
Cyber risk insurance
The growing technological transformation we are immersed in is contributing to accelerating cyber risks, creating new attack vectors and greatly expanding the surface that organisations must monitor and defend.
What is cyber risk insurance
Cyber risk insurance covers the economic consequences of a cyber incident: emergency technical response, data and systems recovery, loss of profits due to downtime, fines and notifications resulting from a data breach, and claims from affected third parties. Its most valuable element is not the compensation, but the response team that is activated in the first hours, when most companies do not know whom to call.
Advantages of cyber risk insurance
The most valued aspect of cyber insurance does not come in the form of compensation, but as a phone call that someone answers.
A team you cannot have on staff
Forensic expert, extortion negotiator, and breach specialist lawyer, available within hours. No medium-sized company can maintain these three profiles on payroll.
Taking out a policy forces you to update yourself
The questionnaire requires two-factor authentication, immutable backups, and managed endpoints. Preparing it raises your actual security level, whether or not you make a claim.
Requirement from your own clients
More and more contracts and tenders require the provider to prove they have cyber insurance. Without it, you are excluded from tenders you could win today.
Billing continues during downtime
The interruption cover supports the profit and loss account during the recovery weeks, which is where the real impact of the attack is determined.
Who we work for
Companies with production dependent on systems
Industry and logistics where an IT outage immediately halts physical activity.
Organisations that handle personal data
Healthcare, education, retail, and professional services, exposed to fines and claims from affected parties.
Companies with critical cloud providers
Profiles whose continuity depends on third parties and need interruption cover due to provider failure.
Companies subject to NIS2
Essential and important entities with reinforced risk management and notification obligations.
How an incident unfolds
The cost of the ransom is almost never the main expense. The expensive part is the downtime and subsequent management.
Production stoppage
A well-executed ransomware attack takes systems down for one to three weeks. For a manufacturer that costs more than any ransom.
Encrypted backups too
Attackers first target backups. If they are on the same network and lack immutability, they cease to be a recovery plan.
Obligation to notify within 72 hours
The GDPR requires notification to the supervisory authority within this timeframe. Without immediate legal advice, breach management worsens the penalty.
CEO fraud and fraudulent transfers
Without technical intrusion, purely through social engineering. Many policies sublimit it very restrictively or exclude it.
Main covers of cyber risk insurance
- 24/7 incident response team: forensic, containment and recovery
- Data restoration, systems and configuration reconstruction
- Business interruption and additional expenses to maintain activity
- Data breach management: notification to affected parties, legal advice and defence before the AEPD
- Third-party liability for data and security failure
- Cyber extortion, with specialised negotiation, and social engineering fraud with negotiated sublimit
The definitive scope depends on the wording of each insurer. We review it with you before recommending anything.
Cómo trabajamos
El mismo método en cualquier solución: entender la exposición real antes de mirar una prima.
Análisis del riesgo
Estudiamos la actividad, el patrimonio y los escenarios plausibles. Sin ese diagnóstico, comparar pólizas es comparar precios de cosas distintas.
Diseño del programa
Definimos coberturas, límites, franquicias y exclusiones aceptables. Decidimos qué se transfiere al asegurador y qué se retiene de forma consciente.
Negociación con el mercado
Presentamos el riesgo a las aseguradoras con las que trabajamos y negociamos condiciones. Somos independientes: no pertenecemos a ninguna compañía.
Acompañamiento y siniestros
Revisamos el programa cada renovación y, cuando ocurre el siniestro, actuamos como tu parte técnica frente al asegurador hasta el cobro.
Lo que más nos preguntan sobre cyber risk insurance
Does the policy pay the ransom for ransomware?
It can cover it, with a specialised negotiator and always within the applicable legal and international sanctions framework. But the decision to pay is the last option and rarely the best: the focus of the work is on recovering from clean backups and containing the spread.
Will I be required to have security measures in place to contract?
Yes. The market today requires at least two-factor authentication for remote access, isolated and immutable backups, and managed endpoint protection. We prepare that questionnaire with the company before going to market, as it affects both the premium and the insurability itself.
Does it cover GDPR fines?
It always covers legal defence and breach management costs. The fine itself is only covered to the extent that it is legally insurable in the applicable jurisdiction, which requires reviewing the specific wording of each policy.
What happens if my cloud provider suffers the incident?
It is covered by the technology provider failure interruption guarantee, which must be expressly contracted. Without it, the fall of a critical provider leaves the company at a standstill and without business interruption cover.
Is the insurance useful if I already have a good IT team?
They are different and complementary things. A good internal team reduces the probability; the policy provides financial capacity and, above all, specialists in incident response, negotiation and legal breach management, profiles that no medium-sized company has on staff.
How long does it take to activate the response?
The incident line operates 24/7 and the forensic team is mobilised within hours. That's why we insist that the response phone number is printed and accessible outside corporate systems: in a massive encryption, the contact directory also becomes unavailable.
The first hour of an incident, planned in writing
We assess your level of exposure and current measures, tell you if you are insurable today and what needs to be corrected before going to market.
- Independent broker: we do not belong to any insurer
- The specialist in the field you consulted answers you
- The review is delivered in writing, policy by policy
What we have written about this
Anatomy of a ransomware claim: the seventy-two hours that determine the cost
The ransom is almost never the most expensive item. The costly part is the downtime, the reconstruction of the environment, and the notifications that must be made against the clock.
8 min de lecturaActualidad normativaNIS2: which companies it affects and what changes in their cyber risk policy
The directive greatly expands the number of obligated entities and introduces personal liability for management. What it implies for insurance.
6 min de lecturaActualidad normativaDORA: what it requires from financial entities and their technology providers
The European regulation on digital operational resilience also applies to those providing ICT services to the financial sector. Many providers still do not know this.
6 min de lectura




