Specialty / Financial Chapter 14 22 min read

Cyber,
the line built on a moving target.

Cyber is the youngest major commercial line and the most reactive. Every wave of attacker behavior reshapes wording. Every controls failure reshapes appetite. This chapter walks first-party vs third-party, the controls underwriters now require, and what is actually inside a cyber tower today.

$8B
US standalone cyber GWP
claims-made
Trigger basis
8+
Distinct insuring agreements
MFA + EDR
Modern controls floor
§ 01

A short history

Cyber insurance began as a privacy-breach product in the late 1990s. It has been re-priced, re-formed, and partially re-defined every two or three years since.

The earliest cyber policies covered media liability and privacy notification costs, sold mostly to financial institutions and healthcare entities subject to HIPAA. The product expanded through the 2000s as state breach notification laws spread (California's SB 1386 in 2003 was the first), making notification costs a real and quantifiable exposure. The 2010s brought retail breaches (Target 2013, Home Depot 2014, Equifax 2017) and the maturation of business interruption coverage. The 2020s have been about ransomware, business email compromise (BEC), and systemic events. Each wave has produced a new round of underwriting, new exclusions, and a re-pricing of the book. The line has been profitable, unprofitable, and profitable again on roughly four-year cycles.

Anchor concept

Cyber covers a risk that is moving. Other lines insure stable underlying exposures (a building does not change, an employee does not change). Cyber insures a risk where the threat actors innovate continuously, the technology stack changes monthly, and the regulatory environment is in motion. Carriers that win in cyber have a tight feedback loop between claims, threat intelligence, and underwriting.

§ 02

First-party vs third-party

A cyber policy bundles two distinct kinds of coverage that other lines split into separate products. Underwriters track them separately even when they sit on the same form.

First-party
The insured's own losses from a cyber event. Includes incident response costs, forensics, notification, credit monitoring, business interruption, cyber extortion (ransom payments), data restoration. The insured is the claimant.
Third-party
Money the insured owes to others because of a cyber event. Privacy liability, network security liability, regulatory defense and fines, payment card industry (PCI) penalties, media content liability. Tort or contract based.

The mix between first-party and third-party shifts by industry. A consumer-facing retailer with millions of records on file leans heavily into third-party (privacy class actions, regulatory exposure). A manufacturer with critical OT systems leans first-party (business interruption, data restoration, extra expense). A healthcare provider has both heavy. Underwriters do not just price total limits, they look at the relative balance of coverage parts.

§ 03

The eight standard insuring agreements

A modern cyber policy has multiple coverage parts (insuring agreements) that can be turned on, off, or sub-limited individually. The eight most common:

  1. Privacy and Network Security Liability. Defense and indemnity for third-party claims arising from a privacy breach or network security failure.
  2. Regulatory Defense and Penalties. Costs of defending regulatory investigations (HIPAA, GDPR, state AG, FTC) and statutory fines where insurable by law.
  3. PCI Fines and Assessments. Card brand penalties and reissuance/reissuance-fraud costs after a payment card breach.
  4. Breach Response and Incident Costs. Forensics, legal counsel, notification, credit monitoring, call center, public relations. The "first 60 days" coverage.
  5. Business Interruption / Network Outage. Lost income and continuing expenses during a cyber-caused system outage. Often subject to a waiting period (8–12 hours typical).
  6. Cyber Extortion / Ransomware. Ransom payments, negotiator fees, decryption tooling, restoration costs.
  7. Data Restoration. Costs to reconstruct destroyed or corrupted data, including from backups or forensic recovery.
  8. Social Engineering / Cyber Crime. Funds transfer fraud (BEC), invoice manipulation, telephone toll fraud. Often a sub-limit, often subject to specific verification controls.

Optional add-ons

Beyond the standard eight, brokers often request: contingent business interruption (loss from a vendor's outage), reputational harm coverage, bricking coverage (replacement cost of hardware bricked by an attack), criminal reward coverage, and various territorial and jurisdictional add-ons. Each carries its own terms and sub-limits.

