What It Covers

Chapter 2 of 5

Two Sides of the Same Policy

Cyber coverage splits into two buckets. Almost everything you'll see on a policy falls into one of them, and knowing which is which makes the whole thing readable.

BucketCovers
First-partyYour own losses — the money it costs you to recover: data restoration, downtime, the ransom question, forensics to find out what happened.
Third-partyOther people's claims against you — a customer or partner whose data leaked through you, plus legal defense and regulatory fines.

Simple way to remember it: first-party is your bill, third-party is their lawsuit. A good small-business policy usually includes both.

What a Policy Actually Pays For

Here are the pieces you'll find on most cyber policies. Not every policy has all of them — which is exactly why you read before you buy.

CoverageWhat it means in plain English
Ransomware / cyber extortionHelp handling — and sometimes paying — a ransom demand when your files get locked, plus the cost of getting back up and running.
Data breach responseThe expensive cleanup after a leak: notifying affected customers, credit monitoring for them, legal guidance, and PR.
Business interruptionLost income while you're down. If an attack shuts you for a week, this is the piece that keeps the lights on.
Funds transfer / social engineering fraudWhen a scammer tricks someone into wiring money or changing payment details. Often a small sub-limit or an add-on — check this one specifically.
Forensics & recoveryPaying the specialists who figure out how they got in, kick them out, and rebuild your systems.
Liability & regulatoryDefense costs and fines if customers or a regulator come after you over exposed data.
Skits the Handyman
Skits' Tip

Watch the social engineering line hardest. The most common way small businesses lose money isn't a dramatic hack — it's a convincing email that gets a real employee to send a real wire. And that's the coverage insurers most often tuck behind a low sub-limit.

The Gaps That Surprise People

This is the part that turns "I have coverage" into "my claim got denied." Cyber policies have exclusions, and they're not hidden — people just don't read them.

The big three to ask about

1. The security-controls exclusion. Many policies won't pay if you didn't have the safeguards you promised on the application — things like multi-factor authentication. Say you have it and you don't, and the claim can be voided. (Chapter 3 is all about this.)

2. Low sub-limits. A policy can say it "covers" wire fraud but cap that specific payout at a fraction of your overall limit. The headline number isn't the number that matters.

3. Known problems & old incidents. Trouble that started before the policy began is usually excluded. Coverage protects against the future, not last month.

A policy you didn't read
is a promise you can't count on.

Worried a hacker could lock your files tomorrow? The Backing Up Your Business Data microcourse covers the 3-2-1 rule — good backups are the single best thing that makes ransomware survivable, insurance or not.

Quick Check — Sort the Losses

Sort each loss into the bucket where it belongs. The rule of thumb: first-party is your bill; third-party is their lawsuit.

How it works

1. Click a card in the tray up top — it lights up to show it's picked up.

2. Click the bucket where that card belongs. It drops in.

3. Repeat until all five cards are sorted, then click Check My Answers.

Put one in the wrong bucket? Double-click the card to pop it back up to the tray, then place it again. (Or single-click the card and click a different bucket.) Nothing's locked in until you check your answers.

Restoring your own ransomware-locked files
Lost income during a week of downtime
A customer sues you after their data leaked
A regulator's fine over the exposed data
Paying forensics experts to investigate the breach
First-Party — your bill
Third-Party — their lawsuit

You know what it buys. Now, do you need it?

You can now read a cyber policy without your eyes glazing over: first-party vs third-party, the six things it pays for, and the three gaps that bite. Next is the decision itself — who actually needs this — plus the requirements insurers now put on you before they'll even offer a policy.

Get monthly tech tips, security alerts, and exclusive offers delivered to your inbox.