Coverage line
Cyber Liability
You get hacked or leak customer data. This pays for the cleanup and the notifications the law requires, and answers the claims that follow.
Built for moments like these.
Ransomware locks production the night before launch. You need forensics and a negotiator.
Covered: Attack response
An attacker exfiltrates your customers' records. Notification letters are legally required.
Covered: Breach fallout
The classic mix-up
Your model gives bad output and a customer loses money. No breach involved.
Not this policy
→ Professional Liability (Tech E&O) answers this oneEasy to confuse.
Cyber Liability
Hacks and leaks.
This page
When to buy
The first time you hold customer data in production.
Typical ask: $1M or more in enterprise contracts.
Who requires it
Enterprise and government contracts, once you touch their data.
How hard to get
Easy to get
Quick to get with sane security basics in place.
Common questions
We run on a major cloud provider. Do we still need cyber insurance?
Yes. The cloud's shared-responsibility model leaves your code, config, and data handling on your side. When customer data you hold is exposed, claims come to you.
Does cyber insurance cover a prompt-injection attack or a model leaking data?
It depends how the policy defines a security event, and those definitions predate language models. We read that wording before a form binds.
Keep reading
Describes a line of coverage in general terms. Not an offer of insurance.