Back to blog

Cyber insurance: what does it really cover? First-party costs, liability, business interruption, extortion

The six sections of a cyber policy, what is almost always excluded, and how to read the sub-limits that decide what actually gets paid.

Loïc Carbonne·8 min read

Cyber insurance covers six families of costs: your own first-party expenses after an attack (forensics, restoration, notifications), your liability to third parties whose data was exposed, your business interruption while systems are down, extortion, social-engineering fraud and reputational harm. It almost never covers administrative fines, known but unpatched vulnerabilities, or claims reported late. And the number that matters is not the limit printed on the front page, but the sub-limit attached to each individual cover.

What does cyber insurance cover, section by section?

A cyber policy separates "first-party" costs, everything the attack costs you, from cyber liability, everything you owe others because of it. Six sections are spread across those two parts, each with its own limit.

Crisis management funds the emergency response: digital forensics, legal assistance, notification of affected individuals and of the data protection authority (the CNIL in France), communications. Restoration pays to rebuild data and systems. Business interruption compensates the margin lost while systems are unavailable. Extortion covers negotiation and, under conditions, the ransom itself. Cyber liability covers damages and defence costs if a client, or a person whose data you process, claims compensation. Finally, two satellite covers are sold as options: social-engineering fraud (fake transfer orders, fake suppliers) and reputational harm.

Business interruption, in cyber insurance, means the gross margin your company fails to earn while a system is unavailable following a covered incident, plus the extra expenses incurred to keep operating. It kicks in after a waiting period expressed in hours and stops at the end of an indemnity period expressed in months.

Why is cyber liability alone not enough?

Because in a real attack, most of the bill is made up of first-party costs. The 2025 Cyber Threat Overview published by ANSSI, the French cybersecurity agency, records 128 ransomware compromises handled in 2025, 48% of which targeted small, medium and mid-sized businesses, and a 51% rise in confirmed data exfiltrations. In those cases the company first pays its experts, its servers and its days of downtime; a third-party claim may or may not follow.

Yet the "cyber" extensions bolted onto a professional liability policy often cover liability only; for a SaaS vendor, the boundary is detailed in our article on liability for coding errors.

How do you read the sub-limits of a cyber policy?

A sub-limit is a specific cap, lower than the policy's overall limit, applied to a given cover. A €1 million policy may cap extortion at €100,000, fraud at €50,000 and business interruption at €300,000: no single type of loss ever reaches the headline limit. Reading a cyber policy means reading the schedule of cover, not the cover page.

CoverWhat it paysWhat to check
Crisis managementForensics, lawyers, notifications, communicationsPanel vendors or free choice; separate or shared limit
Data restorationRebuilding systems and dataBackups required as a condition of cover
Business interruptionLost gross margin, extra expensesWaiting period (often 8 to 24 hours), indemnity period (3 to 12 months)
ExtortionNegotiation, ransom under conditionsFrequent sub-limit, often 10 to 25% of the limit
Cyber liabilityDamages and defence costs owed to third partiesDefence costs inside the limit or in addition
Social-engineering fraudFake transfers, fake CEO instructionsOptional, sub-limit often €50,000 to €250,000

The deductible is the share of each loss you keep, commonly €2,500 to €10,000 for an SME. The indemnity period is the maximum duration over which business interruption is paid: three months is short when rebuilding systems takes six weeks.

Does cyber insurance really reimburse a ransom?

Yes, under strict conditions, never automatically. Since the French law of 24 January 2023 known as LOPMI, article L12-10-1 of the Insurance Code makes indemnification of losses caused by an attack on an automated data processing system conditional on filing a criminal complaint within 72 hours of becoming aware of the attack. The provision covers all of a business's cyber losses, not just the ransom: with no complaint within the deadline, the insurer may decline the entire claim.

Insurers then require that any payment be decided with them, after screening the criminal group against international sanctions lists. Insurance does not replace offline backups: it funds the time and expertise needed to restore without paying.

