24h AssistanceClient Area
Cyber risk insurance
Empresas

Cyber risk insurance

The growing technological transformation we are immersed in is contributing to accelerating cyber risks, creating new attack vectors and greatly expanding the surface that organisations must monitor and defend.

Policies processed320
Claims Processed48
Nº Clients245
In short

What is cyber risk insurance

Cyber risk insurance covers the economic consequences of a cyber incident: emergency technical response, data and systems recovery, loss of profits due to downtime, fines and notifications resulting from a data breach, and claims from affected third parties. Its most valuable element is not the compensation, but the response team that is activated in the first hours, when most companies do not know whom to call.

Advantages

Advantages of cyber risk insurance

The most valued aspect of cyber insurance does not come in the form of compensation, but as a phone call that someone answers.

01

A team you cannot have on staff

Forensic expert, extortion negotiator, and breach specialist lawyer, available within hours. No medium-sized company can maintain these three profiles on payroll.

02

Taking out a policy forces you to update yourself

The questionnaire requires two-factor authentication, immutable backups, and managed endpoints. Preparing it raises your actual security level, whether or not you make a claim.

03

Requirement from your own clients

More and more contracts and tenders require the provider to prove they have cyber insurance. Without it, you are excluded from tenders you could win today.

04

Billing continues during downtime

The interruption cover supports the profit and loss account during the recovery weeks, which is where the real impact of the attack is determined.

Profile

Who we work for

Companies with production dependent on systems

Industry and logistics where an IT outage immediately halts physical activity.

Organisations that handle personal data

Healthcare, education, retail, and professional services, exposed to fines and claims from affected parties.

Companies with critical cloud providers

Profiles whose continuity depends on third parties and need interruption cover due to provider failure.

Companies subject to NIS2

Essential and important entities with reinforced risk management and notification obligations.

Technical criteria

How an incident unfolds

The cost of the ransom is almost never the main expense. The expensive part is the downtime and subsequent management.

01

Production stoppage

A well-executed ransomware attack takes systems down for one to three weeks. For a manufacturer that costs more than any ransom.

02

Encrypted backups too

Attackers first target backups. If they are on the same network and lack immutability, they cease to be a recovery plan.

03

Obligation to notify within 72 hours

The GDPR requires notification to the supervisory authority within this timeframe. Without immediate legal advice, breach management worsens the penalty.

04

CEO fraud and fraudulent transfers

Without technical intrusion, purely through social engineering. Many policies sublimit it very restrictively or exclude it.

Scope

Main covers of cyber risk insurance

  • 24/7 incident response team: forensic, containment and recovery
  • Data restoration, systems and configuration reconstruction
  • Business interruption and additional expenses to maintain activity
  • Data breach management: notification to affected parties, legal advice and defence before the AEPD
  • Third-party liability for data and security failure
  • Cyber extortion, with specialised negotiation, and social engineering fraud with negotiated sublimit

The definitive scope depends on the wording of each insurer. We review it with you before recommending anything.

The JORI& method

Cómo trabajamos

El mismo método en cualquier solución: entender la exposición real antes de mirar una prima.

01

Análisis del riesgo

Estudiamos la actividad, el patrimonio y los escenarios plausibles. Sin ese diagnóstico, comparar pólizas es comparar precios de cosas distintas.

02

Diseño del programa

Definimos coberturas, límites, franquicias y exclusiones aceptables. Decidimos qué se transfiere al asegurador y qué se retiene de forma consciente.

03

Negociación con el mercado

Presentamos el riesgo a las aseguradoras con las que trabajamos y negociamos condiciones. Somos independientes: no pertenecemos a ninguna compañía.

04

Acompañamiento y siniestros

Revisamos el programa cada renovación y, cuando ocurre el siniestro, actuamos como tu parte técnica frente al asegurador hasta el cobro.

Frequent doubts

Lo que más nos preguntan sobre cyber risk insurance

Does the policy pay the ransom for ransomware?

It can cover it, with a specialised negotiator and always within the applicable legal and international sanctions framework. But the decision to pay is the last option and rarely the best: the focus of the work is on recovering from clean backups and containing the spread.

Will I be required to have security measures in place to contract?

Yes. The market today requires at least two-factor authentication for remote access, isolated and immutable backups, and managed endpoint protection. We prepare that questionnaire with the company before going to market, as it affects both the premium and the insurability itself.

Does it cover GDPR fines?

It always covers legal defence and breach management costs. The fine itself is only covered to the extent that it is legally insurable in the applicable jurisdiction, which requires reviewing the specific wording of each policy.

What happens if my cloud provider suffers the incident?

It is covered by the technology provider failure interruption guarantee, which must be expressly contracted. Without it, the fall of a critical provider leaves the company at a standstill and without business interruption cover.

Is the insurance useful if I already have a good IT team?

They are different and complementary things. A good internal team reduces the probability; the policy provides financial capacity and, above all, specialists in incident response, negotiation and legal breach management, profiles that no medium-sized company has on staff.

How long does it take to activate the response?

The incident line operates 24/7 and the forensic team is mobilised within hours. That's why we insist that the response phone number is printed and accessible outside corporate systems: in a massive encryption, the contact directory also becomes unavailable.

Cyber risk

The first hour of an incident, planned in writing

We assess your level of exposure and current measures, tell you if you are insurable today and what needs to be corrected before going to market.

  • Independent broker: we do not belong to any insurer
  • The specialist in the field you consulted answers you
  • The review is delivered in writing, policy by policy

A person from the team that handles that risk replies — not an automated acknowledgement.