Cyber Insurance — Data Breach & Business Interruption

Cyber Insurance:
Data Breach and Business Interruption Coverage

Cyber insurance does not cover IT security expenditures — it covers the financial consequences arising after an incident occurs. Keeping this distinction clear and structuring the right coverage is a core part of Neolife's broker expertise.

IIEA (SEDDK) Licensed Insurance Broker SBD Member First-party losses + third-party liability coverage design KVKK compliance integration

Coverage and quotation at a glance

Cyber insurance may cover response costs, data breach liability, and business interruption losses arising from cyber events defined in the policy. Neolife structures coverage based on your operations, data types, security controls, and existing policies. Ransom, social engineering, and sanctions conditions are reviewed separately.

What cyber insurance is not

Cyber insurance is not an IT security solution. It does not purchase firewalls, EDR software, penetration tests, or security training. Cyber insurance's function, in a single sentence, is this: to cover, within defined limits, the financial consequences arising after a cyber incident occurs.

This distinction is critical for both policy design and underwriting assessment. Insurers offer broader coverage and more reasonable premiums to companies with strong security controls — because they position insurance as a complement to security, not a substitute for it.

First-Party Losses and Third-Party Liability: the coverage distinction

To understand how cyber policies are structured, this fundamental distinction must be grasped first.

First Party

Insured's Own Losses (First-Party)

  • Damage to the insured's own data and systems
  • Business interruption (BI) from the insured's own systems going offline due to a cyber event
  • Data recovery and system restoration costs
  • Ransomware payment — subject to policy and sanctions conditions
  • Incident Response costs, digital forensics fees, PR expenses
  • Notification and credit monitoring costs for affected individuals
  • Cyber extortion
Third Party

Third-Party Liability

  • Claims by customers and third parties for data loss
  • Privacy liability claims arising from data breaches
  • Network security liability — malicious code propagation, denial of service
  • KVKK defence costs and claims from affected individuals
  • Media liability — third-party harm from content
  • Legal costs in regulatory investigations

Common mistake: Some companies purchase only first-party or only third-party coverage. In most real cyber incidents, both dimensions are activated simultaneously — your own systems can go down while customer data is also leaked. Both layers of coverage must be designed together.

Coverage headings

First-Party

🔐Data Breach & Personal Data Exposure

Personal data exposure following unauthorised access or an attack. Notification costs, identity theft monitoring, and costs for affected individuals.

First-Party

💻System Damage & Recovery

Recovery of data corrupted or deleted by malware or a cyber attack, and restoration of systems and software infrastructure.

First + Third

⏸Business Interruption

Revenue loss due to a cyber event. A waiting period applies. First-party BI (own system outage) and Contingent BI (supplier/cloud outage) are assessed separately.

First-Party

🚨Incident Response Costs

Digital forensics, legal advisory, crisis communications and PR, customer notification coordination. Most policies provide 24/7 IR hotline support.

Third-Party

⚖️KVKK & Privacy Liability

Defence costs arising from personal data breaches, claims by data subjects, and legal costs in regulatory investigations. Administrative fines are generally excluded.

Third-Party

🌐Network Security Liability

Harm caused to third parties by malicious code propagating from the insured's network, or by denial-of-service (DDoS) attacks.

Optional

👤Social Engineering & Funds Transfer Fraud (FTF)

Authorised funds transfer fraud through fake identity or manipulation. A sub-limit applies; some insurers direct this risk to a crime policy.

Optional

☁️Supplier / Cloud Dependency

Business interruption loss from outage of a third-party service provider (cloud, SaaS, data centre). Offered as Dependent BI or Contingent BI; not a standard coverage.

Ransomware and Cyber Extortion: the most critical coverage point

Ransomware coverage is the most complex and most frequently questioned section of a cyber policy. The assumption that "the ransom is always paid" is incorrect — the limits of coverage are clear.

Ransomware Coverage: Limits and Conditions

Every heading you must clarify with your insurer when obtaining cyber extortion coverage
Sanctions List Risk
Ransom payments to entities or individuals on OFAC, UN, and EU sanctions lists are excluded. Making such payments creates additional legal sanctions risk. Even where the attacker's identity is unknown, the insurer will carry out a sanctions compliance check.
Insurer Approval
Most cyber policies require the insurer to be notified and to give approval before a ransom payment is made. A payment made without approval may result in claim denial. First step after an incident: call your insurer.
Ransom Sub-Limit
Ransom payments are typically subject to a separate sub-limit well below the policy's aggregate limit. For example, on a policy with a limit of TRY 10 million, the ransom sub-limit might be only TRY 2 million.
No Guarantee of Recovery
Paying the ransom does not guarantee systems will be restored. Insurers commonly treat the unavailability of recovery alternatives (backups, system rebuild) as a precondition before approving payment.
Ransom Decision
The payment decision is made jointly by the insurer and the insured. The insurer may participate in managing the process by appointing forensic specialists and negotiators — this right is stated in the policy wording.

