Cover for what happens after an attack.
Most businesses are one breach away from a very bad week. Cyber insurance covers getting systems working again, telling the people whose data was involved, the income lost while you couldn’t trade and other costs that follow.
Cyber insurance
Usually includes
Incident response & IT forensics
Business interruption after a cyber event
Cyber extortion & ransom
Data restoration & system rebuild
Breach notification & monitoring
Regulatory investigation costs
Know your cover
It insures the aftermath, not the attack.
Cyber insurance responds to what an incident costs you once it has happened: the specialists who work out what went wrong and get you trading again, the duty to tell the people whose data was involved, the income lost while you were down, and the claims that can follow from other people affected. Two things about it surprise people more than anything else. Most of the value is in the response rather than the settlement, and the headline limit is rarely the number that governs a particular claim, because the sections carry sub-limits of their own. Both are on this page rather than buried in the wording.
Response first, payment second
The part that usually matters most is the panel of people who arrive on day one: forensics, legal, and whoever has to speak to the regulator. That is bought as a service, not paid out afterwards.
Sub-limits are important to check
Extortion, notification and funds transfer each carry a sub-limit (a ceiling that applies to one section only, well below the headline limit). Business interruption carries a waiting period too, a set number of hours an outage has to last before it pays anything.
Your controls change the terms
How you sign in, where your backups sit and whether your software is still supported affect the price, the sub-limits, and in some cases whether cover is offered.
What we cover
What each cover does, and where it stops.
The cover, the conditions attached to it, and the things it typically won’t reach, set out side by side rather than three clicks apart.
Cover
What comes with it
Commonly excluded
Incident response & IT forensics
The people who work out what happened and get you back online.
Almost always through the insurer’s own notified panel. Using your own IT provider without agreement can reduce or lose the claim. These costs normally come out of the policy limit rather than sitting on top of it.
Work by your own provider engaged before the insurer agreed to it. Improving the systems while you are in there rather than restoring them. Anything spent before the incident was notified.
Business interruption after a cyber event
The income lost while you couldn’t trade, not just the cost of the fix.
A waiting period applies before anything is payable, and it is often longer than a short outage. The section usually carries a sub-limit below the policy limit, and the loss is measured against documented past trading.
An outage shorter than the waiting period. Loss you cannot evidence from your own accounts. A failure of a public network or utility rather than an attack on you, on many wordings.
Cyber extortion & ransom
Where a policy responds to a demand, and on what terms.
Sub-limited, and subject to the insurer’s consent before any payment. Sanctions screening applies, and in some cases a payment would be unlawful regardless of what the policy says.
Any payment made without the insurer’s consent. A payment that sanctions law prohibits, whatever the policy says. The data loss and the downtime themselves, which sit in the other sections.
Data restoration & system rebuild
Getting systems and records back to where they were.
Pays to get systems back to the state they were in, not to improve them. Upgrades are excluded as betterment. Data you cannot evidence existed is difficult to claim for.
Betterment, meaning the upgrade rather than the restoration. Data whose existence cannot be evidenced. Systems already unsupported or past end of life, on many wordings.
Breach notification & monitoring
Telling the people whose data was involved, and supporting them afterwards.
Sub-limited, often capped by the number of individuals as well as by cost. Usually only where notification is legally required or the insurer agrees to it.
Notifying people where there was no legal duty and the insurer did not agree to it. Goodwill payments or compensation offered on your own initiative. Your own staff time.
Regulatory investigation costs
Dealing with the ICO, and fines in the cases where they can be insured.
Defence and investigation costs are generally covered. Fines are only payable where insuring them is lawful, which in the UK frequently means they are not. Contractual penalties are a separate question again.
Fines where insuring them would be unlawful. Contractual penalties, including card scheme assessments on many wordings. Anything arising from a breach you knew about and did not act on.
Third-party liability for a data breach
Claims brought against you by other people affected.
Covers claims brought against you by others. Normally excludes liability you took on by contract, and excludes bodily injury and physical damage.
Liability you accepted by contract rather than at law. Bodily injury and physical damage to property. Claims between parties insured under the same policy, on most wordings.
Funds transfer & social engineering fraud
Money that left because someone was deceived into sending it.
Usually an optional extension with a low sub-limit, not part of the standard cover. Typically conditional on a documented verification step having been followed. If it was skipped, most wordings decline the claim.
