Cyber insurance limits – what a cyber policy may and may not do

0
36

Tim Chadwick | CEO | Chadwicks | mail me |


So, what do most comprehensive cyber insurance policies usually cover?

First, they cover the costs of investigating and responding to a breach. Forensic teams do not work for free. You will need them to determine what happened, how severe the breach is and whether the attacker left evidence behind. Understanding these response costs is essential when assessing cyber insurance limits.

Second, policies typically cover the cost of restoring systems and data after an insured cyber event. This includes hiring specialists, rebuilding servers and recovering data from backups. However, this assumes your backups are usable. In practice, insurers usually require this as a condition of cover, which again illustrates how cyber insurance limits operate in real-world scenarios.

Third, cyber policies often cover business interruption losses during a covered cyber event. For example, if a ransomware attack locks you out for forty days and revenue declines, your policy should respond. That said, compensation remains subject to terms and conditions. These include definitions, exclusions, limits and waiting periods. At this point, cyber insurance limits become particularly visible, especially when downtime exceeds predefined thresholds.

Fourth, policies may cover liability to third parties. This applies when a breach exposes third-party data or disrupts their operations. In such cases, cover may extend to legal fees, settlements and possibly regulatory fines, provided these fall within defined cyber insurance limits.

Understanding where cyber insurance limits sit

Most policies will almost certainly not cover large systemic and fundamental risk events. These include war and terrorism. They also include nationwide power grid failures or the collapse of major cloud providers without physical damage. Insurers list these events as exclusions.

The wording often looks similar across policies. This uniformity exists because insurers rely on the same reinsurance markets. No insurer wants to absorb fundamental systemic risk alone, and cyber insurance limits reflect that shared constraint.

Importantly, this is not a flaw in your policy. It reflects reality. The objective is not to find a policy with no exclusions. Instead, the goal is to understand exactly where cyber insurance limits sit, so you can plan effectively beyond them.

What you need to do

With that in mind, here are several business survival tips. These steps improve your chances of a calm weekend and a peaceful festive season, even when cyber insurance limits are reached.

Tip 1 – Draw the picture

Start with the customer and work backwards. Identify every step required to deliver when you are offline. For each step, document the digital tools involved and the suppliers behind them. This exercise is not glamorous. It is diagnostic. Few people enjoy it, but it reveals what actually happens.

Typically, this process involves a whiteboard and several capable people. Each person often explains the payment system differently. Sometimes, you discover that nobody fully understands what happens between the customer clicking “submit” and the funds reaching your account.

Drawing boxes on a whiteboard may feel childish. Nevertheless, it beats issuing public apologies, offering plausible deniability or facing uncomfortable shareholder meetings. Proper process mapping matters, especially when cyber insurance limits prevent full financial recovery.

Tip 2 – Design systems on the assumption that the internet will fail

Do not assume it might fail. Assume it will fail. Keep critical operations accessible on your internal network. This allows you to operate in island mode when external connectivity disappears, rather than relying solely on cyber insurance limits for protection.

Where possible, use multiple ISPs and multiple cloud storage providers. Combine different connection types. For optimal redundancy, use multiple fibre lines linked to different undersea cables. Add fast cellular data access points. If feasible, include satellite connectivity. In South Africa, that may soon become more realistic.

For larger organisations, consider building an internal intranet. Maintain on-premises, offline storage for key information. This next point may sound heretical, especially from a paperless advocate. Nevertheless, keep paper copies of critical processes, supplier lists, templates, contracts and SLAs. Yes, paper. Keep two or three copies off-site. Store them in different locations, buildings and with trusted individuals.

Tip 3 – Secure proper cyber insurance through risk professionals

Do this with full awareness. Understand the exclusions. Ask your risk advisor to explain precisely what qualifies as a covered event.

Clarify how the policy treats systemic fundamental disasters. Make sure you understand cyber insurance limits in relation to non-malicious events, business interruption, third-party cyber liability, and restoration costs.

Tip 4 – Clarify force majeure and vis major clauses

Work with your legal team to review these provisions. These clauses function as contractual escape hatches when extraordinary events make performance impossible.

Ensure agreements with clients, suppliers and vendors address grid collapse, cable failures and major internet outages. While these clauses will not prevent disaster, they can mitigate uncontrollable risk. Push suppliers to commit to reasonable redundancy.

At the same time, accept that they will also exclude systemic events. They operate under the same constraints. Remember that vis major clauses do not excuse negligence. Poor design and foreseeable risks remain your responsibility. You cannot contract out of negligence by rebranding it as an act of God.

Tip 5 – Consider offline AI solutions

Many businesses now depend heavily on AI tools. Almost all of these require internet access. Unfortunately, internet reliability often resembles a pen that never works when you need it.

Offline AI platforms do exist. Examples include LocalAI and similar tools that run on desktops or mobile devices. They lack the power and currency of cloud-based systems. However, they can perform basic tasks when connectivity fails. The trade-off lies in hardware requirements. These platforms demand serious computing power. High RAM and VRAM are no longer luxuries. They are becoming essential.

Install LocalAI on an outdated laptop and observe the results. The machine will struggle, overheat and shut down unexpectedly. What once qualified as a supercomputer now approaches standard business equipment.

Tip 6 – Prepare a first-hour communications script

Decide in advance who will declare the incident. Assign responsibility for customer communication, supplier contact and social media. A clear update within the first hour buys time and preserves credibility.

By contrast, silence invites speculation. Speculation fuels conspiracy theories, emergency board meetings and expensive consultants. Decide early. Write it down. Store it somewhere accessible. Do not bury it in a SharePoint folder protected by multiple passwords and divine intervention.

Tip 7 – Test the ugly spinning wheel day

A business continuity plan that sits on a shelf offers no protection. Once or twice a year, deliberately disrupt a system. Do so without warning. Observe the outcome.

You will quickly learn which processes hold and which collapse. You will also see who stays calm under pressure. Often, one quiet individual retrieves the plan and executes it flawlessly. While others panic, that person acts. Reward them accordingly.

Finally, remember this principle. Treat insurance as the last line of defence. Treat risk mitigation, contractual protection and operational controls as the first line, particularly where cyber insurance limits apply.

Action trumps denial

This may offer limited comfort, but it remains true. Everyone faces the same fragility. If the internet fails, it fails for all of us. No secret policy exists that covers everything beyond cyber insurance limits. The real difference lies elsewhere.

Resilient businesses design hybrid risk systems with redundancy. They purchase appropriate cyber cover. They negotiate contracts that provide some protection when fundamental risks emerge.

The internet is a fragile cooperative system. It depends on cables, contracts and optimism. When it breaks, cyber insurance limits define how much help you receive. Contracts may absorb another party. For the remainder, survival depends on manual processes, offline backups and prior planning. Beyond that point, cyber insurance limits end and fundamental risk begins. Think strategically. Think in terms of risk. Ask uncomfortable questions. Then plan, act, test and repeat.





LEAVE A REPLY

Please enter your comment!
Please enter your name here