Skip to content
Atlas
Cyber Liability Insurance

Cyber insurance for companies that hold other people's data.

Incident response on day one, the forensics and legal bill, the business interruption loss, and the liability when a customer says the breach was your fault.

At a glance
The question it answers
What happens if we get breached, or our data leaks?
Typical limit
$3M – $5Mat Series B
In plain English

What Cyber actually does

Cyber liability does two jobs. The first-party side pays your costs when something goes wrong inside your environment: the forensics firm, breach counsel, notification, credit monitoring, the ransom decision, restoring corrupted data, and the revenue you lost while systems were down. The third-party side pays when someone sues you — a customer whose records were exposed, a regulator opening an inquiry, a card brand assessing PCI fines.

For technology companies, cyber is rarely bought alone. It is usually packaged with Technology Errors & Omissions on a single form, from a single carrier, with a shared limit. That structure matters: when a customer sues after an outage, the claim can be part professional-services failure and part security failure, and a combined form removes the argument about which policy responds.

The market has also gotten specific about controls. Multi-factor authentication on email and remote access, endpoint detection, tested backups, and privileged access management are effectively underwriting prerequisites for meaningful limits. Getting the application right is most of the pricing outcome.

Buy it when

  • A customer contract requires cyber liability at a stated limit
  • You are entering a security review or vendor risk assessment
  • You just closed a round and are hiring into a bigger data footprint
  • You started handling PII, PHI, cardholder data, or biometric data
  • You had a near miss — a phishing incident, an exposed bucket, a vendor breach
Coverage

What it covers

Grants vary by carrier and form. These are the components we look for when we place it.

01

Incident response

A 24/7 breach hotline, pre-approved forensics vendors, and breach counsel — usually outside the retention or with a reduced retention if you use panel firms.

02

Ransomware and cyber extortion

Negotiation, ransom payment where lawful, and the cost of rebuilding what was encrypted or exfiltrated.

03

Business interruption and dependent BI

Lost income from your own outage and — critically for SaaS — from an outage at a cloud or hosting provider you depend on.

04

Data restoration

The engineering cost of recreating or restoring data and applications that were corrupted or destroyed.

05

Privacy and network security liability

Defense and damages when a third party claims your failure to secure a network or protect personal information harmed them.

06

Regulatory defense, fines, and penalties

Response to state AG, FTC, HHS, or EU/UK regulator inquiries — and the fines themselves where insurable by law.

07

PCI-DSS assessments

Fines, penalties, and card-reissuance costs assessed by card brands or your acquirer after a payment data event.

08

Social engineering and funds transfer fraud

Usually a sublimit. Covers fraudulently induced wire transfers — the single most common loss we see at seed and Series A.

09

Media liability

Defamation, copyright, and trademark claims arising from your website, product content, and marketing.

Just as important

What it doesn't cover

We put this in front of you at binding — the only moment you can still do something about it.

  • Bodily injury and property damage (that is General Liability)
  • The cost of upgrading your security to a better state than before the incident (betterment)
  • Loss of value in your own intellectual property or trade secrets
  • Prior known incidents and circumstances disclosed or knowable before the policy started
  • Failures of infrastructure you don't control, such as broad internet or power outages, unless specifically endorsed
  • War and certain state-backed cyber operations — the wording here varies materially between carriers and is worth reading
How claims actually happen

Three ways this policy earns its premium

Composite scenarios drawn from how these losses typically develop. Illustrative, not case files.

Scenario 01

Vendor compromise cascades into your platform

A subprocessor is breached. Attackers pivot into your production environment through a shared integration and exfiltrate records for 140,000 end users across 60 customer accounts. Cyber pays for forensics, notification in 43 states, credit monitoring, breach counsel, and the class action that follows.

Scenario 02

Ransomware halts the product for nine days

Production is encrypted on a Friday night. You restore from backups rather than pay, but it takes nine days. Cyber pays the incident response cost, the engineering hours to rebuild, and the contractual SLA credits and lost revenue during the outage.

Scenario 03

A finance hire wires $310,000 to a spoofed vendor

An attacker impersonates a supplier over email and changes remittance details. The social engineering sublimit responds — which is precisely why that sublimit's size deserves attention at binding, not at claim time.

Limits

What limit is normal

Ranges we commonly see for technology companies. Your contracts and exposure decide the answer — this is where the conversation starts, not where it ends.

StageTypical
Pre-seed / Seed$1M
Series A$2M – $3M
Series B$3M – $5M
Series C+$5M – $15M+
Who buys it

Companies that need this

  • Any company that stores, processes, or transmits customer data
  • SaaS and cloud platforms where downtime is a contractual event
  • Companies pursuing SOC 2 or ISO 27001 — buyers routinely ask for proof of cyber cover
  • Anyone signing enterprise MSAs, DPAs, or BAAs
  • Companies moving money, including any team that can be tricked into wiring it

What we need to quote

  • Completed cyber application or carrier-specific ransomware supplement
  • Revenue, employee count, and records held by type (PII, PHI, PCI, biometric)
  • MFA status on email, remote access, and privileged accounts
  • Backup strategy, frequency, segregation, and last restore test
  • EDR/MDR in place and coverage percentage across endpoints
  • SOC 2 report or security questionnaire responses if available
  • Five years of loss runs and any prior incident history

Most of this is collected once in the Atlas submission and reused across the markets we approach.

Start a submission
Questions

Cyber, answered

Yes. Cloud providers cover the security of the cloud; you are responsible for security in the cloud — your configurations, your access controls, your application, your data. Nearly every breach we see at software companies is a customer-side failure, not a hyperscaler failure.

No, but they are usually bought together. Tech E&O responds when your product or service fails to perform. Cyber responds when data or systems are compromised. Many claims are both, which is why we generally place them on one combined form with a shared limit.

Cyber forms often don't add additional insureds the way General Liability does. What the customer usually needs is a certificate evidencing the limit, and sometimes a waiver of subrogation. We handle that language with the customer's procurement team directly.

For a clean sub-$10M revenue technology company with MFA in place, same-day to 48 hours is realistic. Missing MFA is the most common reason a submission stalls.

Cyber

Find out what cyber costs for your company.

Tell us about the business once. A broker reviews it the same business day and comes back with a plan and a timeline.