Two Sides of the Same Policy
Cyber coverage splits into two buckets. Almost everything you'll see on a policy falls into one of them, and knowing which is which makes the whole thing readable.
Simple way to remember it: first-party is your bill, third-party is their lawsuit. A good small-business policy usually includes both.
What a Policy Actually Pays For
Here are the pieces you'll find on most cyber policies. Not every policy has all of them — which is exactly why you read before you buy.
Skits' Tip
Watch the social engineering line hardest. The most common way small businesses lose money isn't a dramatic hack — it's a convincing email that gets a real employee to send a real wire. And that's the coverage insurers most often tuck behind a low sub-limit.
The Gaps That Surprise People
This is the part that turns "I have coverage" into "my claim got denied." Cyber policies have exclusions, and they're not hidden — people just don't read them.
The big three to ask about
1. The security-controls exclusion. Many policies won't pay if you didn't have the safeguards you promised on the application — things like multi-factor authentication. Say you have it and you don't, and the claim can be voided. (Chapter 3 is all about this.)
2. Low sub-limits. A policy can say it "covers" wire fraud but cap that specific payout at a fraction of your overall limit. The headline number isn't the number that matters.
3. Known problems & old incidents. Trouble that started before the policy began is usually excluded. Coverage protects against the future, not last month.
A policy you didn't read
is a promise you can't count on.
Worried a hacker could lock your files tomorrow? The Backing Up Your Business Data microcourse covers the 3-2-1 rule — good backups are the single best thing that makes ransomware survivable, insurance or not.
Quick Check — Sort the Losses
Sort each loss into the bucket where it belongs. The rule of thumb: first-party is your bill; third-party is their lawsuit.
How it works
1. Click a card in the tray up top — it lights up to show it's picked up.
2. Click the bucket where that card belongs. It drops in.
3. Repeat until all five cards are sorted, then click Check My Answers.
Put one in the wrong bucket? Double-click the card to pop it back up to the tray, then place it again. (Or single-click the card and click a different bucket.) Nothing's locked in until you check your answers.
Restoring your own ransomware-locked files
Lost income during a week of downtime
A customer sues you after their data leaked
A regulator's fine over the exposed data
Paying forensics experts to investigate the breach
Third-Party — their lawsuit
You know what it buys. Now, do you need it?
You can now read a cyber policy without your eyes glazing over: first-party vs third-party, the six things it pays for, and the three gaps that bite. Next is the decision itself — who actually needs this — plus the requirements insurers now put on you before they'll even offer a policy.