---
title: Cyber Insurance Clauses - Have You Read the Fine Print?
description: Does your Cyber Insurance adequately protect your business? The devil is in the details.
image: https://blog.lmttech.com/hubfs/75951764_s_123rf-1.png
---

[![lmt-logo-rgb1 copy](https://blog.lmttech.com/hs-fs/hubfs/lmt-logo-rgb1%20copy.jpg?width=2932&height=1619&name=lmt-logo-rgb1%20copy.jpg "lmt-logo-rgb1 copy")](https://www.lmttech.com)

# The LMT Blog

## [Cyber Insurance Clauses - Have You Read the Fine Print?](https://blog.lmttech.com/cyber-insurance)

** Sep 10, 2019 12:12:00 PM / by [James Keeler](https://blog.lmttech.com/author/james-keeler)

A client recently reached out to me about their Cyber Insurance coverage asking if the coverage limits looked reasonable. Since Cyber Insurance is a new insurance product, it’s no wonder that there is a lot of mystery around these policies. Let’s take a look at some insights that can help you ask the right questions and make the correct choices for your business when it comes to Cyber Insurance.

Ransomware attacks and data breaches are all over the news; naturally businesses are interested in acquiring coverage to help protect themselves financially from these threats. When evaluating Cyber Insurance, most businesses focus on coverage limits. However, the biggest concern is reviewing the actual policy clauses rather than just the coverage limits. You can have a $5 million policy, but if the claims are denied due to unnoticed clauses in the policy, then the coverage limit doesn’t really matter. The devil is in the details.

Key Items to Look for in a Cyber Insurance Policy:

- **Cyber Extortion/Ransomware**  
  Does the policy only cover the ransom payment, or do you have an option to resolve the incident without paying the ransom and have those costs covered?
- **Data Loss & Recovery**  
  Are lost productivity/business losses covered in the event of malware erasing your files? Are data recovery costs included in the coverage?
- **Civil Suit Coverage**  
  Is reimbursement for defending against civil suits brought by victims of fraud or identity theft resulting from a breach of your business’s data covered?
- **Fines & Breach Notification**  
  Are regulatory fines (HIPAA, NYS DFS, etc.) and/or the costs associated with disclosing, notifying, and providing credit monitoring for victims whose data was lost in a breach of your business data covered?
- **Cyber Terrorism/Act of War Coverage**  
  If a cyberattack is deemed to be the result of a foreign government or terrorist group’s action, will it still be covered? What is the threshold for this determination?
- **Actual Financial Loss & Remediation and Investigation** (value of cash/goods lost due to fraud & IT and legal professional costs)  
  Are both of these items included in coverage, is it an either/or, or is only one side of this covered?

- **Exclusions**  
  Some policies exclude anything that originated from Social Engineering or that might be covered under your general Business Insurance policy. What specifically is not covered under the policy?

Not all policies offer the same coverage and it’s important that you carefully review this new product with your insurance agent to make sure you’re financially protected in the manner you’re expecting. Your Cyber Extortion policy may only cover paying the ransom (which may or may not actually result in restoration of your files) and may not cover the cost for IT professionals (like LMT) to restore data from backups. If that’s the case, you’re gambling that the criminals victimizing you have purchased or written ransomware that can actually restore all your files. There are a large number of reasons the criminals behind the ransomware may not be able to restore the files – see our previous post “[Should I Pay the Ransom?](https://blog.lmttech.com/should-i-pay-the-ransom)” for more details on these.

“Your Cyber Extortion policy may only cover  
paying the ransom and may not cover the cost for  
IT professionals to restore data from backups.”

 

One prime example of a reason to carefully review the Cyber Terrorism/Act of War portions of your coverage is the ongoing case of [Mondelez International, Inc. v. Zurich American Insurance Co.](https://www.nytimes.com/2019/04/15/technology/cyberinsurance-notpetya-attack.html) In this case, Zurich Insurance company is denying a claim for damages caused by the NotPetya “Eraserware” (it was supposed to be ransomware but ended up wiping out the data instead.) Since NotPetya’s development had been attributed to the Russian government as an offensive weapon against Ukraine, Zurich claims that the loss was not covered under the Cyber Insurance policy because it is seen as an “act of war.”

Additionally, claims can be denied if your company isn’t making its best effort to protect their systems. Reviewing what your insurance company requires as adequate effort on your company's part, and understanding the clauses they have in place, is as important as the limits they offer.

Coming up later: "Cyber Insurance: Are Your Limits Enough?"