* The conditions above vary by insurer and policy wording. Neolife compares different insurers' approaches and recommends the most appropriate structure.

Business Interruption: cyber-caused

Cyber Business Interruption (Cyber BI) coverage compensates for revenue loss caused solely by systems being offline, without requiring physical damage. This is the key distinction from traditional business interruption insurance.

6–12 hrs
Waiting Period

Systems must be offline for at least this long before indemnity begins. A shorter waiting period means a higher premium.

30–90 days
Maximum Indemnity Period

Even if systems remain offline longer, insurance only covers revenue loss for this duration. Varies by policy.

Sub-Limit
Contingent BI

A separate and lower sub-limit typically applies for outages caused by a supplier or cloud provider. Not all insurers offer this coverage.

Own systems vs. supplier?

When the company's own systems go offline, first-party BI is triggered. When your operations stop because a cloud provider such as AWS, Azure, or Google Cloud experiences an outage, the applicable coverage is Contingent BI / Dependent BI. Both coverages may exist on the same policy, but Contingent BI is typically optional and subject to a sub-limit. Companies with high cloud dependency must specifically request its inclusion in the quotation.

KVKK and privacy liability: not fines, but defence costs

Cyber insurance and KVKK (Turkey's Personal Data Protection Law) obligations are frequently confused. Knowing the clear distinction allows you to set the right expectations from your policy.

✓ Cyber policy may cover

  • Legal advisory and defence costs arising from KVKK breaches
  • Legal fees incurred during a Personal Data Protection Board (KVKK) investigation
  • Notification and communication costs to affected data subjects
  • Liability in compensation claims brought by data subjects
  • Identity theft monitoring services (for affected individuals)

✗ Typically excluded

  • KVKK administrative fines (public policy principle)
  • Fines from intentional violations
  • Cost of creating data privacy policies
  • KVKK compliance consulting fees (preventive)

Supplier-caused data breach and liability

Under KVKK, the data controller is the party holding control over the processing activity. If a personal data breach occurs through a security vulnerability at one of your data processors (a software firm, outsourcing partner, or cloud provider), KVKK obligations still fall on you: 72-hour notification to the Personal Data Protection Board, notification to affected individuals, and potential liability.

The privacy liability and network security liability coverages in a cyber policy may cover this scenario. The allocation of responsibility in supplier contracts and the scope of the policy must be evaluated together.

Cyber crime policy vs. cyber insurance: the difference

Although the two products appear similar, the risks and loss types they cover differ. Some scenarios may require both; others fall under only one.

Scenario Cyber Insurance Crime / BBB Notes
External hacker entering the system and encrypting data Cyber — Typical ransomware / data breach scenario
Employee wiring funds following a fake CEO email Cyber (sub-limit) Crime — broader coverage Social engineering — crime policy may provide clearer coverage
Insider stealing customer data Cyber (partial) Crime — employee dishonesty Both policies' boundaries should be reviewed together
Personal data breach + claim by affected individual Cyber — Privacy liability and KVKK defence costs
Loss caused by breach of a supplier's system Cyber (Contingent BI) — Requires Contingent BI optional coverage
Physical cryptocurrency / cash theft — Crime Outside cyber policy scope — physical asset loss
Hacker + insider crime together (coordinated attack) Cyber Crime Overlap risk — coverage boundaries of both insurers must be clarified

Limit structure: aggregate, sub-limits and waiting period

Annual Aggregate Limit

The total upper limit applicable to all claims during the policy year. All coverage items (BI, ransom, IR costs) are counted together against this limit.

Sub-Limit

An upper ceiling set below the aggregate limit for specific coverage items. Ransom payments, social engineering, and Contingent BI are typically subject to sub-limits.

Deductible / Retention

The first-loss amount borne by the insured for each claim. A higher deductible lowers the premium but may leave small incidents uncovered.

Waiting Period

The minimum time systems must be offline before business interruption indemnity begins. 6–12 hours is common; shorter options are possible at higher premium.

Note — retroactive date: Cyber policies also operate on a claims-made basis. Claims arising from a breach that was known or occurred before the retroactive date are excluded. When changing insurer, preserving the retroactive date and declaring prior known circumstances is mandatory.

Post-incident notification and breach response process

In a cyber incident, speed directly affects both the right to indemnity and legal obligations. KVKK imposes a 72-hour notification requirement; policies may also provide for loss of rights on delayed notification.

