Skip to content
Explore coverage

Cyber insurance

Cyber insurance covers two things: your own costs after a hack or data breach, and claims from other people who were affected. The first can include investigators, legal advice, notifying the people involved, and restoring systems. The second covers liability to others.

Cilantro Risk arranges cyber insurance for investment firms and startups. We start from what you depend on: the data you hold, the systems you run, and the vendors you rely on.

Your costs and claims against you

After an incident, the policy will tell you how to reach the insurer and may require you to use approved specialists or get consent before hiring your own. Costs you run up outside that process may not be covered. We set this out for you when the policy starts, so the right person knows who to call.

Claims from others are a separate part of the policy with its own terms. A policy can be strong on incident response and thin on liability, or the reverse. We read the two parts separately and tell you which is which.

Downtime and vendor outages

Business interruption coverage is for income lost while your systems are down. It usually starts after a waiting period and may have its own smaller limit.

An outage at your cloud provider or administrator is a different trigger from your own systems failing, and not every policy includes it. Your vendor’s insurance protects your vendor, not you. We ask insurers about your key vendors specifically.

Where wire fraud falls

Say someone breaks into an email account and uses it to redirect a payment. The cost of investigating the break-in and the money that was lost are two separate questions, and the second is often a matter for crime insurance or a limited add-on.

We review cyber and crime together, so you can see how a payment fraud loss would be handled. For each quote, we set out:

  • Which response costs share one limit
  • Whether you need consent before hiring help
  • How ransom demands and downtime are handled
  • Which payment fraud scenarios need a crime policy

Help with the application

Cyber applications ask detailed questions about your security, such as access controls, backups, and how payments are verified. An inaccurate answer can put a claim at risk later. We go through the application with you and explain what each question is asking.

To get started, send us your current policy if you have one, and a short summary of your systems, sensitive data, and key vendors.

Further reading

Background from insurers and regulators. These pages describe their own products and rules, and are not an offer of coverage from Cilantro Risk.

Travelers: how cyber insurance works

The Hartford: investment adviser insurance

Common questions

Does cyber insurance replace security controls?

No. Insurers ask about your controls, and some policy conditions depend on them. Insurance is for what gets through anyway.

Is every fraudulent wire a cyber claim?

No. It depends on how the money left. Some losses fall under cyber, some under crime, and some under a social engineering add-on with a smaller limit. An email being involved doesn’t make it a cyber claim.

Does cyber insurance cover an outage at one of our vendors?

Only if the policy includes it. We check which events at outside providers are covered, how long the waiting period is, and what the limit is.

Talk to us about your insurance

Tell us about your business, what you’re trying to decide, and any deadline. We’ll follow up to set up a call. You don’t need to upload anything now.

Request a call

Tell us about your business, what is changing, and when you need coverage. We will follow up to discuss next steps.

Include any renewal, fundraising, or contract deadline.

Privacy policy