A payment made without the verification step the policy requires. Theft by your own employee, which is a crime policy. Anything above the extension sub-limit, which normally sits well below the policy limit.
The headline limit is rarely the number that governs your claim.
Extortion, notification and funds transfer are typically capped well below it, and business
interruption does not start paying until the waiting period has passed. Two policies quoted at
the same limit and a similar price can behave completely differently once you read the inner
numbers, which is where we spend our time.
Words you’ll see
Six terms that decide whether it pays.
Sub-limit
A ceiling inside the policy that applies to one section only, and sits below the headline limit. Extortion, notification and funds transfer are the usual ones. Comparing policies on the headline limit alone tells you very little about what a claim is worth.
Waiting period
The time an outage has to last before the business interruption section pays anything at all. Short outages fall inside it and are simply not covered, so the length of it matters more than the limit for most businesses.
Notified panel
The insurer’s own list of forensic, legal and public relations firms that respond to an incident. Using someone else without agreement first can reduce a claim or lose it, which is the single most common way cyber claims go wrong.
Betterment
Any improvement over what you had before. The policy restores systems to their previous state, so if the rebuild leaves you better off than you were, the difference is normally yours to fund.
Funds transfer fraud
Money that left the business because someone was deceived into sending it, usually through a spoofed instruction. It is generally an extension with its own low sub-limit, and it is normally conditional on a verification step having been followed.
Prior known incident
Anything you were already aware of when cover started. A breach, an intrusion or a suspicious payment you knew about cannot be insured after the event, so it is better disclosed at the outset than discovered at claim stage.

Why Vara
Bespoke service for you & your business,
without the big-firm minimum.
01
We ask about your controls before we approach anyone
How you sign in, where the backups sit, what is still supported and who is allowed to move money. Insurers price on those answers, and getting them straight first changes what you are offered.
02
We read the inner numbers, not just the limit
The waiting period, the section limits and the extension sub-limits are what a claim actually runs into. We set them out next to each other so you can see the difference between two policies that look identical.
03
Named insurers, not a black box
We place with a published panel and tell you who’s on it. You can see where your risk went and who’s carrying it.
04
We recommend, and we write it down
We set out cover, limits and exclusions, recommend a policy from our panel, and put in writing why we consider it meets your demands and needs, so you can check it. The decision is always yours.
You talk to a person. The machines do the typing.
Alongside this policy
The three that sit next to it.
Professional indemnity
Most professional indemnity wordings now carry a cyber exclusion, so the two are bought alongside each other rather than one reaching into the other’s territory.
Commercial combined
Property, liability and business interruption. Interruption caused by an attack is measured differently and sits in the cyber policy rather than the property one.
Management liability & D&O
Claims made against a director personally rather than against the business, including for how an incident was handled. Different insured, separate contract.
Free review of your cyber cover and costs.
Leave your details and we’ll call you straight back. One conversation covers your data, your systems and how you control access to them.
What the review covers
We go through the policy you have now, so you can see what it does and doesn’t cover against a breach, an outage or a fraudulent payment.
We point out the terms that catch cyber customers out most often, waiting periods and notified panels among them, so you can check yours.
We approach insurers on our panel who write cyber cover, and come back with what they’ll offer.
We explain each option in plain English, including what it doesn’t cover.
If it’s not a risk we can place, we’ll tell you straight away rather than leave you waiting.
No obligation to switch. You decide what fits.
Rather not wait? Call us on 0333 091 3663
Good to know
Cyber questions, answered straight.
How does cyber cover work alongside good IT controls?
What's the difference between the limit and a sub-limit?
Does a policy pay a ransom?
How quickly do we have to report an incident?
What will insurers ask us about?
Can we use our own IT provider to deal with an incident?
Is a payment we were tricked into making covered?
Doesn't our other insurance already cover this?

Vara Commercial Insurance · 0333 091 3663
Vara is a trading name of Koral AI Operating Company Limited. Vara is an appointed representative of Innovative Risk Labs Ltd, under Firm Reference Number 1060955. Innovative Risk Labs Ltd is authorised and regulated by the Financial Conduct Authority, under FRN 609155. We are registered in England and Wales under Registered Company Number 17256222. Registered office: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.