Cyber insurance for companies that hold other people's data.
Incident response on day one, the forensics and legal bill, the business interruption loss, and the liability when a customer says the breach was your fault.
- The question it answers
- “What happens if we get breached, or our data leaks?”
- Typical limit
- $3M – $5Mat Series B
- Usually bought with
- Tech E&OCrimeGeneral Liability
What Cyber actually does
Cyber liability does two jobs. The first-party side pays your costs when something goes wrong inside your environment: the forensics firm, breach counsel, notification, credit monitoring, the ransom decision, restoring corrupted data, and the revenue you lost while systems were down. The third-party side pays when someone sues you — a customer whose records were exposed, a regulator opening an inquiry, a card brand assessing PCI fines.
For technology companies, cyber is rarely bought alone. It is usually packaged with Technology Errors & Omissions on a single form, from a single carrier, with a shared limit. That structure matters: when a customer sues after an outage, the claim can be part professional-services failure and part security failure, and a combined form removes the argument about which policy responds.
The market has also gotten specific about controls. Multi-factor authentication on email and remote access, endpoint detection, tested backups, and privileged access management are effectively underwriting prerequisites for meaningful limits. Getting the application right is most of the pricing outcome.
Buy it when
- A customer contract requires cyber liability at a stated limit
- You are entering a security review or vendor risk assessment
- You just closed a round and are hiring into a bigger data footprint
- You started handling PII, PHI, cardholder data, or biometric data
- You had a near miss — a phishing incident, an exposed bucket, a vendor breach
What it covers
Grants vary by carrier and form. These are the components we look for when we place it.
Incident response
A 24/7 breach hotline, pre-approved forensics vendors, and breach counsel — usually outside the retention or with a reduced retention if you use panel firms.
Ransomware and cyber extortion
Negotiation, ransom payment where lawful, and the cost of rebuilding what was encrypted or exfiltrated.
Business interruption and dependent BI
Lost income from your own outage and — critically for SaaS — from an outage at a cloud or hosting provider you depend on.
Data restoration
The engineering cost of recreating or restoring data and applications that were corrupted or destroyed.
Privacy and network security liability
Defense and damages when a third party claims your failure to secure a network or protect personal information harmed them.
Regulatory defense, fines, and penalties
Response to state AG, FTC, HHS, or EU/UK regulator inquiries — and the fines themselves where insurable by law.
PCI-DSS assessments
Fines, penalties, and card-reissuance costs assessed by card brands or your acquirer after a payment data event.
Social engineering and funds transfer fraud
Usually a sublimit. Covers fraudulently induced wire transfers — the single most common loss we see at seed and Series A.
Media liability
Defamation, copyright, and trademark claims arising from your website, product content, and marketing.
What it doesn't cover
We put this in front of you at binding — the only moment you can still do something about it.
- Bodily injury and property damage (that is General Liability)
- The cost of upgrading your security to a better state than before the incident (betterment)
- Loss of value in your own intellectual property or trade secrets
- Prior known incidents and circumstances disclosed or knowable before the policy started
- Failures of infrastructure you don't control, such as broad internet or power outages, unless specifically endorsed
- War and certain state-backed cyber operations — the wording here varies materially between carriers and is worth reading
Three ways this policy earns its premium
Composite scenarios drawn from how these losses typically develop. Illustrative, not case files.
Vendor compromise cascades into your platform
A subprocessor is breached. Attackers pivot into your production environment through a shared integration and exfiltrate records for 140,000 end users across 60 customer accounts. Cyber pays for forensics, notification in 43 states, credit monitoring, breach counsel, and the class action that follows.
Ransomware halts the product for nine days
Production is encrypted on a Friday night. You restore from backups rather than pay, but it takes nine days. Cyber pays the incident response cost, the engineering hours to rebuild, and the contractual SLA credits and lost revenue during the outage.
A finance hire wires $310,000 to a spoofed vendor
An attacker impersonates a supplier over email and changes remittance details. The social engineering sublimit responds — which is precisely why that sublimit's size deserves attention at binding, not at claim time.
What limit is normal
Ranges we commonly see for technology companies. Your contracts and exposure decide the answer — this is where the conversation starts, not where it ends.
| Stage | Typical | |
|---|---|---|
| Pre-seed / Seed | $1M | Usually a packaged Tech E&O + Cyber form. Enough to satisfy early enterprise contracts. |
| Series A | $2M – $3M | Contract requirements start to cluster at $2M. Watch the social engineering sublimit. |
| Series B | $3M – $5M | Dependent business interruption and regulatory coverage become the negotiating points. |
| Series C+ | $5M – $15M+ | Towers with excess layers. Panel counsel, retention structure, and BI waiting periods drive value. |
Companies that need this
- Any company that stores, processes, or transmits customer data
- SaaS and cloud platforms where downtime is a contractual event
- Companies pursuing SOC 2 or ISO 27001 — buyers routinely ask for proof of cyber cover
- Anyone signing enterprise MSAs, DPAs, or BAAs
- Companies moving money, including any team that can be tricked into wiring it
What we need to quote
- Completed cyber application or carrier-specific ransomware supplement
- Revenue, employee count, and records held by type (PII, PHI, PCI, biometric)
- MFA status on email, remote access, and privileged accounts
- Backup strategy, frequency, segregation, and last restore test
- EDR/MDR in place and coverage percentage across endpoints
- SOC 2 report or security questionnaire responses if available
- Five years of loss runs and any prior incident history
Most of this is collected once in the Atlas submission and reused across the markets we approach.
Start a submissionSituations that put this policy on your desk
Cyber, answered
Yes. Cloud providers cover the security of the cloud; you are responsible for security in the cloud — your configurations, your access controls, your application, your data. Nearly every breach we see at software companies is a customer-side failure, not a hyperscaler failure.
No, but they are usually bought together. Tech E&O responds when your product or service fails to perform. Cyber responds when data or systems are compromised. Many claims are both, which is why we generally place them on one combined form with a shared limit.
Cyber forms often don't add additional insureds the way General Liability does. What the customer usually needs is a certificate evidencing the limit, and sometimes a waiver of subrogation. We handle that language with the customer's procurement team directly.
For a clean sub-$10M revenue technology company with MFA in place, same-day to 48 hours is realistic. Missing MFA is the most common reason a submission stalls.
Find out what cyber costs for your company.
Tell us about the business once. A broker reviews it the same business day and comes back with a plan and a timeline.