 

[**James Keeler**](mailto:JKeeler@LMTtech.com), CISSP  
LMT Cybersecurity Manager

![James Keeler-1](https://blog.lmttech.com/hs-fs/hubfs/James%20Keeler-1.jpeg?width=167&name=James%20Keeler-1.jpeg)

[![CONTACT US](https://no-cache.hubspot.com/cta/default/5032426/9d883da3-c6ef-44d8-b5cb-dd5c95bb15e9.png)](https://cta-redirect.hubspot.com/cta/redirect/5032426/9d883da3-c6ef-44d8-b5cb-dd5c95bb15e9)

 

 Topics: [IT](https://blog.lmttech.com/topic/it), [Cyber-Security](https://blog.lmttech.com/topic/cyber-security), [#cyberinsurance](https://blog.lmttech.com/topic/cyberinsurance)

Share on Social:

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fblog.lmttech.com%2Fcyber-insurance%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.lmttech.com%2Fcyber-insurance%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fblog.lmttech.com%2Fcyber-insurance%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fblog.lmttech.com%2Fcyber-insurance%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=)

---

### Subscribe to Email Updates

---

[![New call-to-action](https://no-cache.hubspot.com/cta/default/5032426/8e6ab643-791b-45e2-936c-e1aab416761f.png)](https://cta-redirect.hubspot.com/cta/redirect/5032426/8e6ab643-791b-45e2-936c-e1aab416761f)

---

### Recent Posts

---

### Posts by Topic

- [Cybersecurity (36)](https://blog.lmttech.com/tag/cybersecurity)
- [IT (30)](https://blog.lmttech.com/tag/it)
- [Cyber-Security (22)](https://blog.lmttech.com/tag/cyber-security)
- [security (14)](https://blog.lmttech.com/tag/security)
- [technology (11)](https://blog.lmttech.com/tag/technology)
- [Email Compromise (10)](https://blog.lmttech.com/tag/email-compromise)
- [Business (9)](https://blog.lmttech.com/tag/business)
- [Cybercrime (9)](https://blog.lmttech.com/tag/cybercrime)
- [Phishing (9)](https://blog.lmttech.com/tag/phishing)
- [Small Business (9)](https://blog.lmttech.com/tag/small-business)
- [Cyber Crime (7)](https://blog.lmttech.com/tag/cyber-crime)
- [COVID-19 (5)](https://blog.lmttech.com/tag/covid-19)
- [Coronavirus (5)](https://blog.lmttech.com/tag/coronavirus)
- [Data Privacy (4)](https://blog.lmttech.com/tag/data-privacy)
- [Digital Communication (4)](https://blog.lmttech.com/tag/digital-communication)
- [Information Security (4)](https://blog.lmttech.com/tag/information-security)
- [MFA (4)](https://blog.lmttech.com/tag/mfa)
- [Business Continuity (3)](https://blog.lmttech.com/tag/business-continuity)
- [Data Protection (3)](https://blog.lmttech.com/tag/data-protection)
- [Holidays (3)](https://blog.lmttech.com/tag/holidays)
- [Ransomware (3)](https://blog.lmttech.com/tag/ransomware)
- [Vendor Email Compromise (3)](https://blog.lmttech.com/tag/vendor-email-compromise)
- [#CybersecurityAwarenessMonth (2)](https://blog.lmttech.com/tag/cybersecurityawarenessmonth)
- [#cyberinsurance (2)](https://blog.lmttech.com/tag/cyberinsurance)
- [Artificial Intelligence (2)](https://blog.lmttech.com/tag/artificial-intelligence)
- [Cybersecurity Awareness Month (2)](https://blog.lmttech.com/tag/cybersecurity-awareness-month)
- [Disaster Recovery (2)](https://blog.lmttech.com/tag/disaster-recovery)
- [Due Diligence (2)](https://blog.lmttech.com/tag/due-diligence)
- [Financial Relief (2)](https://blog.lmttech.com/tag/financial-relief)
- [ITSupport (2)](https://blog.lmttech.com/tag/itsupport)
- [Multifactor Authentication (2)](https://blog.lmttech.com/tag/multifactor-authentication)
- [New York Reopens (2)](https://blog.lmttech.com/tag/new-york-reopens)
- [Remote workforce returning to the office (2)](https://blog.lmttech.com/tag/remote-workforce-returning-to-the-office)
- [Risk Management (2)](https://blog.lmttech.com/tag/risk-management)
- [VEC (2)](https://blog.lmttech.com/tag/vec)
- [industries (2)](https://blog.lmttech.com/tag/industries)
- [#Christmas (1)](https://blog.lmttech.com/tag/christmas)
- [#Shopping (1)](https://blog.lmttech.com/tag/shopping)
- [2FA (1)](https://blog.lmttech.com/tag/2fa)
- [3CX (1)](https://blog.lmttech.com/tag/3cx)
- [AI (1)](https://blog.lmttech.com/tag/ai)
- [Automation (1)](https://blog.lmttech.com/tag/automation)
- [BCDR (1)](https://blog.lmttech.com/tag/bcdr)
- [BuildingAStrongerAmerica (1)](https://blog.lmttech.com/tag/buildingastrongeramerica)
- [Business Model (1)](https://blog.lmttech.com/tag/business-model)
- [Business Security (1)](https://blog.lmttech.com/tag/business-security)
- [Business Technology (1)](https://blog.lmttech.com/tag/business-technology)
- [CISA (1)](https://blog.lmttech.com/tag/cisa)
- [CISSP (1)](https://blog.lmttech.com/tag/cissp)
- [Client Experience (1)](https://blog.lmttech.com/tag/client-experience)
- [Cloud (1)](https://blog.lmttech.com/tag/cloud)
- [Cloud Services (1)](https://blog.lmttech.com/tag/cloud-services)
- [Compliance (1)](https://blog.lmttech.com/tag/compliance)
- [CriticalInfrastructure (1)](https://blog.lmttech.com/tag/criticalinfrastructure)
- [DFS (1)](https://blog.lmttech.com/tag/dfs)
- [Data Breach (1)](https://blog.lmttech.com/tag/data-breach)
- [Digital Identity (1)](https://blog.lmttech.com/tag/digital-identity)
- [Digital Transformation (1)](https://blog.lmttech.com/tag/digital-transformation)
- [Document Drafting (1)](https://blog.lmttech.com/tag/document-drafting)
- [Endpoint Detection (1)](https://blog.lmttech.com/tag/endpoint-detection)
- [Holiday Scams (1)](https://blog.lmttech.com/tag/holiday-scams)
- [IT Consulting (1)](https://blog.lmttech.com/tag/it-consulting)
- [IT Infrastructure (1)](https://blog.lmttech.com/tag/it-infrastructure)
- [Identity Theft (1)](https://blog.lmttech.com/tag/identity-theft)
- [Law Firms (1)](https://blog.lmttech.com/tag/law-firms)
- [Legal (1)](https://blog.lmttech.com/tag/legal)
- [Legal Firm (1)](https://blog.lmttech.com/tag/legal-firm)
- [Legal IT (1)](https://blog.lmttech.com/tag/legal-it)
- [Legal Tech (1)](https://blog.lmttech.com/tag/legal-tech)
- [Legal Trends (1)](https://blog.lmttech.com/tag/legal-trends)
- [MSP (1)](https://blog.lmttech.com/tag/msp)
- [Managed Service Provider (1)](https://blog.lmttech.com/tag/managed-service-provider)
- [Microsoft (1)](https://blog.lmttech.com/tag/microsoft)
- [Microsoft End of Life (1)](https://blog.lmttech.com/tag/microsoft-end-of-life)
- [NYS Department of Financial Services (1)](https://blog.lmttech.com/tag/nys-department-of-financial-services)
- [NYSDFS (1)](https://blog.lmttech.com/tag/nysdfs)
- [Network Security (1)](https://blog.lmttech.com/tag/network-security)
- [Non-Disclosure Agreement (1)](https://blog.lmttech.com/tag/non-disclosure-agreement)
- [Phishing Scams (1)](https://blog.lmttech.com/tag/phishing-scams)
- [PrintNightmare (1)](https://blog.lmttech.com/tag/printnightmare)
- [Remote Workers (1)](https://blog.lmttech.com/tag/remote-workers)
- [Returning to the Office (1)](https://blog.lmttech.com/tag/returning-to-the-office)
- [SMB (1)](https://blog.lmttech.com/tag/smb)
- [Security Audits (1)](https://blog.lmttech.com/tag/security-audits)
- [Silent Starling (1)](https://blog.lmttech.com/tag/silent-starling)
- [Smartphone (1)](https://blog.lmttech.com/tag/smartphone)
- [Social Engineering (1)](https://blog.lmttech.com/tag/social-engineering)
- [Stolen Identity (1)](https://blog.lmttech.com/tag/stolen-identity)
- [Tax Season (1)](https://blog.lmttech.com/tag/tax-season)
- [Travel (1)](https://blog.lmttech.com/tag/travel)
- [Vacation (1)](https://blog.lmttech.com/tag/vacation)
- [Windows 7 (1)](https://blog.lmttech.com/tag/windows-7)

