the premium: it becomes the reason a claim is declined. Going through that questionnaire carefully is part of our job.

What information do you need to prepare a proposal?

A description of your infrastructure and critical services, the volume and type of personal data you process, annual turnover, the detail of your security measures and backup policy, and, if you have one, the current policy with its specific conditions and the questionnaire that was completed.

Related analysis

This information is for guidance only and is not binding. Covers, limits and exclusions are governed in all cases by the specific terms of each policy. New Brokers Correduría de Seguros, S.L., registered with the DGSFP under reference J0140.