Cyber insurance is a contractual requirement. That’s because a successful attack can interrupt production, expose sensitive information, affect customers and generate recovery costs that suppliers may struggle to absorb.
Yet cyber insurance is often not treated as a priority, particularly by smaller suppliers. The biggest worry is that limits may be too low to cover a serious incident or that policy exclusions may make an attack ineligible for coverage.
If a supplier’s inadequate cybersecurity causes an incident that costs its prime contractor money, the prime’s insurance may initially cover the loss. The prime’s insurer could then seek to recover that money from the supplier or the supplier’s insurer.
Suppliers should begin by asking whether their coverage reflects the losses they could realistically experience. Those losses may include:
- Operational downtime and lost production
- Supply chain disruption
- Third-party liability
- Incident response and forensic investigation
- Legal and regulatory expenses
- System restoration and data recovery
A broker or cyber insurance adviser can help model potential incidents and recommend appropriate coverage limits. Tabletop exercises can also help suppliers estimate the potential costs of ransomware, compromised credentials, cloud outages, destructive malware and disruptions to operational technology.
The policy language deserves as much attention as the coverage limit. Suppliers should confirm whether their policies cover:
- Business interruption and dependent business interruption
- Outages involving critical technology and nontechnology suppliers
- Ransomware, extortion and incident response costs
- Destructive malware, firmware attacks and operational technology
- Legal defense, regulatory expenses and third-party claims
- Nation-state attacks and other incidents that could be affected by war exclusions
Standard cyber policies commonly cover data breaches, ransomware, incident response and some business interruption losses. Coverage for supply chain compromises, operational technology, destructive attacks and nation-state activity can vary significantly.
Suppliers should not assume standard policy language covers every mission-critical operational loss. Many policies exclude or limit coverage related to war, hostile or warlike actions and certain nation-state attacks. Suppliers should ask their broker or insurer to explain how these exclusions would apply to realistic cyberattack scenarios.
They should also understand the claims process before an attack occurs. That means knowing:
- Who to call and how quickly the insurer must be notified
- Which forensic, legal and communications firms the insurer has approved
- Whether the insurer must authorize major expenses in advance
- What documentation will be needed to support a claim
Cyber insurance is balance-sheet protection. It can help a company absorb the financial effects of an attack, but it cannot prevent one. Even well-protected businesses can experience successful cyberattacks. Insurance should therefore complement, not replace, strong cybersecurity practices and incident-response planning.