The short version
- First-party coverage pays your business's own costs: investigating and responding to a breach, ransomware, lost income, restoring data, and some kinds of fraud.
- Third-party coverage pays when someone else claims against you: customers, patients, clients, regulators, or card brands.
- Each coverage part has its own limit. A $1 million policy can carry a $100,000 sublimit for wire fraud. The declarations page shows what you actually bought.
- Business interruption has a waiting period before payments start, and it may or may not include outages at your vendors.
- Ransomware is the main event in Washington. 58% of the cyberattacks reported to the Washington Attorney General from July 2023 to July 2026 were ransomware, and a ransomware claim usually touches four or five coverage parts at once.
First-party and third-party at a glance
| First-party coverage | Third-party coverage | |
|---|---|---|
| Whose loss | Your business's own costs and lost income | Claims, suits, and penalties brought by others |
| Typical triggers | Ransomware, a breach, a system outage, a fraudulent payment | A lawsuit over exposed data, a regulator's inquiry, a card brand assessment |
| What it pays | Vendors, restoration, income, extortion, stolen funds (if covered) | Defense costs, settlements, judgments, and insurable fines |
| Who chooses vendors | Often the insurer's panel, or with its consent | Defense counsel is often appointed or approved by the insurer |
First-party coverage, part by part
Breach response
The core of most cyber policies. It pays for the people you need in the first weeks after an incident:
- A breach attorney (often called a breach coach) to run the response and decide notice obligations
- Forensic investigators to find out what happened, what was taken, and whether the attacker is still inside
- Notification to affected people, as state laws like Washington's 30-day rule require, plus a call center
- Credit or identity monitoring offered to affected people
- Public relations help when customers or the press are asking questions
Some policies put breach response costs outside the main limit; others erode the limit. Ask which yours does.
Cyber extortion and ransomware
Pays for ransomware specialists to assess and negotiate, and in many policies the ransom itself, when payment is lawful and the insurer agrees in advance. The U.S. Treasury warns that paying sanctioned groups can violate federal law, which is one reason insurers control the process.
Business interruption
Pays the net income you lose and the extra expenses you incur while your systems are down because of a covered cyber event. Three details decide how much it is worth:
| Term | What it means | What to check |
|---|---|---|
| Waiting period | How long an outage must last before coverage starts, usually stated in hours | Shorter is better; compare it with how long your business can run on paper |
| Period of restoration | How long lost income is covered after systems come back | Whether it ends when systems are restored or when revenue recovers |
| Dependent business interruption | Lost income when a vendor you rely on, such as a cloud, payroll, or scheduling provider, has an outage | Whether it is included at all, and whether it covers vendor system failures or only vendor cyberattacks |
Some policies also cover system failure: an outage caused by an accidental error or a bad update, with no attacker involved. If a software update or IT mistake could stop your business, ask for it.
Data restoration
Pays to restore, recreate, or recollect data and software damaged in a covered event. It generally does not pay to upgrade systems beyond what you had (betterment), although a few policies offer limited betterment coverage.
Funds transfer fraud and social engineering
Pays money lost when someone tricks your business into sending funds: a spoofed email from your "CEO," a vendor invoice with new bank details, or an attacker inside your email changing payment instructions. This is a large and growing risk. The FBI's Internet Crime Complaint Center received 21,442 business email compromise complaints in 2024, with reported losses of more than $2.77 billion.
| Variation | What it covers |
|---|---|
| Funds transfer fraud | An outsider breaks in and sends money from your accounts without your knowledge |
| Social engineering | An employee is deceived into sending money themselves |
| Invoice manipulation | A customer pays a fake invoice sent from your hacked email, and you cannot collect the real one |
These are frequently sublimited, sometimes require a verification procedure such as a call-back to a known number, and are sometimes only available by endorsement. Some businesses cover them under a crime policy instead.
Other first-party coverages to look for
- Cryptojacking: extra utility or cloud costs from attackers using your systems to mine cryptocurrency
- Telecommunications fraud: charges from hackers using your phone system
- Hardware replacement ("bricking"): replacing devices made unusable by an attack, rather than repairing them
- Reputational harm: lost income from customers who leave after a publicized breach, usually for a limited period
Third-party coverage, part by part
| Coverage | What it responds to | Example |
|---|---|---|
| Privacy liability | Claims that you failed to protect personal information or violated privacy law | Patients sue after their records are exposed |
| Network security liability | Claims that your security failure harmed someone else, such as passing malware to a client | A client's systems are infected through your shared connection |
| Regulatory defense and penalties | Investigations by state attorneys general and other regulators, plus fines where insurable by law | The Attorney General asks why your breach notice was late |
| Payment card (PCI) liability | Fines, assessments, and reimbursements demanded by card brands after a card data breach | Your point-of-sale system leaks card numbers |
| Media liability | Defamation, invasion of privacy, and copyright or trademark claims over your online content | A competitor claims your website copied its content |
Third-party coverage is usually written on a claims-made basis: the claim must be made during the policy period, for an incident after the retroactive date. Keeping coverage continuous, with the same retroactive date, matters when you switch insurers.
How a ransomware claim uses the policy
| What happens | Coverage part |
|---|---|
| Systems are encrypted and a ransom note appears | Cyber extortion |
| A breach attorney and forensic firm are engaged | Breach response |
| The office cannot schedule, bill, or ship for eight days | Business interruption, after the waiting period |
| Servers and files are rebuilt from backups | Data restoration |
| The attackers also copied customer files, so notices go out | Breach response (notification and monitoring) |
| Customers whose data was exposed file suit | Privacy liability |
This is why the overall limit matters. One event can draw on several coverage parts, and on policies where they share an aggregate limit, it can draw down the whole policy.
How limits, sublimits, and retentions work
- Aggregate limit: the most the policy pays in the policy period for all claims combined.
- Sublimits: smaller caps on particular coverage parts, such as social engineering, PCI, regulatory fines, or dependent business interruption. They sit inside the aggregate, not on top of it.
- Retention: your deductible. Some policies have different retentions for different coverage parts.
- Coinsurance: some ransomware or extortion coverage requires you to pay a percentage of the loss.
A declarations page checklist
When you compare cyber quotes, line them up on these points:
- The aggregate limit, and whether breach response costs erode it
- Each sublimit, especially social engineering, funds transfer fraud, regulatory, and PCI
- The business interruption waiting period and period of restoration
- Whether dependent business interruption and system failure are included
- The retention for each coverage part
- The retroactive date and any prior acts limitation
- Whether you must use the insurer's panel of vendors
- Any coinsurance on ransomware or extortion
The exclusions matter as much as the coverage. See what cyber insurance does not cover.