Home  ›  Glossary  ›  Cyber Liability Insurance

What is cyber liability insurance?

Cyber liability insurance is insurance that pays for an organization's losses after a cyber incident such as ransomware or a data breach, and for claims others bring against it. A policy usually combines first-party cover for the organization's own costs with third-party cover for its liability to customers, partners and regulators.

Backup questions on the application and renewal

For many mid-sized organizations the cyber insurer has become one of the loudest outside voices on backup design. Application and renewal questionnaires ask directly whether backups are immutable or offline, whether backup credentials are separate from the production domain, whether MFA protects the backup console, and whether restores are tested. The answers influence whether cover is offered, at what premium and with how large a retention.

Those answers resurface during a claim. Insurers weigh a loss against what was declared at application, so a backup environment that no longer matches the questionnaire can complicate the claim at the moment the money is most needed.

First-party costs, third-party claims and the limits on both

First-party (own costs)Third-party (liability to others)
Incident response and forensic investigationClaims from customers whose data was exposed
Data restoration and rebuilding systemsRegulatory investigations, and fines where insurable
Business interruption: income lost during the outageLegal defense, settlements and judgments
Breach notification, and extortion costs where includedPrivacy and media liability claims

A handful of policy terms decide how much of a ransomware loss is actually paid. The aggregate limit is the most the policy pays in the policy period. Sublimits cap specific items, commonly extortion and business interruption, at lower amounts. The retention is the share of each loss the organization carries before cover starts. For business interruption, a waiting period sets how many hours an outage lasts before lost income counts. Exclusions, such as acts of war, remove certain causes of loss from cover altogether.

Insurance pays for parts of a bad outcome; it does not bring data back. The length of the outage depends on how quickly servers can be rebuilt, on the restore throughput of the backup storage and on whether the restore points are intact. The policy compensates only part of that downtime, after the waiting period and up to the sublimit. Four days offline remain four days for customers and staff, whatever arrives from the insurer later.

The questionnaire amounts to a description of the environment the insurer believes it is covering. Statements such as "backups are immutable" or "backup credentials are separate from Active Directory" carry weight at claim time only if the running configuration matches them, not just the design document. An immutability answer also depends on how retention is enforced: a lock an administrator can bypass protects less than one no account can remove.

Evidence enters the claim file too. After an incident the insurer's forensic team reconstructs what happened, and storage access logs, records of restore tests and the retention settings in force on the day of the attack all get examined. Service providers often face these questions twice, once from their own insurer and again from the insurer of each client.

ARTESCA and cyber liability insurance

The ARTESCA Cyber Guarantee is a commitment from Scality, not an insurance product, and it sits alongside whatever cover the organization holds. Scality makes a one-time payment of $100,000 when an external cyberattack encrypts or deletes data stored on ARTESCA. Qualifying requires at least 50 TB of licensed ARTESCA capacity in production, ARTESCA 4.1.3 or any later supported release, the recommended security practices in place, the affected data locked by S3 Object Lock in compliance mode, and written notice within 48 hours.

Four cases fall outside it: data stolen without being encrypted or deleted, credentials compromised outside ARTESCA, credentials shared between people, and unauthorized acts by approved personnel. Several of those conditions mirror questions already on an insurance renewal form, compliance-mode retention above all.