Cyber insurance for SMBs: necessary or not?
Cyber insurance can soften the blow of an incident, but it covers far from everything. What it is and is not for, and what to watch in the small print.
By Limburg Cyber Group
Now that cyber incidents are more common, the question comes up more and more: as an SMB, do I need cyber insurance? The answer is nuanced. Insurance can be valuable, but it is no miracle cure and certainly not a replacement for good basic security. Work through this before you sign.
What cyber insurance usually covers
Coverage differs per policy, but often it includes:
- Recovery costs after an incident: IT experts, forensic investigation, rebuilding systems;
- Business losses from downtime;
- Costs of legal support and notifications, for example after a data breach;
- Liability towards third parties whose data was affected;
- sometimes support with extortion (ransomware).
That first aid, access to specialists at the moment it matters, may well be the greatest value for many smaller businesses.
What it does not do
Insurance does not prevent incidents and does not restore your reputation. And importantly: insurers increasingly set requirements for your security before they pay out. No MFA, no working backups, or outdated updates? Then a claim can be rejected. Having the basics in order is therefore not an alternative to insurance, but a condition for it.
Watch the small print
- Which requirements does the policy set for your own measures? Can you meet them, and keep meeting them?
- What is excluded? Think of known, unpatched vulnerabilities or negligence.
- How high is the excess, and what are the maximum payouts?
- How fast is help available in an incident, and how does reporting work?
Basics first, then insurance
The sensible order is clear: get your basic security in order first, do a risk assessment, and then look at which residual risk you want to insure. Insurance is the safety net for what remains after good measures, not the first step.
Independent advice?
We help you, without selling insurance ourselves, to determine whether and which coverage fits your risk, and to get the basics in order first. See our consultancy & advice service or book a conversation.
Read more
A business continuity plan for SMBs: carrying on when things go wrong
What do you do when your systems fail, your premises are unusable, or your data is held hostage? A practical continuity plan keeps your business running in a crisis.
Choosing the right IT supplier: 8 questions to ask up front
Your IT partner has access to your whole business. These eight questions help you choose a reliable, fitting supplier, and spot hot air.
Information security risk assessment in 5 steps (no consultant-speak)
A risk assessment sounds heavy, but it is just structured thinking about what can go wrong. Here is how to do one yourself in five understandable steps.