What Cyber Insurance Actually Covers in 2026 - and What It Quietly Excludes

by ryskly Team
CyberInsuranceCoverageExclusionsSME

Most buyers read the coverage limit and stop. The document that matters is the exclusions list - it decides whether your worst month ends with a wire transfer from your insurer or a polite decline letter.

What a standard cyber policy covers

Nearly every cyber policy on the market covers a core set of first-party costs:

  • Incident response - forensics, containment, recovery specialists
  • Data restoration - rebuilding systems and data after an attack
  • Business interruption - lost income while systems are down
  • Notification & credit monitoring - legal obligations after a breach
  • Cyber extortion - ransom negotiation and (where legal) payment
  • Third-party liability - claims from customers whose data you lost

So far, so uniform. The differences start below the surface.

Where policies quietly diverge

Across the 682 products we track on Ryskly, the spread is wide:

  • Cyber crime and funds-transfer fraud: only 332 products (49%) explicitly cover it. This is the coverage that pays when an employee is tricked into wiring money to a fraudster - the single most common SME loss scenario. Half the market treats it as an optional add-on.
  • Technology E&O combined: 162 products (24%) bundle professional liability for tech firms with cyber. If you ship software, this distinction decides which policy responds when your product causes a client's breach.
  • GenAI-related risks: just 76 products (11%) address losses tied to generative-AI use - leaked prompts, model poisoning, AI-generated fraud. The market is only starting to price this.

The exclusions that bite

Four clauses cause most declined claims:

  1. War and state-sponsored attacks. Nearly every policy carries a war exclusion; the fight is over attribution. After NotPetya, insurers litigated for years over whether a Russian military cyberattack on Ukraine that spilled worldwide was "war." Read how your policy defines it - the wording varies enormously between carriers.
  2. Failure to maintain security. If you claimed MFA on the application and an auditor finds none, expect a denial for misrepresentation.
  3. Prior known incidents. Breaches that began before the policy period are excluded - and attackers often dwell in networks for months.
  4. Social engineering sublimits. Even when funds-transfer fraud is covered, it is often capped at €50,000–€250,000 - far below the headline limit.

How to read a policy in 15 minutes

Skip the marketing summary. Go straight to: definitions of "computer system" and "war"; the schedule of sublimits; conditions precedent (what you must maintain for coverage to hold); and the claims notification window. Those four sections tell you more than everything else combined.

Then compare across the market instead of trusting one quote: browse products by country on Ryskly - we list coverage extensions, war-exclusion wording and market focus for every product we track.