What cyber insurance covers
Cyber policies are built in two halves. First-party sections respond to the insured's own costs when an incident occurs. Third-party sections respond to claims made against the insured by other people as a result of that incident. Most organisations underestimate the first half, because the immediate cost of responding to a serious incident - forensics, legal advice, notification, credit monitoring, system restoration and lost trading - usually arrives long before any third party sues.
The distinction matters when limits are set. A single sub-limit for incident response costs can be exhausted within days of a significant ransomware event, leaving the balance of the policy limit intact but unavailable for the work that actually needs doing. The structure of the limit deserves as much attention as its size.
It is also worth being clear about what cyber insurance is not. It is not a substitute for security controls, and increasingly it is not available without them. It does not respond to the cost of upgrading systems that were inadequate before the incident. And it does not remove the regulatory duties that follow a compromise of personal information.
The sections a cyber policy typically contains:
- Incident response - forensic investigation, legal advice, breach counsel and public relations support.
- Data restoration - the cost of recovering or recreating data and reconfiguring systems.
- Business interruption - loss of income and increased cost of working during system unavailability.
- Cyber extortion - ransom negotiation, specialist advisers and, where lawful, payment.
- Notification costs - notifying data subjects and the Information Regulator, and monitoring services where appropriate.
- Privacy liability - third-party claims arising from the compromise of personal or confidential information.
- Network security liability - claims arising from the transmission of malware or a failure of network security.
- Regulatory defence - the cost of responding to an Information Regulator enforcement process, and insurable fines where the law permits.
- Funds transfer fraud and social engineering - usually a modest sub-limit, often confused with a full crime section.
POPIA: the duty that turns an incident into a regulatory event
The Protection of Personal Information Act 4 of 2013 is what converts a technical incident into a legal one. Section 19 requires a responsible party to secure the integrity and confidentiality of personal information in its possession by taking appropriate, reasonable technical and organisational measures - which includes identifying reasonably foreseeable internal and external risks, establishing and maintaining safeguards against them, verifying that those safeguards are effectively implemented, and updating them in response to new risks.
Section 22 sets out what must happen when those safeguards fail. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovery. There is no materiality threshold in the section. Notification may be delayed only where a public body responsible for detection or prevention of offences, or the Regulator, determines that notification would impede a criminal investigation.
The notification to data subjects must be in a prescribed manner and must provide sufficient information to allow them to take protective measures - including a description of the possible consequences, the measures the responsible party intends to take, a recommendation on what the data subject can do, and, if known, the identity of the unauthorised person. Section 21 adds a further layer for outsourced processing: the responsible party must have a written contract with its operator, and the operator must notify the responsible party immediately where there are reasonable grounds to believe personal information has been compromised.
Enforcement carries real consequence. The Regulator may issue an enforcement notice, and failure to comply with an enforcement notice is an offence. Administrative fines of up to R10 million may be imposed, and certain offences under the Act carry fines or imprisonment. Whether a regulatory penalty is insurable is a matter of law and policy wording and cannot be assumed.
Source: Protection of Personal Information Act 4 of 2013, sections 19 (security measures), 21 (operators), 22 (notification of security compromises), 107 and 109 (penalties and administrative fines).
The controls underwriters now require
Cyber underwriting changed materially after the ransomware losses of the early 2020s. Insurers moved from rating on turnover and industry to rating on demonstrated controls, and several controls became conditions of quoting rather than factors in pricing. An organisation that cannot evidence them will frequently find that no terms are offered at all, at any premium.
The proposal form is a disclosure document, and the answers given on it are material facts. Stating that multi-factor authentication is enforced across all remote access when it is enforced only for some users is not a technicality; it goes to the heart of the risk the insurer accepted, and it is exactly the kind of misstatement that supports avoidance at claims stage.
The practical approach is to verify each answer against the actual configuration before signing, and to raise any gap openly. Insurers will frequently offer terms with a condition or a higher retention where a control is partially implemented. They will not overlook a control that was represented as present and was not.
Controls insurers commonly treat as prerequisites:
- Multi-factor authentication on all remote access, email and privileged accounts.
- Endpoint detection and response deployed across the estate, not only on servers.
- Offline or immutable backups, segregated from the production network, with documented restore testing.
- A defined patching cycle for critical vulnerabilities, with evidence of adherence.
- Network segmentation limiting lateral movement from a compromised endpoint.
- Removal or hardening of remote desktop protocol exposed to the internet.
- Privileged access management and prompt removal of departed users.
- Email filtering, and out-of-band verification of payment instruction changes.
- Security awareness training with phishing simulation records.
- A written and rehearsed incident response plan.
Business interruption and supplier dependency
For most organisations the largest cyber exposure is not the data - it is the downtime. A ransomware event that encrypts production systems stops invoicing, dispatch, production scheduling and customer service simultaneously, and recovery is measured in weeks rather than days once forensic containment, rebuild and verification are taken into account.
Cyber business interruption is structured differently from property business interruption and the differences matter. Cover normally begins only after a waiting period, commonly between six and twenty-four hours, and a shorter waiting period is often better value than a larger limit. The indemnity period runs from the incident, not from the point at which the business realises how bad it is. And the basis of loss calculation should be checked against how the business actually recognises revenue.
Dependency is the harder question. Where a business relies on a cloud platform, a hosted enterprise system, a payment processor or an outsourced provider, an incident at that provider can halt trading without any compromise of the insured's own network. Contingent or dependent business interruption cover addresses this, but it is frequently sub-limited, frequently restricted to named providers, and frequently excludes outages that are not caused by a security failure. Listing the providers on which the business genuinely depends, and confirming how each is treated, is a short exercise with a large payoff.
