What it actually covers, what it quietly doesn't, and the questions worth asking before you sign anything. No insurance background assumed — every term is decoded the first time it appears.
Cyber liability insurance pays for the costs that follow a computer-related incident: someone breaks into your email, ransomware locks your files, a donor database leaks, or an employee is tricked into wiring money to a stranger. Depending on the policy, it can pay for the specialists who clean it up, the legal notices you're required to send, the income you lose while you're down, and the claims other people bring against you afterwards.
That is the whole idea. Everything else on this page is detail about which of those things a particular policy actually does, because the differences between policies are enormous.
There is no standard cyber policy. Property and general liability insurance are broadly standardised — a general liability policy from one insurer looks much like another. Cyber is not. Every insurer writes its own wording, the coverage parts have different names, and two policies both called "cyber liability" can cover almost entirely different things. Nothing on this page can tell you what your policy covers. Only your policy documents do that.
Every cyber policy divides into two kinds of coverage, and the distinction runs through everything else.
First-party coverage pays you, for your losses. Your forensic investigators, your ransom payment, your lost income, your notification letters.
Third-party coverage pays other people who claim you harmed them — plus your legal defence. A congregant sues because their giving records leaked; a regulator opens an investigation; a vendor claims your compromised system infected theirs.
Small organisations almost always use the first-party half. The third-party half is what protects you from the rare, expensive event. A policy heavy on one and light on the other is a real gap, and the declarations page — the summary sheet at the front listing each coverage and its limit — is where you can see the balance.
A cyber policy is built from separate insuring agreements — individual promises to pay, each with its own trigger and often its own limit. You do not necessarily get all of them. Some are optional and must be bought deliberately.
Here are the agreements you're most likely to meet, what sets each one off, and what it pays for.
Triggered by: discovering that personal information has been exposed.
Pays for: digital forensics to work out what happened, specialist legal counsel ("breach counsel") to determine what the law requires you to do, producing and mailing notification letters, a call centre for the people you notified, credit and identity monitoring for them, and public relations help.
This is the agreement small organisations use most, and for many incidents it is the entire claim. Notification is not optional goodwill — every US state, plus the District of Columbia and the territories, has a law requiring it in defined circumstances.
Triggered by: your own systems going down or being degraded by an incident.
Pays for: income you lose while you're down, plus "extra expense" — the extra money you spend to keep operating.
Read the definition of income closely. Forms typically measure loss as net profit before taxes plus continuing operating expenses. A church has no profit, and one broker analysis notes that payroll is often treated as a fixed cost and not reimbursed — which, for an organisation where salaries are most of the budget, can hollow out the value of this coverage. How a form measures loss for a nonprofit is a question worth putting directly to your broker, in writing.
Triggered by: an outage at a provider you rely on, rather than at you.
This matters more than the previous one for most churches. You probably don't run a server; you run on a church management platform, a giving platform, and a hosted email service. The outage you will actually experience happens at one of those vendors.
Policies handle this three ways: scheduled (only providers you list by name), named-service (only certain types), and blanket (any outsourced provider). Even blanket forms commonly exclude infrastructure like internet providers and the power grid. And there are two different triggers — a security failure (an attack) versus a system failure (an accident or human error). System failure is less commonly covered and often carries a smaller limit.
Triggered by: an extortion threat.
Pays for: the ransom itself and the costs around it — professional negotiators, and acquiring cryptocurrency if it comes to that.
There is a condition here that will void your claim if you get it wrong. Essentially every policy requires the insurer's prior written consent before you pay anything. One published form states that extortion monies "shall not be paid without prior consultation with us and with our express written consent." If a panicked staff member pays a ransom on a Saturday and you tell the insurer on Monday, you may have paid for nothing.
Triggered by: data or software being damaged, corrupted or destroyed.
Pays for: the cost of restoring or recreating it.
Two hard limits. It pays to get you back to where you were, not to somewhere better — see betterment below. And if the data was never backed up and cannot be recreated, there may be nothing for the policy to pay for. Insurance does not un-delete a membership database that existed in only one place.
Triggered by: someone else suing you because your security failure hurt them — for example, malware spreading from your systems to theirs.
Triggered by: someone suing you over a privacy breach — congregants, donors, employees, counselling clients.
Some forms carry a separate employee privacy agreement. That matters for churches, because staff and volunteer records — with Social Security numbers, dates of birth and background-check results — are often the most sensitive data the organisation holds, ahead of the donor list.
