What Does Cyber Insurance Cover? First-Party and Third-Party Coverage, Explained

Cyber insurance covers two kinds of loss. First-party coverage pays your own costs after an incident: breach response, ransomware, lost income while systems are down, data restoration, and often funds transfer fraud. Third-party coverage pays for claims against you: lawsuits over exposed data, regulatory investigations, payment card assessments, and media claims. Each part has its own limit, so read the declarations page.

By Trella Commercial · Updated October 3, 2026

The short version

  • First-party coverage pays your business's own costs: investigating and responding to a breach, ransomware, lost income, restoring data, and some kinds of fraud.
  • Third-party coverage pays when someone else claims against you: customers, patients, clients, regulators, or card brands.
  • Each coverage part has its own limit. A $1 million policy can carry a $100,000 sublimit for wire fraud. The declarations page shows what you actually bought.
  • Business interruption has a waiting period before payments start, and it may or may not include outages at your vendors.
  • Ransomware is the main event in Washington. 58% of the cyberattacks reported to the Washington Attorney General from July 2023 to July 2026 were ransomware, and a ransomware claim usually touches four or five coverage parts at once.

First-party and third-party at a glance

First-party coverageThird-party coverage
Whose lossYour business's own costs and lost incomeClaims, suits, and penalties brought by others
Typical triggersRansomware, a breach, a system outage, a fraudulent paymentA lawsuit over exposed data, a regulator's inquiry, a card brand assessment
What it paysVendors, restoration, income, extortion, stolen funds (if covered)Defense costs, settlements, judgments, and insurable fines
Who chooses vendorsOften the insurer's panel, or with its consentDefense counsel is often appointed or approved by the insurer

First-party coverage, part by part

Breach response

The core of most cyber policies. It pays for the people you need in the first weeks after an incident:

  • A breach attorney (often called a breach coach) to run the response and decide notice obligations
  • Forensic investigators to find out what happened, what was taken, and whether the attacker is still inside
  • Notification to affected people, as state laws like Washington's 30-day rule require, plus a call center
  • Credit or identity monitoring offered to affected people
  • Public relations help when customers or the press are asking questions

Some policies put breach response costs outside the main limit; others erode the limit. Ask which yours does.

Cyber extortion and ransomware

Pays for ransomware specialists to assess and negotiate, and in many policies the ransom itself, when payment is lawful and the insurer agrees in advance. The U.S. Treasury warns that paying sanctioned groups can violate federal law, which is one reason insurers control the process.

Business interruption

Pays the net income you lose and the extra expenses you incur while your systems are down because of a covered cyber event. Three details decide how much it is worth:

TermWhat it meansWhat to check
Waiting periodHow long an outage must last before coverage starts, usually stated in hoursShorter is better; compare it with how long your business can run on paper
Period of restorationHow long lost income is covered after systems come backWhether it ends when systems are restored or when revenue recovers
Dependent business interruptionLost income when a vendor you rely on, such as a cloud, payroll, or scheduling provider, has an outageWhether it is included at all, and whether it covers vendor system failures or only vendor cyberattacks

Some policies also cover system failure: an outage caused by an accidental error or a bad update, with no attacker involved. If a software update or IT mistake could stop your business, ask for it.

Data restoration

Pays to restore, recreate, or recollect data and software damaged in a covered event. It generally does not pay to upgrade systems beyond what you had (betterment), although a few policies offer limited betterment coverage.

Funds transfer fraud and social engineering

Pays money lost when someone tricks your business into sending funds: a spoofed email from your "CEO," a vendor invoice with new bank details, or an attacker inside your email changing payment instructions. This is a large and growing risk. The FBI's Internet Crime Complaint Center received 21,442 business email compromise complaints in 2024, with reported losses of more than $2.77 billion.

VariationWhat it covers
Funds transfer fraudAn outsider breaks in and sends money from your accounts without your knowledge
Social engineeringAn employee is deceived into sending money themselves
Invoice manipulationA customer pays a fake invoice sent from your hacked email, and you cannot collect the real one

These are frequently sublimited, sometimes require a verification procedure such as a call-back to a known number, and are sometimes only available by endorsement. Some businesses cover them under a crime policy instead.