§ 04

Claims-made and the retroactive date

Cyber is written claims-made. The trigger is when a claim is first made against the insured during the policy period (or made/reported, in claims-made-and-reported variants), not when the underlying breach occurred. This matters because cyber breaches often go undetected for months or years before they surface as a claim.

The retroactive date

Every claims-made policy has a retro date. The policy responds to claims first made during the policy period that arise from acts, errors, omissions, or events occurring on or after the retro date. The first-time cyber buyer might get a retro date equal to inception (no prior acts coverage). A renewal customer with continuous prior coverage maintains a retro date going back to the original placement.

The breach-discovery problem

The 2017 Equifax breach was disclosed in September 2017 but the intrusion began in May 2017. If a buyer's policy renewed in July 2017 with a tightened retro date, the claim made in late 2017 might fall outside the retro window. This is the central tension of claims-made cyber. Buyers almost always negotiate hard for full prior acts on renewal because losing that retro date is functionally a coverage cut.

Extended Reporting Period (ERP)

If the policy is non-renewed or canceled, the buyer can purchase an ERP (sometimes called tail coverage) that extends the time to report claims for acts that occurred during the policy period. Standard cyber ERPs run 12, 24, or 36 months. Pricing is a percentage of expiring premium (often 100–250%, longer ERPs higher).

§ 05

Ransomware and BEC

Two attack patterns dominate modern cyber claims: ransomware (data encrypted, system held hostage) and business email compromise (an attacker spoofs an executive or vendor and tricks the buyer into wiring funds). They drive the bulk of severity and the bulk of underwriting questions.

Ransomware

Ransomware actors encrypt the victim's data and demand cryptocurrency payment for the decryption key. Modern variants also exfiltrate data first (double extortion) and threaten public release. Some variants threaten the victim's customers directly (triple extortion). The 2020-2024 wave produced many losses in the $5M–$50M range and several at $100M+. The carrier's payout includes the ransom (where lawful), negotiation fees, forensics, restoration, business interruption, and often the legal and regulatory tail. Carriers respond with mandated controls and, increasingly, ransom co-insurance or sub-limits below the policy limit.

BEC and social engineering

An attacker compromises an executive email account or spoofs a vendor and submits a fraudulent wire instruction. The buyer's accounts payable team processes the transfer and the funds are gone within hours. Average BEC loss is in the high six figures. BEC sits in the cyber crime / social engineering insuring agreement, often with a sub-limit ($250K–$1M typical) and specific control requirements (callback verification, dual approval, wire-confirmation procedures).

Other patterns worth knowing

  • Vendor compromise. Software supply-chain attacks like SolarWinds (2020) and the MOVEit Transfer (Cl0p, 2023) where an attacker compromises a widely-used third-party tool and pivots into customer environments.
  • Cloud account takeover. Compromised IdP credentials (Okta-related events 2022-2024 publicized this pattern) used to pivot into customer SaaS and cloud accounts.
  • Wiper malware. Destructive payloads that overwrite data without ransom demand. Common in geopolitically motivated attacks.
§ 06

Controls and the underwriting bar

In 2020 cyber insurance was sold on revenue and industry. Today it is sold on controls. Carriers will not bind an account without specific technical controls in place.

