August 27, 2026 ยท by David Gilbert ยท 3 min read ยท Cyber Security
Cyber insurance comes up in a meaningful share of my small business conversations, usually framed as a straightforward safety net โ pay a premium, sleep easier about the risk. The honest, slightly less comfortable truth is more nuanced than that, and I think small businesses deserve the nuanced version rather than the comforting one.
What Cyber Insurance Actually Covers
Policies vary considerably, but decent ones can help with incident response costs, certain legal and notification obligations, and sometimes a portion of business interruption losses following a genuine cyber incident. That's genuinely valuable protection, and I'm not arguing against having a policy at all for businesses that can reasonably afford one.
The Question Nobody Likes Answering
The uncomfortable question is this: have you actually read your specific policy's conditions closely enough to know what's required of you for a claim to actually be honoured? Plenty of policies have meaningful conditions attached โ specific minimum security measures, particular reporting timeframes, certain documented practices โ and failing to meet them can mean a claim gets reduced or denied entirely, right at the exact moment you most need it to pay out.
Why This Gets Skipped So Often
Insurance paperwork is genuinely tedious, and it's tempting to treat a policy as a generic, simple safety net rather than reading the specific fine print closely enough to understand exactly what's actually required of you in return for that protection. I understand the temptation completely. It's also exactly how a business ends up believing it's covered for something it actually isn't, right when the gap matters most.
What I Actually Tell Clients
Insurance is a genuinely reasonable backstop for a worst-case scenario, not a substitute for the basic, ongoing security practices that meaningfully reduce how likely you are to need it in the first place. And if you do hold a cyber insurance policy, it's worth the slightly tedious effort of actually understanding its specific conditions now, while you're calm, rather than discovering them for the first time mid-crisis when a claim is on the line.
The Bigger Pattern I See
Insurance, in general, works best as a backstop behind genuinely good underlying practices, not as a replacement for them โ and cyber insurance is no different from any other category in that respect. A business with solid basic security and a cyber policy is in a genuinely strong position. A business relying purely on the policy, with weak underlying practices, is in a considerably weaker position than the premium payment alone might make them feel.
What I'd Actually Recommend Doing This Week
If you hold a policy, actually read the specific conditions section properly, not just the marketing summary, and check honestly whether your business genuinely meets every condition right now, today, not in some vague, eventually-we'll-get-to-it sense. If you don't hold one, the basic security fundamentals matter considerably more in the meantime, because they're doing all of the actual protective work on their own until a policy is in place.
The Honest Bottom Line
Cyber insurance is a genuinely reasonable, sensible tool for plenty of small businesses. It is not, and was never designed to be, a substitute for actually doing the basic security work โ and the businesses that get the most genuine value from a policy are reliably the ones treating it as a backstop behind real practices, not as the primary, entire plan on its own.