Read our business interruption insurance guide →
Ransomware, extortion and the legal constraints
Where an extortion demand is made, the decision on whether to engage or pay is a legal decision before it is a commercial one. Sanctions screening is mandatory: payment to a sanctioned entity or to a group associated with one exposes the payer, and potentially the insurer and any adviser involved, to serious consequence. Cyber policies invariably exclude payments that would contravene sanctions or anti-terrorism law, and the screening must be done before funds move.
South African law also imposes reporting duties. The Cybercrimes Act 19 of 2020 creates the substantive cybercrime offences and, in section 54, obliges electronic communications service providers and financial institutions to report certain offences to the South African Police Service without undue delay and within seventy-two hours of becoming aware of them. Reporting obligations under the Financial Intelligence Centre Act may also be engaged depending on the circumstances of the payment.
The insurance point is procedural. Almost every cyber policy requires the insurer's prior consent before an extortion payment is made or before significant response costs are incurred. Engaging the insurer's panel from the first hour protects the claim; appointing advisers independently and seeking consent afterwards frequently does not.
Source: Cybercrimes Act 19 of 2020, section 54 (obligation to report offences); Electronic Communications and Transactions Act 25 of 2002.
Incident response: the first seventy-two hours
The quality of the first three days determines both the size of the loss and the strength of the claim. A rehearsed plan that names the decision-makers, sets out the escalation route, identifies the insurer notification number and preserves forensic evidence is worth more than an additional layer of limit.
Two mistakes recur. The first is rebuilding compromised systems before forensic images are taken, which destroys the evidence needed to establish what was accessed - and therefore forces a broader and far more expensive POPIA notification than the facts may have required. The second is delay in notifying the insurer, which can prejudice cover under the notification condition and forfeits access to specialist breach counsel and negotiators at the point they are most useful.
The plan should be tested, not merely written. A short tabletop exercise involving the executive, IT, legal and communications reliably exposes the assumptions that do not survive contact with a live incident - including the discovery that the incident response plan itself was stored on the encrypted file server.
Explore our risk improvement programmes →
COMMON QUESTIONS
Cyber insurance questions, answered clearly.
What does cyber insurance cover?
Cyber policies combine first-party sections - incident response, forensics, data restoration, business interruption and extortion - with third-party sections covering privacy liability, network security liability and regulatory defence. The actual response depends on the policy wording, its exclusions and conditions, and the insurer's decision on the particular facts.
Is cyber insurance required by POPIA?
No. The Protection of Personal Information Act 4 of 2013 does not require insurance. Section 19 requires appropriate, reasonable technical and organisational security measures, and section 22 requires notification of the Information Regulator and affected data subjects where personal information has been accessed by an unauthorised person. Insurance funds the response to those duties; it does not discharge them.
How quickly must a data breach be reported in South Africa?
Section 22 of POPIA requires notification to the Information Regulator and to affected data subjects as soon as reasonably possible after discovery of the compromise. Notification may be delayed only where a public body responsible for the detection or prevention of offences, or the Regulator, determines that it would impede a criminal investigation. Separately, section 54 of the Cybercrimes Act 19 of 2020 requires certain service providers and financial institutions to report specified offences within seventy-two hours.
Why do cyber insurers ask about multi-factor authentication and backups?
Because these controls materially affect both the likelihood and the severity of the most common cyber events. Multi-factor authentication, endpoint detection and response, offline or immutable backups with tested restores, and a defined critical-patching cycle have moved from rating factors to conditions of quoting for many insurers. Answers given on the proposal form are material facts and should be verified against the actual configuration before signing.
Does cyber insurance cover ransomware payments?
Cyber extortion sections may cover negotiation costs, specialist advisers and, where lawful and with the insurer's prior consent, the payment itself. Payments that would contravene sanctions or anti-terrorism law are excluded, and sanctions screening must be completed before funds move. Insurer consent is almost always a condition, so the insurer should be engaged from the first hour.
Does cyber insurance cover business interruption?
Most cyber policies include a business interruption section, but it is structured differently from property business interruption. Cover typically begins only after a waiting period of between six and twenty-four hours, and the indemnity period runs from the incident. Where the business depends on cloud platforms or outsourced providers, dependent or contingent business interruption cover should be confirmed, as it is often sub-limited and restricted to named providers.
Are POPIA fines insurable?
Whether a regulatory penalty is insurable is a question of law and of the policy wording, and it cannot be assumed. Policies commonly cover the cost of defending a regulatory process, and cover fines only to the extent that insurance of them is legally permissible. The distinction between defence costs and the penalty itself should be confirmed specifically.
Does cyber insurance cover funds transfer fraud?
Many cyber policies include a modest sub-limit for social engineering or funds transfer fraud, but this is not a substitute for a full crime or fidelity section. Where the exposure is significant, the sub-limit and its conditions - which commonly require out-of-band verification of payment instruction changes - need to be examined specifically.
Does cyber insurance replace cyber-security controls?
No. Insurance does not replace prevention, detection, incident response or recovery planning, and increasingly it is not available without evidence of those controls. It should be considered as one part of a broader cyber-risk programme, funding response and liability rather than substituting for security.
What should be done in the first hours of a cyber incident?
Preserve forensic evidence before rebuilding systems, because destroying it removes the ability to establish what was actually accessed and forces a broader and more expensive notification than the facts may require. Notify the insurer immediately, since delay can prejudice cover under the notification condition and forfeits access to breach counsel and negotiators when they are most useful.