Life • Health • Financial Services
Protecting What You Have, Who You Love, and What’s Ahead!
Cyber Liability Insurance

Protection when digital risk becomes a business problem.

Cyber liability insurance can help with qualifying costs and liability following data breaches, network attacks, cyber extortion, business interruption and other covered cyber events.

Laptop displaying cyber security information in an office
Cyber Risk Coverage for certain costs and liabilities after a covered cyber event.
01
Data Breach Response and notification costs
02
Business Interruption Covered cyber shutdowns
03
Cyber Extortion Subject to policy terms
04
Third-Party Liability Claims and legal response
Digital Business Risk

Cyber risk can affect businesses of many sizes.

Businesses may depend on computers, cloud services, payment systems, customer information, employee records and third-party technology providers every day.

A covered cyber event can create recovery expenses for the business and may also lead to claims brought by customers or other parties.

Cyber Insurance Coverage

What may a cyber policy help address?

Cyber policies vary widely. Coverage depends on the policy form, limits, retention, sublimits, conditions and exclusions.

01 / Investigation

Forensic Investigation

Certain policies may help pay qualifying forensic costs used to investigate the nature and extent of a covered cyber event.

02 / Data

Data Recovery

First-party cyber coverage may help with qualifying recovery or replacement costs for lost or compromised data.

03 / Notification

Breach Response

Coverage may include certain notification, call-center, legal and response costs following a covered data incident.

04 / Interruption

Business Income Loss

Certain cyber policies may address qualifying lost income when a covered cyber event interrupts business systems.

05 / Extortion

Cyber Extortion

Cyber policies may include certain response costs connected with qualifying cyber-extortion events, subject to policy conditions.

06 / Liability

Third-Party Claims

Third-party cyber coverage may respond to qualifying claims, litigation and regulatory-response costs connected with a covered event.

Computer monitors displaying code in a dark technology workspace
Incident Response A cyber event can require technical, legal and operational response.
After a Cyber Event

The first costs can appear before a lawsuit ever begins.

A business may need to investigate what happened, contain the incident, restore systems and determine whether notification duties apply.

01
Investigate

Technical specialists may be needed to determine what systems and information were affected.

02
Contain the incident

The business may need technical assistance to limit further unauthorized activity.

03
Restore systems and data

Recovery work may be needed before normal operations can resume.

04
Review notification duties

Legal and regulatory duties depend on the incident, information involved and applicable law.

Cyber Exposure

Digital risk can enter through several parts of a business.

Cyber exposure is not limited to technology businesses. It can follow the systems and information a business uses.

01

Customer Data

Businesses storing personal, financial or account information can face costs and claims after a qualifying data incident.

02

Employee Information

Payroll, personnel and other employee information can also be affected by cyber events.

03

Business Systems

Email, cloud platforms, websites and internal systems can become part of a covered cyber incident.

04

Vendors & Third Parties

Businesses may also depend on outside providers that store data or provide technology services.

Two Sides of Cyber Insurance

First-party costs and third-party liability are different.

A cyber policy may contain one or both types of coverage depending on the product purchased.

First-Party Coverage

Costs incurred by your business.

First-party coverage can address certain direct costs your business faces after a covered cyber event.

Forensic investigation
Data recovery and restoration
Customer notification
Business interruption
Certain cyber extortion and fraud costs
Third-Party Coverage

Liability claims brought against you.

Third-party coverage can address certain claims and legal costs when another party alleges harm following a covered cyber event.

Consumer claims
Litigation expenses
Certain regulatory-response costs
Settlements and judgments when covered
Other covered privacy or network liability
Systems & Information

Cyber exposure follows the technology you depend on.

Insurance discussions may include the systems used by the business, the information stored and the way employees and vendors access it.

01 Customer Information

Personal or account information stored by the business.

02 Employee Records

Payroll, personnel and employment-related information.

03 Cloud Systems

Hosted software, storage and third-party platforms.

04 Payment Technology

Systems used to process qualifying customer transactions.

Computer monitor displaying digital security code
Digital Systems Data, devices and connected systems can all become part of a cyber event.
Business team working at computers in a modern office
Vendors & Third Parties

Your digital operation may extend beyond your own network.

Cloud platforms, software providers, payment processors and other vendors can hold information or provide systems that the business depends on.

01
Cloud providers

Outside platforms may store business or customer information.

02
Software vendors

Business operations may depend on systems maintained by another party.

03
Payment services

Third-party services may be involved in processing customer payments.

04
Policy wording

Review how the policy handles qualifying incidents involving vendors or outside service providers.

Cybersecurity Practices

Insurance works alongside security practices.

Cyber insurance does not replace cybersecurity controls. Insurers may ask about the systems and safeguards used by the business.

01

Multi-Factor Authentication

Additional authentication can reduce reliance on passwords alone.

02

Data Backups

Regular backups can support recovery after certain cyber incidents.

03

Software Updates

Keeping software current helps address known security vulnerabilities.

04

Incident Response Plan

A documented response plan can help organize actions when a cyber event occurs.

Policy Review

Cyber policies can differ in important ways.

01

Coverage Limits

Review overall limits and any lower sublimits applying to individual cyber coverage sections.

02

Retention

Check the amount the business may be responsible for before covered payment begins.

03

Vendor Incidents

Check how the policy addresses qualifying incidents involving outside technology providers.

04

Exclusions

Review excluded events, conditions and security requirements within the policy.

Getting Started

Start with the systems and data your business uses.

Basic technology and business information helps frame the cyber insurance review.

01

Describe the business.

Share business activity, locations and the systems used during daily operations.

02

Identify data and systems.

Review customer data, employee information, cloud systems and key vendors.

03

Review security practices.

Be prepared to discuss backups, access controls, authentication and incident response.

04

Review policy terms.

Check limits, retention, sublimits, vendor coverage and exclusions.

Cyber Liability FAQ

Common questions.

Cyber policy terms can differ considerably between insurers.

Cyber liability insurance can help with certain direct business costs and third-party liability arising from covered cyber events, data breaches or network incidents.

First-party cyber coverage can address certain direct costs to the insured business, such as forensic investigation, data recovery, notification, business interruption and other covered response expenses.

Third-party cyber coverage can address certain liability claims, litigation costs and regulatory-response expenses when another party alleges harm from a covered cyber event.

Businesses should not assume that ordinary general liability or commercial property insurance provides the cyber protection they need. Cyber coverage should be reviewed separately.

Certain cyber policies can include business interruption coverage for qualifying income loss caused by a covered cyber event. Policy triggers and waiting periods may differ.

Information may include the type of business, systems used, data stored, vendors, revenue, security practices, prior cyber incidents and other underwriting information requested by the insurer.

Cyber Liability Insurance

Put cyber coverage around the systems your business relies on.

Tell Trinity about your business, systems, data and technology use to begin reviewing available cyber liability insurance options.

Coverage availability, eligibility, policy terms, limits and exclusions vary by product and carrier. Contact Trinity for product availability and coverage details.