Call us

For companies

When your systems stop on a Monday

In a cyber incident the cost rarely comes from the stolen data itself. It comes from the days the company cannot operate, from the forensic experts working out what happened, and from the obligations towards the Commissioner for Information of Public Importance and Personal Data Protection and towards the people whose data was exposed. Cyber policies differ from insurer to insurer mostly in whether they cover business email compromise at all and how quickly the incident response team is mobilised, and that is exactly what we compare before you sign anything.

What the policy covers

  • Ransomware, data decryption and the cost of restoring systems and databases
  • Business interruption following an incident, lost profit and increased cost of working during the outage
  • Digital forensics and engagement of an incident response team
  • Business email compromise, where an employee makes a payment on an instruction that appears to come from a director or a supplier
  • Costs of notifying affected individuals and the costs of proceedings before the Commissioner
  • Third party liability for breaches of personal data and confidential business information
  • Legal advice, guidance on notification duties and support in public communication
  • Cyber extortion, including negotiations with attackers and intermediary costs

What is usually not covered

  • A known vulnerability reported before the policy was placed and not remedied within a reasonable time
  • Legacy software and systems no longer supported by the vendor, where the terms expressly exclude them
  • Missing or faulty backups, where regular backups were a condition of the policy
  • Deliberate acts by management, and ordinary employee embezzlement, which belongs to a different class of insurance
  • Fines and penalties, to the extent they are uninsurable under Serbian law
  • Damage to hardware, since physical damage to devices is settled under a property policy
  • The cost of improving systems beyond their pre incident state, meaning upgrades rather than restoration

Exclusions differ from one insurer to another, and checking them is part of our work before we recommend a policy to you.

When the policy pays out

01

Ransomware in a factory

An attacker encrypts the servers and production stops for several days while the systems are restored from backups. The policy covers forensics, restoration costs and lost profit for the outage beyond the agreed time deductible. If the backups were not sound, part of the loss can stay uncovered, which is why we check the state of your backups before placing cover.

02

A fake supplier email

Accounts receives an email with a changed bank account number, apparently from a regular supplier, and makes the payment. This type of fraud is not included in every cyber policy and needs a specific extension, often called funds transfer fraud or business email compromise cover. When we compare quotes we look closely at whether that cover exists and what the limit per event is.

03

A customer data leak

Customer data leaks from a web shop, which triggers a duty to assess the incident and notify the Commissioner within seventy two hours, and to inform the individuals as well if the risk is high. The policy covers legal advice, notification and call centre costs, and the defence against compensation claims. Without a policy those costs land on the company immediately, before anyone has even established who was at fault.

The examples are illustrative and show how the cover works in practice.

Frequently asked questions

What exactly does cyber insurance cover?

Two groups of costs. The first are your own costs: forensics, restoring systems, lost profit from the outage, notifying affected individuals and legal advice. The second is liability towards others: compensation claims from customers and partners over the breach of their data, and the costs of any proceedings that follow.

Does the policy pay the ransom in a ransomware attack?

Some policies include extortion cover, subject to prior consent from the insurer and a check that payment is not prohibited under sanctions rules. Paying a ransom is a last resort, since it does not guarantee the data comes back. In practice the more valuable part of the policy is the one that funds the incident response team and the restoration from backups.

What are my duties under the Personal Data Protection Act?

If personal data has been breached, the controller must notify the Commissioner without delay, as a rule within seventy two hours of becoming aware of it, unless the breach is unlikely to create a risk to the rights of individuals. If the risk is high, the individuals themselves must be informed too. An internal record of breaches is also kept, and the policy covers the cost of legal advice and of carrying out those steps.

We are a small company, do we really need this?

Size is not protection, because a large share of attacks is automated and simply finds whoever is least protected. For smaller companies the cost of downtime matters more than the value of the data, since a few days without billing or production feeds straight into the annual result. Limits and premiums scale with revenue, so a policy for a small company is nowhere near corporate level pricing.

What does the insurer ask for before quoting?

Usually a security questionnaire covering basic controls: regular backups that are tested, multi factor authentication for remote access, patching and staff training. The answers form part of the contract, so an inaccurate answer can be grounds for reducing or declining a claim. We go through the questionnaire with you before it is submitted and approach insurers whose terms fit your actual situation.

Request a quote for this type of insurance

Send us a short enquiry. We collect offers from every insurer that covers this risk and explain the differences before you sign anything.