Other first-party coverages to look for

  • Cryptojacking: extra utility or cloud costs from attackers using your systems to mine cryptocurrency
  • Telecommunications fraud: charges from hackers using your phone system
  • Hardware replacement ("bricking"): replacing devices made unusable by an attack, rather than repairing them
  • Reputational harm: lost income from customers who leave after a publicized breach, usually for a limited period

Third-party coverage, part by part

CoverageWhat it responds toExample
Privacy liabilityClaims that you failed to protect personal information or violated privacy lawPatients sue after their records are exposed
Network security liabilityClaims that your security failure harmed someone else, such as passing malware to a clientA client's systems are infected through your shared connection
Regulatory defense and penaltiesInvestigations by state attorneys general and other regulators, plus fines where insurable by lawThe Attorney General asks why your breach notice was late
Payment card (PCI) liabilityFines, assessments, and reimbursements demanded by card brands after a card data breachYour point-of-sale system leaks card numbers
Media liabilityDefamation, invasion of privacy, and copyright or trademark claims over your online contentA competitor claims your website copied its content

Third-party coverage is usually written on a claims-made basis: the claim must be made during the policy period, for an incident after the retroactive date. Keeping coverage continuous, with the same retroactive date, matters when you switch insurers.

How a ransomware claim uses the policy

What happensCoverage part
Systems are encrypted and a ransom note appearsCyber extortion
A breach attorney and forensic firm are engagedBreach response
The office cannot schedule, bill, or ship for eight daysBusiness interruption, after the waiting period
Servers and files are rebuilt from backupsData restoration
The attackers also copied customer files, so notices go outBreach response (notification and monitoring)
Customers whose data was exposed file suitPrivacy liability

This is why the overall limit matters. One event can draw on several coverage parts, and on policies where they share an aggregate limit, it can draw down the whole policy.

How limits, sublimits, and retentions work

  • Aggregate limit: the most the policy pays in the policy period for all claims combined.
  • Sublimits: smaller caps on particular coverage parts, such as social engineering, PCI, regulatory fines, or dependent business interruption. They sit inside the aggregate, not on top of it.
  • Retention: your deductible. Some policies have different retentions for different coverage parts.
  • Coinsurance: some ransomware or extortion coverage requires you to pay a percentage of the loss.

A declarations page checklist

When you compare cyber quotes, line them up on these points:

  1. The aggregate limit, and whether breach response costs erode it
  2. Each sublimit, especially social engineering, funds transfer fraud, regulatory, and PCI
  3. The business interruption waiting period and period of restoration
  4. Whether dependent business interruption and system failure are included
  5. The retention for each coverage part
  6. The retroactive date and any prior acts limitation
  7. Whether you must use the insurer's panel of vendors
  8. Any coinsurance on ransomware or extortion

The exclusions matter as much as the coverage. See what cyber insurance does not cover.

Common questions

What is the difference between first-party and third-party cyber coverage?

First-party coverage pays your own losses, such as breach response, ransomware, lost income, and data restoration. Third-party coverage pays when others claim against you, such as customers suing over exposed data or regulators investigating. Most small business cyber policies include both.

Does cyber insurance cover lost income?

Yes, if the policy includes business interruption. It pays lost net income and extra expenses while your systems are down from a covered event, after a waiting period. Outages at your vendors are covered only if the policy includes dependent business interruption.

Does cyber insurance cover wire fraud?

Often, but usually under a social engineering or funds transfer fraud coverage part with its own sublimit, and sometimes only by endorsement. Check the sublimit and any requirement to verify payment changes by phone.

Does cyber insurance cover a breach at my vendor?

It depends. If your customers' data was exposed at a vendor, your breach response and liability coverage may respond, since the notice duty usually stays with you. Lost income from a vendor's outage is covered only under dependent business interruption.

Is ransomware covered by cyber insurance?

Ransomware is typically covered through several parts at once: cyber extortion for the negotiation and any approved payment, breach response for investigation and notification, business interruption for lost income, and data restoration for rebuilding systems.

Sources

This page describes coverage commonly found in cyber policies. Policies differ widely; what yours pays depends on its wording and the underwriting. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.