Coverage and quotation at a glance
Cyber insurance may cover response costs, data breach liability, and business interruption losses arising from cyber events defined in the policy. Neolife structures coverage based on your operations, data types, security controls, and existing policies. Ransom, social engineering, and sanctions conditions are reviewed separately.
What cyber insurance is not
Cyber insurance is not an IT security solution. It does not purchase firewalls, EDR software, penetration tests, or security training. Cyber insurance's function, in a single sentence, is this: to cover, within defined limits, the financial consequences arising after a cyber incident occurs.
This distinction is critical for both policy design and underwriting assessment. Insurers offer broader coverage and more reasonable premiums to companies with strong security controls — because they position insurance as a complement to security, not a substitute for it.
First-Party Losses and Third-Party Liability: the coverage distinction
To understand how cyber policies are structured, this fundamental distinction must be grasped first.
Insured's Own Losses (First-Party)
- Damage to the insured's own data and systems
- Business interruption (BI) from the insured's own systems going offline due to a cyber event
- Data recovery and system restoration costs
- Ransomware payment — subject to policy and sanctions conditions
- Incident Response costs, digital forensics fees, PR expenses
- Notification and credit monitoring costs for affected individuals
- Cyber extortion
Third-Party Liability
- Claims by customers and third parties for data loss
- Privacy liability claims arising from data breaches
- Network security liability — malicious code propagation, denial of service
- KVKK defence costs and claims from affected individuals
- Media liability — third-party harm from content
- Legal costs in regulatory investigations
Common mistake: Some companies purchase only first-party or only third-party coverage. In most real cyber incidents, both dimensions are activated simultaneously — your own systems can go down while customer data is also leaked. Both layers of coverage must be designed together.
Coverage headings
Data Breach & Personal Data Exposure
Personal data exposure following unauthorised access or an attack. Notification costs, identity theft monitoring, and costs for affected individuals.
System Damage & Recovery
Recovery of data corrupted or deleted by malware or a cyber attack, and restoration of systems and software infrastructure.
Business Interruption
Revenue loss due to a cyber event. A waiting period applies. First-party BI (own system outage) and Contingent BI (supplier/cloud outage) are assessed separately.
Incident Response Costs
Digital forensics, legal advisory, crisis communications and PR, customer notification coordination. Most policies provide 24/7 IR hotline support.
KVKK & Privacy Liability
Defence costs arising from personal data breaches, claims by data subjects, and legal costs in regulatory investigations. Administrative fines are generally excluded.
Network Security Liability
Harm caused to third parties by malicious code propagating from the insured's network, or by denial-of-service (DDoS) attacks.
Social Engineering & Funds Transfer Fraud (FTF)
Authorised funds transfer fraud through fake identity or manipulation. A sub-limit applies; some insurers direct this risk to a crime policy.
Supplier / Cloud Dependency
Business interruption loss from outage of a third-party service provider (cloud, SaaS, data centre). Offered as Dependent BI or Contingent BI; not a standard coverage.
Ransomware and Cyber Extortion: the most critical coverage point
Ransomware coverage is the most complex and most frequently questioned section of a cyber policy. The assumption that "the ransom is always paid" is incorrect — the limits of coverage are clear.
Ransomware Coverage: Limits and Conditions
* The conditions above vary by insurer and policy wording. Neolife compares different insurers' approaches and recommends the most appropriate structure.
Business Interruption: cyber-caused
Cyber Business Interruption (Cyber BI) coverage compensates for revenue loss caused solely by systems being offline, without requiring physical damage. This is the key distinction from traditional business interruption insurance.
Systems must be offline for at least this long before indemnity begins. A shorter waiting period means a higher premium.
Even if systems remain offline longer, insurance only covers revenue loss for this duration. Varies by policy.
A separate and lower sub-limit typically applies for outages caused by a supplier or cloud provider. Not all insurers offer this coverage.
Own systems vs. supplier?
When the company's own systems go offline, first-party BI is triggered. When your operations stop because a cloud provider such as AWS, Azure, or Google Cloud experiences an outage, the applicable coverage is Contingent BI / Dependent BI. Both coverages may exist on the same policy, but Contingent BI is typically optional and subject to a sub-limit. Companies with high cloud dependency must specifically request its inclusion in the quotation.
KVKK and privacy liability: not fines, but defence costs
Cyber insurance and KVKK (Turkey's Personal Data Protection Law) obligations are frequently confused. Knowing the clear distinction allows you to set the right expectations from your policy.
✓ Cyber policy may cover
- Legal advisory and defence costs arising from KVKK breaches
- Legal fees incurred during a Personal Data Protection Board (KVKK) investigation
- Notification and communication costs to affected data subjects
- Liability in compensation claims brought by data subjects
- Identity theft monitoring services (for affected individuals)
✗ Typically excluded
- KVKK administrative fines (public policy principle)
- Fines from intentional violations
- Cost of creating data privacy policies
- KVKK compliance consulting fees (preventive)
Supplier-caused data breach and liability
Under KVKK, the data controller is the party holding control over the processing activity. If a personal data breach occurs through a security vulnerability at one of your data processors (a software firm, outsourcing partner, or cloud provider), KVKK obligations still fall on you: 72-hour notification to the Personal Data Protection Board, notification to affected individuals, and potential liability.