The limit of a cyber policy is the headline; the sub-limits, waiting periods and conditions of cover are the text. The text is what the insurer will read on the day of the loss.

What is almost always excluded from cyber insurance?

Four exclusions appear everywhere. Fines and administrative penalties, including those imposed by the CNIL: on 18 March 2025, the French insurance regulator ACPR reiterated that a clause covering financial penalties imposed by an administrative authority would be contrary to public policy, and therefore void. Known vulnerabilities left unpatched beyond the period set by the policy, often 30 to 60 days after the fix is released. War and acts attributed to a State. Lastly, breaches of the conditions declared in the questionnaire: no multi-factor authentication, untested backups, unmaintained antivirus.

More discreetly, the failure of an external infrastructure (power or telecom outage, incident at your hosting provider) is excluded or capped by most insurers. Business interruption caused by your supplier falls under a "dependent business" or "external providers" extension that must be requested explicitly.

What does cyber insurance cost an SME in 2026?

The market has softened. The LUCY 2026 study by AMRAE, the French risk managers' association, measures a 23% drop in the average premium of mid-sized companies and 32% for large corporates over 2025, with 97% more medium-sized businesses insured. Meanwhile, claims on the French market rose from €54.5 million to €83.2 million: insurers cut prices for well-run files and decline the others.

ProfileUsual limitIndicative annual premiumCommon deductible
SME, 10 to 50 employees, turnover < €10M€250,000 to €1M€1,200 to €4,000€2,500 to €5,000
SME, 50 to 250 employees, turnover €10M to €50M€1M to €3M€4,000 to €15,000€5,000 to €10,000
SaaS or fintech scale-up, sensitive data€2M to €5M€8,000 to €30,000€10,000 to €25,000
Mid-sized company (LUCY 2026 average)€4.2MDown 23% over 2025Down 17%

These ranges are orders of magnitude; the actual price depends on your sector, the data you process and above all your demonstrated maturity: MFA everywhere, EDR on the whole estate, tested offline backups. These are also the requirements of NIS2, detailed in our article on NIS2, DORA and SME cyber insurance. A company exposed to supplier payments will add the fraud cover: account takeover accounted for 21% of the threats against businesses handled by Cybermalveillance.gouv.fr in 2025, and wire-transfer fraud rose 93% in one year.

Frequently asked questions

Is cyber insurance mandatory for an SME?

No, no law requires it. It is, however, increasingly demanded by contract: tenders, large clients subject to NIS2 or DORA, investors during a funding round.

Does my property or professional liability policy already cover cyber risk?

Rarely beyond a limited extension. Professional liability covers what you owe your clients, not your own costs after an attack. A commercial property policy generally excludes financial loss without physical damage, and has often carried an explicit cyber exclusion since 2022.

What is the difference between limit, sub-limit and deductible?

The limit is the maximum the insurer pays for the whole policy, per claim or per year. The sub-limit is a lower maximum applied to one specific cover, such as extortion or fraud. The deductible is the share of each loss that stays with you.

What should I do in the first hours of an attack to preserve cover?

Call the insurer's emergency line before any other provider, pay or negotiate nothing on your own, isolate systems without wiping them to preserve evidence, file a criminal complaint within 72 hours and notify the CNIL within the same period if personal data is involved.

At Lesto, we read a cyber policy through its schedule of cover: sub-limits, waiting period, indemnity period, conditions of cover, external providers. We consult nine insurers on average per file and deliver our analysis within 72 hours. Want to know what your policy really covers? Discover our cyber insurance offer and request your analysis.

Recommended coverage

Our offers

The coverages we recommend most often to businesses.

Tags

  • #cyber insurance
  • #cyber risk
  • #SME
  • #ransomware
  • #business interruption
Loïc Carbonne

Loïc Carbonne

CTO

Loïc is passionate about tech, code and artificial intelligence. He is building the platform that allows Lesto's clients to be properly insured.

LinkedIn →