The modern controls floor

  • Multi-factor authentication (MFA). On email, on remote access (VPN, RDP), on privileged accounts, on cloud admin consoles. The single biggest control. No MFA usually equals no quote.
  • Endpoint detection and response (EDR). Modern endpoint security with detection and response capability, not just legacy AV. CrowdStrike, SentinelOne, Microsoft Defender for Endpoint at appropriate tier, others.
  • Privileged access management (PAM). Vaulting and rotation of admin credentials, just-in-time elevation.
  • Backup and recovery. Air-gapped or immutable backups, tested restoration, RTO/RPO targets defined.
  • Email security. Anti-phishing, link rewriting, attachment sandboxing, DMARC/SPF/DKIM enforcement.
  • Patch management. Critical patches deployed within defined windows; vulnerability scanning.
  • Security awareness training. Annual minimum, with phishing simulations and click-rate measurement.
  • Incident response plan. Documented, tested at least annually, with named external partners (forensics, breach counsel, PR).
  • Network segmentation. Particularly between corporate IT and any operational technology (OT) environments.
  • Access reviews / SoD. Periodic review of access entitlements, separation of duties for financial systems.
The controls supplemental

Most carriers run a controls supplemental of 50-100 questions in addition to the main application. Several large carriers do active scanning (BitSight, SecurityScorecard, BlackKite, plus some carrier-proprietary scans) of public-facing posture. Misrepresentation on the controls supplemental is a basis for claim denial. Underwriters now ask for evidence: screenshots of MFA dashboards, EDR coverage reports, backup test logs.

§ 07

Systemic risk and aggregation

Cyber's biggest worry is correlated loss. A single attacker, a single CVE, a single compromised vendor can trigger thousands of policies at once. Systemic events have happened (NotPetya 2017, Kaseya 2021, MOVEit 2023, CrowdStrike outage 2024) and the industry has had to think harder about correlated tail.

Aggregation drivers

  • Common cloud providers. A multi-hour outage at AWS, Azure, or Google Cloud cascades into thousands of insureds at once.
  • Common SaaS dependencies. Microsoft 365, Salesforce, Workday, Okta, Snowflake. Outages or compromises ripple.
  • Common security vendors. The CrowdStrike Falcon update incident in July 2024 grounded flights, halted hospitals, and produced significant cyber claims activity, reminding the market that security tooling is itself a single point of failure.
  • Common operating systems and infrastructure. Microsoft monthly patch cadence, OpenSSL CVEs, Log4j (December 2021) all examples of cross-cutting exposure.
  • Common file transfer / managed file products. MOVEit Transfer (Cl0p, 2023) hit hundreds of organizations through a single vulnerability.

Reinsurance and ILS response

Cyber reinsurance has matured to cover this systemic tail, and a small but growing cyber catastrophe bond market lets capital markets investors take on slices of correlated cyber risk. The economics are still being worked out. Cyber cat losses are harder to model than hurricane because the threat moves and the data is short.

§ 08

War, infrastructure, and the exclusions

The 2022 Lloyd's market bulletin on war and cyber and the subsequent industry exclusions tightened cyber forms around state-sponsored events. The basic move: explicitly exclude state-backed cyber operations even when not formally declared as war, with carve-backs for defined attribution thresholds. Forms vary. The LMA5564 / LMA5565 / LMA5566 / LMA5567 family of clauses are widely used in the London market and have been adopted in domestic forms with carrier-specific tweaks.

Standard cyber exclusions also include:

  • Bodily injury and tangible property damage (those go on GL or specialty bodily injury cyber)
  • Patent and trade secret infringement (separate IP coverage)
  • Acts of war, kinetic war, hostile acts (with state-sponsored cyber carve-outs, see above)
  • Failure of utility infrastructure (with limited carve-backs)
  • Unencrypted devices for some breach scenarios (with sub-limits)
  • Pre-existing breaches known to the insured at policy inception
War exclusion litigation

Merck's NotPetya litigation against its property insurers (resolved in 2022 in Merck's favor) tested the war exclusion in the property context. The cyber-specific exclusions written since are partly a response, drafted to remove the ambiguity that opened the door for Merck's coverage win. Read the war exclusion in any cyber policy carefully. The drafting still varies meaningfully across the market.

