Foundational Explainer · 11 min read

Cyber Insurance for Technology Firms: What It Actually Covers

Cyber insurance is one of the most misunderstood policies in the startup stack. This article walks through what it covers, what it excludes, and how underwriting has shifted in the last three years.

About the author

Written by Amir.

What cyber covers

First-party loss: ransomware payments, business interruption, data restoration, funds-transfer fraud. Third-party liability: privacy claims, regulatory action, customer indemnification. Breach response: forensics, legal counsel, customer notification, credit monitoring, PR.

What cyber doesn't cover

Cyber is not Tech E&O. If a customer sues you because your product malfunctioned and caused them harm, that's Tech E&O — not cyber. Many tech firms carry both on a combined form.

Underwriting expectations in 2026

MFA on email, VPN, and admin consoles. EDR (not legacy antivirus) deployed on every endpoint. Encrypted, immutable, tested backups. A documented and tested incident-response plan.

How much cyber insurance do I need?

Limits are usually driven by your largest customer contracts. Most enterprise SaaS contracts require $5M–$10M; some require $25M.

Does cyber cover ransomware payments?

Yes, on most modern policies — but with sublimits, coinsurance, and a requirement that you involve the carrier's panel forensics firm.

Frequently asked questions

How much cyber insurance do I need?

Limits are usually driven by your largest customer contracts. Most enterprise SaaS contracts require $5M–$10M; some require $25M.

Does cyber cover ransomware payments?

Yes, on most modern policies — but with sublimits, coinsurance, and a requirement that you involve the carrier's panel forensics firm.

This material is general educational information, not legal, tax, or insurance advice. Coverage availability, policy terms, and regulatory requirements vary by state, carrier, and applicant.