Skip to main content
Backup & Recovery

Why Your Business Insurance Might Not Cover a Cyberattack

31 July 20266 min read

Standard business insurance almost never covers cyber incidents. Cyber insurance is a separate product and most policies require basic security controls to be in place, including MFA, endpoint protection and up-to-date software, before a claim will be paid.

Business insurance policy gaps that exclude cyber attack coverage

If you asked most business owners whether they are covered for a cyberattack, the majority would say yes. They have business insurance, it covers everything, and that is that. The reality is very different and most businesses only discover the gap when they are trying to make a claim after an incident.

Standard business insurance and cyber insurance are not the same thing. Understanding the difference before you need it could save your business from a very expensive surprise.

What standard business insurance typically covers

Your general business insurance, sometimes called commercial insurance or a business owner's policy, typically covers physical risks. Fire, theft, property damage, public liability and business interruption caused by physical events. These policies were designed for a world where the biggest threats to a business were tangible.

Cyber incidents do not fit neatly into any of these categories. A ransomware attack does not cause physical damage. A data breach does not involve a break-in. Business email compromise does not destroy property. Your standard policy was never designed to cover these scenarios and in most cases it explicitly excludes them.

Legal and compliance requirements for cyber insurance claims

What cyber insurance covers

Cyber insurance is a separate product specifically designed for digital risks. A good cyber policy typically covers the cost of investigating and containing a breach, data recovery and system restoration, legal fees and regulatory fines including POPIA penalties, notification costs for informing affected individuals, business interruption losses caused by a cyber incident, ransom payments in some cases though this is increasingly debated, and public relations support for managing reputational damage.

The specifics vary between insurers and policies, but the principle is clear. If your business faces a cyber incident, cyber insurance covers the costs that your standard business policy does not.

Why most businesses do not have it

The main reason is awareness. Many business owners genuinely believe their existing policy covers cyber incidents because they have never been told otherwise. Others assume that cyber insurance is only for large companies or technology businesses and does not apply to them.

Some businesses have looked into it and decided the premium is not worth it. That calculation changes dramatically when you consider what a single incident actually costs. A ransomware attack on a small business can easily cost tens of thousands of rand in recovery alone, before you factor in lost revenue and reputational damage.

The conditions you need to meet

Here is where it gets important for IT specifically. Most cyber insurance policies have conditions around your security practices. Insurers want to see that you have taken reasonable steps to protect your business before they agree to cover you. Common requirements include multi-factor authentication on all business accounts, endpoint protection on every device, regular data backups stored securely, up-to-date software and operating systems, and documented security policies.

If you make a claim and the insurer finds that basic protections were not in place, they can decline the claim. Having a policy is not enough. You need to meet the conditions of that policy, and those conditions are directly related to your IT security setup.

The POPIA connection

Under POPIA, businesses that experience a data breach involving personal information face potential fines of up to ten million rand. Cyber insurance can cover these fines and the legal costs associated with a regulatory investigation.

Without cyber insurance, those costs come directly out of your business. For a small business, a six-figure fine combined with recovery costs and lost revenue can be existential.

How to evaluate your position

Start by reading your current business insurance policy carefully, specifically the exclusions section. Look for language around cyber events, data breaches, electronic crime and technology failures. If these are excluded, which they almost certainly are, you know you have a gap.

Then talk to your broker about cyber insurance specifically. Ask about the security requirements and make sure your IT setup meets them before you take out the policy. There is no point paying for cover that will be declined because your MFA was not enabled.

The bottom line

Cyber insurance is not a luxury for large companies. It is a practical protection for any business that uses technology, which is every business. The question is not whether you can afford cyber insurance. It is whether you can afford to be without it when something goes wrong.

At Recloud we help businesses get their IT security to the standard that insurers require, and we provide the documentation and reporting that supports a claim if one ever needs to be made. If you are not sure whether your business meets the requirements for cyber insurance, get in touch and we will assess where you stand.

Need help with your IT?

Recloud provides managed IT support for businesses across Cape Town.

Get in touch