Skip to main content

Cyber insuranceFAQs

What cyber risk insurance covers, how it differs from cybersecurity, and from the cover included in a multi-risk policy.

It's insurance designed for companies whose activity depends on systems, data or technology providers. Depending on the policy, it covers the consequences of a cyberattack — any failure in IT system security that leads to unauthorised access, alteration or loss of data, or a denial-of-service attack — data breach management, and business interruption arising from systems being unavailable. It doesn't replace the company's cybersecurity measures: it complements them.

No: the cyber risk guarantees in a multi-risk policy are basic coverage for minor incidents and don't replace a dedicated cyber risk policy.

What the multi-risk add-on usually covers is limited to basic IT support — phone or remote help setting up a router or removing a common virus — and backups, with very low monetary limits.

What you leave uncovered if you don't take out a dedicated cyber risk policy is more significant: a cyber policy covers three risks a multi-risk policy doesn't touch. Actual business interruption — if a cyberattack paralyses your systems or your online shop for days, cyber insurance pays for the money you stop earning, while a multi-risk policy only pays if the business stops due to physical damage such as a fire or a flood. Data breaches and GDPR fines — if customer data is stolen, the dedicated policy covers the forensic investigation, the legally required cost of notifying those affected, and fines from the Spanish Data Protection Agency (AEPD), none of which a multi-risk policy covers. And extortion and data ransom, covering negotiation and specialist management costs if a hacker encrypts your servers and demands a ransom.

It's a security incident that causes unauthorised access, leakage, loss, alteration or theft of confidential information.

These are the costs a cyber insurer covers to repair, recover and get your company's IT infrastructure running again after a cyberattack. They include: digital forensics services — hiring experts to analyse the origin of the attack and clean systems of viruses or malware; data recovery — costs to restore databases and lost information from backups; software reconfiguration — costs of reinstalling operating systems, business applications and licences that were damaged or corrupted; and replacement of damaged hardware.

Because cybersecurity and cyber insurance aren't alternatives to each other — they're two complementary layers that act at different moments of the same problem: cybersecurity reduces the likelihood of an incident, cyber insurance covers its consequences when it happens.

Cybersecurity acts before the incident: firewalls, antivirus software, two-factor authentication, staff training, software updates, regular backups. It's essential, and no cyber insurance can replace it. Cyber insurance acts once the incident happens: it covers the financial, operational and legal consequences of the attack. It doesn't prevent the damage, it mitigates it once it's occurred.

The problem with relying only on cybersecurity is that zero risk doesn't exist, because the most frequent entry point in a cyberattack isn't technical, it's human: an employee who opens a malicious file, an executive connecting from public wifi, a supplier with system access who suffers their own breach. The companies with the most mature cybersecurity are precisely those that invest the most in cyber insurance, because they understand the residual risk better.

Example: a technology consultancy with ISO 27001 certification and a robust in-house security team suffered a ransomware attack that came in through a maintenance provider with remote access to its systems. The consultancy's certification didn't cover the supplier's systems. Investing in cybersecurity is necessary; relying on it alone is a risk.

No: a liability clause with your software provider doesn't protect you against the consequences of a cybersecurity incident, because legal liability towards the AEPD and your clients still rests with you.

There are three reasons. First, liability towards the AEPD is always yours: the GDPR states that the company is the data controller, not its provider; if there's a breach, it's your company that must notify within 72 hours and that can face the penalty. Second, reputation isn't recovered by passing the blame to third parties: when your customers' data is leaked, those customers hold you responsible, not your provider. Third, claiming against the provider is a long, uncertain legal process: liability clauses in software contracts are usually full of limitations, exclusions and caps, and while it's being resolved, your company has already borne all the response, defence and penalty costs.

Cyber insurance acts at the moment of the incident, not at the end of a lawsuit: it covers immediate response costs, defence before the AEPD and compensation to those affected without waiting for it to be resolved who's right with the provider. Your provider being contractually liable doesn't mean you aren't legally liable: these are separate liabilities that coexist.

It depends on what the customer can prove: if your company did nothing to create the confusion, direct liability for the fraudulent transaction is hard to attribute to the legitimate company — but that doesn't stop you from being sued, and cyber insurance covers both the legal defence and the reputational response.

This is the typosquatting scenario taken to its most unfair consequence: the company that's a victim of the fraud also becomes the target of a claim. There are several fronts where the company can be affected even without direct fault: a claim over confusion of identity, the need to prove the fraudulent domain isn't yours (with the legal defence costs that involves even if the claim is unfounded), immediate reputational damage, and the risk that a slow response is read as negligence in protecting your digital identity.

In this scenario, cyber insurance covers: legal costs to act against the fraudulent domain (formal notices, action before the registrar, takedown); defence against the customer's claim, even if it's unfounded; crisis communication services to inform affected customers; liability towards the customer within the policy limits; and guidance on monitoring future domain-impersonation attempts.

Yes, significantly: holidays, sick leave, public holidays or restructuring are the moments when cybercriminals concentrate their attacks, because cover staff have less training and fewer protocols, and incident detection slows down.

Three factors reinforce each other in these periods: the human factor is amplified because cover staff don't always have the same security training; AI makes large-scale targeted attacks easier, scanning social media and corporate websites to identify who's away and who's covering for them; and response times get longer because the security team is also reduced.

Example: a finance director posts on LinkedIn that they're starting their holidays. Two days later, their cover receives an email from an address almost identical to the CEO's, urgently requesting a transfer for a confidential deal. With no access to the CEO and no clear protocol, the cover processes the transfer and the money isn't recovered.

Cyber insurance is active 365 days a year, with the same level of cover at any time, and doesn't depend on the internal team detecting the incident in time: it acts once it's reported. Business Email Compromise (BEC) cover specifically protects against this type of fraud. Beyond the insurance, it helps to have a written verification protocol for any payment request, specific training for cover staff, and to avoid posting information about absences or organisational structure on social media.

Related insurance

The more specific your situation, the more important it is to review it with our team before making a decision.