§ 09

How underwriters evaluate the risk

  1. Industry and data type. Healthcare, financial services, retail, manufacturing, education, government, professional services. Each has different breach exposure profiles and regulatory regimes.
  2. Revenue and record count. Sets the baseline for limit adequacy and notification cost potential.
  3. Controls. Application + supplemental + scan data + evidence. The underwriter wants to know whether MFA is universal or just on email, whether EDR is on every endpoint, whether backups have been tested in the last 90 days.
  4. Loss history. Prior incidents, prior claims, prior near-misses. A buyer with a prior breach has to demonstrate post-incident remediation.
  5. Vendor concentration. Critical vendors with system access, payment processors, cloud and SaaS dependencies.
  6. Tower. Excess limits behavior is similar to casualty. Lead carriers are the most engaged on controls; excess layers follow form.

Ideal submission pack

DocumentPurpose
Cyber applicationCarrier-specific; long
Controls supplemental50-100 questions on technical controls
Network diagramArchitecture and segmentation
External scan reportBitSight / SecurityScorecard / similar
SOC 2 / ISO 27001 reportsWhere applicable
Incident response planPlan and table-top history
Prior loss runsCyber-specific incident history
Privacy policy and breach notification proceduresRegulatory readiness
§ 10

Where IDP earns its keep

Cyber underwriting has the longest application of any commercial line. The application plus the controls supplemental plus the carrier-specific addenda can run 60-150 pages. Triaging that volume across thousands of submissions per year is one of the most painful broker-and-underwriter pain points in the industry. Cyber claims documentation is also dense: forensic reports, breach counsel memoranda, ransom notes, FBI IC3 filings, restoration vendor statements.

01
Intake
App + supp + scans + supporting docs.
02
Classify
Doc types, app sections.
03
Extract
Controls answers, revenue, records, exposures.
04
Validate
Cross-check app vs scan, flag inconsistencies.
05
Triage
Controls floor, appetite, knockout flags.
06
Underwriter
Pre-populated workspace + scan summary.

The cyber workflows where Indico shows up

  • Application normalization. Carrier-specific 80-question apps and 120-question supplementals into a normalized control profile that surfaces gaps against the carrier's controls floor.
  • Scan-vs-application reconciliation. Compare external scan findings (open services, expired certs, unpatched CVEs) against application answers. Flag inconsistencies for underwriter review.
  • Forensic report extraction. Pull root cause, attack vector, timeline, indicators of compromise, scope of data accessed, from incident response reports to support claim adjudication.
  • Vendor inventory parsing. Identify critical vendors named in application, map to known systemic risk lists.
  • Renewal application diff. Compare expiring application to renewal, surface control changes, exposure changes, scope creep.
Where the demo lands

For cyber carriers, the highest-leverage demo is application + supplemental + scan running through one normalized output that surfaces the underwriter's three or four key control questions on page one. The underwriter then drills only where the data disagrees. That single pattern compresses cyber underwriting time meaningfully, because most accounts are clean and the underwriter only needs to spend time on the ones that are not.

Chapter 14 · Specialty / Financial · 22 min read

Cyber — Cheat Sheet

Cyber is the youngest major commercial line and the most reactive. Every wave of attacker behavior reshapes wording. Every controls failure reshapes appetite. This chapter walks first-party vs third-party, the controls underwriters now require, and what is actually inside a cyber tower today.

The mental model: Cyber covers a risk that is moving. Other lines insure stable underlying exposures (a building does not change, an employee does not change). Cyber insures a risk where the threat actors innovate continuously, the technology stack changes monthly, and the regulatory environment is in motion. Carriers that win in cyber have a tight feedback loop between claims, threat intelligence, and underwriting.

Watch for

Key terms

BEC · Business Email Compromise
EDR · Endpoint Detection & Response
MFA · Multi-Factor Authentication
PAM · Privileged Access Management
RTO/RPO · Recovery Time / Point Objective
ERP · Extended Reporting Period
BI · Business Interruption
IR · Incident Response

If you remember three things

Cyber is claims-made, controls-driven, and aggregation-aware. MFA is the price of admission. Read the war exclusion every time.