[See all](https://blog.lmttech.com/cyber-insurance#)

---

[Tweets by LMTtechnology](https://twitter.com/LMTtechnology?ref_src=twsrc%5Etfw)

## About LMT

**LMT Technology Solutions in Rochester, NY delivers managed IT, cybersecurity, cloud computing, risk management, systems integration, VCIO and other business information technology services. We've been a trusted IT partner in Western New York and beyond since 1996.**

[Learn More](https://www.lmttech.com/)

## Links

## Contact Us

**

 (585) 784-7470

**

[support@LMTtech.com](mailto:support@LMTtech.com)

**

 800 Linden Avenue  
 Rochester, New York 14625

© Copyright 2026 LMT Technology Solutions.

[**](https://blog.lmttech.com/cyber-insurance#)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "James Keeler",
    "url" : "https://blog.lmttech.com/author/james-keeler"
  },
  "dateModified" : "2019-12-10T15:00:58.366Z",
  "datePublished" : "2019-09-10T16:12:00.000Z",
  "headline" : "Cyber Insurance Clauses - Have You Read the Fine Print?",
  "image" : [ "https://blog.lmttech.com/hubfs/75951764_s_123rf-1.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.lmttech.com/cyber-insurance",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.lmttech.com/hubfs/lmt-logo-rgbB-1.png"
    },
    "name" : "LMT Technology Solutions"
  }
}
```