1

Detect and Isolate the Incident

Isolate affected systems and stop the spread of the attack. This step starts the clock for policy notification.

2

Call Your Insurer and Broker

Notify your insurer before making any payment, including ransom. Most policies require approval; failure to obtain it may forfeit the right to indemnity. Neolife takes over coordination in this process.

3

Engage the Digital Forensics Team

The insurer's approved IR firm or the policy's covered forensic team determines the incident scope, attack vector, and data exposure. A system image must be taken to preserve evidence.

4

KVKK Notification

If personal data is involved, notification to the Personal Data Protection Board within 72 hours is mandatory. Whether notification to affected individuals is required is assessed separately. Legal counsel must be involved in managing the process.

5

Crisis Communications and PR

If customer, media, and public communications are mishandled, reputational harm can exceed the incident itself. A cyber policy may cover PR and crisis communications costs; these specialists work alongside the IR team.

6

Loss Assessment and Claims Process

Business interruption and direct loss are assessed based on the forensic team's report and accounting records. Complete documentation directly affects the speed and amount of indemnity.

What does the Underwriter require from you?

During the cyber quotation process, insurers complete a questionnaire assessing the company's security controls. The status of these controls directly determines premium, limits, and even whether a quotation is offered.

Cyber Readiness Checklist

If the controls below are absent, the quotation may be declined, sub-limits may be applied, or the premium may rise significantly. Honestly disclosing the current status at the quotation stage is both a legal obligation and a coverage guarantee.

Multi-Factor Authentication (MFA)

Mandatory on remote access (VPN, RDP), email, and privileged accounts. The absence of MFA alone may result in quote rejection.

Critical

EDR / XDR (Endpoint Detection & Response)

Current EDR solution on all workstations and servers. Traditional antivirus is not considered sufficient.

Critical

Offline & Encrypted Backups

Offline, air-gapped, or immutable backup that ransomware cannot reach. Cloud backup alone is not sufficient.

Critical

Patch Management

Regular patching policy for operating systems and critical applications. A maximum of 30 days for critical patches is a common expectation.

High

Privileged Access Management (PAM)

Admin accounts not used for standard work, just-in-time access, privileged session recording.

High

Phishing Awareness Training

Regular simulated phishing tests and an employee awareness programme. Generally a prerequisite for social engineering coverage.

High

Incident Response Plan (IRP)

Written and tested incident response plan covering who to call, which systems to isolate, and the notification chain.

High

Network Segmentation

Isolation of critical systems (OT, finance, customer data) from the business network. A key control that limits ransomware propagation.

Medium

Email Security (SPF / DKIM / DMARC)

Core protocols against phishing and email spoofing. A DMARC policy set to "reject" mode is the expected standard.

Medium

Supplier Security Assessment

Periodic assessment of critical suppliers' security controls. Particularly scrutinised for companies with high cloud and SaaS dependency.

Medium

Disclosure obligation: Inaccurate or incomplete disclosure of existing security controls in the insurance application gives the insurer grounds to deny indemnity at the time of a claim. Neolife supports you in managing the disclosure process correctly.

Frequently asked questions

Does cyber insurance cover IT security expenditures?
No. Cyber insurance covers the financial consequences of an actual incident — it does not finance security infrastructure, licences, or preventive investments. Preventive security controls do, however, directly affect premium, coverage scope, and underwriting decisions.
Is a ransomware payment covered under cyber insurance?
Conditionally and with limits. Critical restrictions apply: sanctions-list screening, insurer pre-approval, and sub-limit application. The assumption that "payment is always covered" is incorrect. The ransom decision is made jointly with the insurer; a payment made without insurer approval may result in claim denial.
Are fines arising from a KVKK breach covered by insurance?
Administrative fines are typically excluded. However, defence costs, legal advisory fees, notification costs to affected individuals, and liability arising from compensation claims may be covered by the policy.
Is social engineering fraud and funds transfer fraud covered under a cyber policy?
Some cyber policies may include it under a sub-limit, but this is not standard. A Crime policy or BBB often provides clearer and broader coverage for this risk. The overlaps and gaps between the two policies should be reviewed together.
Is business interruption caused by a cloud provider outage covered under cyber insurance?
Some policies include Contingent BI / Dependent Business Interruption coverage, but it is optional and subject to a sub-limit. Companies with high cloud dependency should specifically request this coverage in the quotation.
Can I get a quotation without MFA?
In the vast majority of cases, no — or only with very limited coverage and a very high premium. MFA — especially for remote access and privileged accounts — has become an almost universal prerequisite for cyber insurance today. The absence of this control is among the most common reasons for quote rejection.

Related pages