The privacy liability and network security liability coverages in a cyber policy may cover this scenario. The allocation of responsibility in supplier contracts and the scope of the policy must be evaluated together.
Cyber crime policy vs. cyber insurance: the difference
Although the two products appear similar, the risks and loss types they cover differ. Some scenarios may require both; others fall under only one.
| Scenario | Cyber Insurance | Crime / BBB | Notes |
|---|---|---|---|
| External hacker entering the system and encrypting data | Cyber | — | Typical ransomware / data breach scenario |
| Employee wiring funds following a fake CEO email | Cyber (sub-limit) | Crime — broader coverage | Social engineering — crime policy may provide clearer coverage |
| Insider stealing customer data | Cyber (partial) | Crime — employee dishonesty | Both policies' boundaries should be reviewed together |
| Personal data breach + claim by affected individual | Cyber | — | Privacy liability and KVKK defence costs |
| Loss caused by breach of a supplier's system | Cyber (Contingent BI) | — | Requires Contingent BI optional coverage |
| Physical cryptocurrency / cash theft | — | Crime | Outside cyber policy scope — physical asset loss |
| Hacker + insider crime together (coordinated attack) | Cyber | Crime | Overlap risk — coverage boundaries of both insurers must be clarified |
Limit structure: aggregate, sub-limits and waiting period
Annual Aggregate Limit
The total upper limit applicable to all claims during the policy year. All coverage items (BI, ransom, IR costs) are counted together against this limit.
Sub-Limit
An upper ceiling set below the aggregate limit for specific coverage items. Ransom payments, social engineering, and Contingent BI are typically subject to sub-limits.
Deductible / Retention
The first-loss amount borne by the insured for each claim. A higher deductible lowers the premium but may leave small incidents uncovered.
Waiting Period
The minimum time systems must be offline before business interruption indemnity begins. 6–12 hours is common; shorter options are possible at higher premium.
Note — retroactive date: Cyber policies also operate on a claims-made basis. Claims arising from a breach that was known or occurred before the retroactive date are excluded. When changing insurer, preserving the retroactive date and declaring prior known circumstances is mandatory.
Post-incident notification and breach response process
In a cyber incident, speed directly affects both the right to indemnity and legal obligations. KVKK imposes a 72-hour notification requirement; policies may also provide for loss of rights on delayed notification.
Detect and Isolate the Incident
Isolate affected systems and stop the spread of the attack. This step starts the clock for policy notification.
Call Your Insurer and Broker
Notify your insurer before making any payment, including ransom. Most policies require approval; failure to obtain it may forfeit the right to indemnity. Neolife takes over coordination in this process.
Engage the Digital Forensics Team
The insurer's approved IR firm or the policy's covered forensic team determines the incident scope, attack vector, and data exposure. A system image must be taken to preserve evidence.
KVKK Notification
If personal data is involved, notification to the Personal Data Protection Board within 72 hours is mandatory. Whether notification to affected individuals is required is assessed separately. Legal counsel must be involved in managing the process.
Crisis Communications and PR
If customer, media, and public communications are mishandled, reputational harm can exceed the incident itself. A cyber policy may cover PR and crisis communications costs; these specialists work alongside the IR team.
Loss Assessment and Claims Process
Business interruption and direct loss are assessed based on the forensic team's report and accounting records. Complete documentation directly affects the speed and amount of indemnity.
What does the Underwriter require from you?
During the cyber quotation process, insurers complete a questionnaire assessing the company's security controls. The status of these controls directly determines premium, limits, and even whether a quotation is offered.
Cyber Readiness Checklist
Multi-Factor Authentication (MFA)
Mandatory on remote access (VPN, RDP), email, and privileged accounts. The absence of MFA alone may result in quote rejection.
CriticalEDR / XDR (Endpoint Detection & Response)
Current EDR solution on all workstations and servers. Traditional antivirus is not considered sufficient.
CriticalOffline & Encrypted Backups
Offline, air-gapped, or immutable backup that ransomware cannot reach. Cloud backup alone is not sufficient.
CriticalPatch Management
Regular patching policy for operating systems and critical applications. A maximum of 30 days for critical patches is a common expectation.
HighPrivileged Access Management (PAM)
Admin accounts not used for standard work, just-in-time access, privileged session recording.
HighPhishing Awareness Training
Regular simulated phishing tests and an employee awareness programme. Generally a prerequisite for social engineering coverage.
HighIncident Response Plan (IRP)
Written and tested incident response plan covering who to call, which systems to isolate, and the notification chain.
HighNetwork Segmentation
Isolation of critical systems (OT, finance, customer data) from the business network. A key control that limits ransomware propagation.
MediumEmail Security (SPF / DKIM / DMARC)
Core protocols against phishing and email spoofing. A DMARC policy set to "reject" mode is the expected standard.
MediumSupplier Security Assessment
Periodic assessment of critical suppliers' security controls. Particularly scrutinised for companies with high cloud and SaaS dependency.
MediumDisclosure obligation: Inaccurate or incomplete disclosure of existing security controls in the insurance application gives the insurer grounds to deny indemnity at the time of a claim. Neolife supports you in managing the disclosure process correctly.