Triggered by: content claims — defamation, copyright or trademark infringement, invasion of privacy — arising from your website, livestream, podcast, newsletter or social media.
This is disproportionately relevant to churches and is routinely overlooked. You stream services, project song lyrics, use images you found somewhere, and publish sermon audio. Every one of those is a content risk.
Triggered by: a regulator investigating you after a privacy incident.
Pays for: your defence costs, and fines or penalties — but almost always with the qualifier "to the extent insurable under applicable law." That phrase carries a great deal of weight. Whether a particular fine can lawfully be insured is often unsettled until a claim actually arises. Treat defence-cost coverage as the reliable part and fines as the uncertain part.
Triggered by: a breach involving payment card data.
If your church takes card donations — through a giving app, a website, or a lobby kiosk — you are a merchant and you have this exposure. Most churches do not know this.
Two different things sit here. Fines are penalties for not meeting the card industry's security standard. Assessments are the card brands recovering their own costs — fraud losses, reissuing cards — passed down to you through your bank. There is a mechanic worth knowing: when a breach happens, the card industry generally treats the merchant as non-compliant even if it had met every requirement. Many insurers exclude or reduce this coverage if you cannot prove compliance.
If you read one section, read this one. It is where the attack your organisation is most likely to suffer meets the part of the policy least likely to pay for it.
The scenario is familiar: an email that appears to come from your building contractor says their bank details have changed. Your bookkeeper updates the payee and sends the payment. The money is gone. Or a message that looks like it's from the pastor asks for an urgent transfer.
In insurance language, the first is funds transfer fraud, and the deception behind it is social engineering fraud. And there is a historical wrinkle that still shapes how policies respond.
Traditional crime insurance distinguishes between money taken from you involuntarily — a break-in, an unauthorised intrusion into your systems — and money you handed over voluntarily because you were deceived. Because a tricked bookkeeper transfers the money on purpose, older crime policies frequently denied these claims: nothing was stolen as the policy defined stealing.
The market has largely responded with specific social engineering coverage. But it is usually an optional add-on you must buy deliberately, not part of the base policy — and it is nearly always capped well below the main limit.
This is easiest to see in a real published example. One denominational insurance programme publishes a base policy that automatically includes $250,000 for losses from system attacks and $25,000 for cybercrime — scams, theft and fraud. At the higher optional tier those become $1 million and $100,000.
Look at the ratio. At both tiers, the cybercrime limit is one tenth of the breach limit. Now set that against the loss data: in one large cyber insurer's own claims for 2025, the average funds transfer fraud loss was $141,000, and business email compromise plus funds transfer fraud together accounted for 58% of all incidents. That figure comes from a single carrier's book rather than the whole market, but the direction is unambiguous, and it matches what the FBI reports.
The attack you are most likely to suffer is the one your policy is most likely to cap at a fraction of the loss. Finding that number on your declarations page takes two minutes and is probably the single most useful thing you can do with this page.
It may sit in your cyber policy, in a separate commercial crime policy, in both, or in neither. Crime policies often offer higher limits for this than cyber policies do. If both respond, you need to know which pays first and whether the other is excess or excluded. These are questions for your broker, and they are worth asking in writing.
Insurers increasingly require that changes to payment details be verified by phoning the payee on a number you already had — not a number in the email requesting the change. Adopt that rule regardless of what your policy says. It is the single most effective defence against this category of attack, it costs nothing, and you do not need an insurer's permission to start using it on Monday.
Cyber coverage reaches small organisations in two quite different shapes, and they are not close to equivalent.
An endorsement is an add-on bolted to your existing package policy, often called something like "data compromise coverage." A standalone policy is a separate contract written specifically for cyber risk.
Regulator data shows how different they are. In the National Association of Insurance Commissioners' most recent market report, endorsements were 55.1% of all cyber policies in force but only 4% of premium. More than half the cyber policies in America are endorsements, and they collect roughly one twenty-fifth of the money. You cannot buy much coverage for one twenty-fifth of the premium.
Concretely, one nonprofit-focused package endorsement publishes a $50,000 limit with a $5,000 sublimit for legal and forensic review. A competent breach counsel and forensics engagement can exceed $5,000 in the first few days.
| Coverage | Typically in an endorsement? |
|---|---|
| Notification, forensics, legal review, credit monitoring, PR | Yes — but sublimited, sometimes severely |
| Ransomware / cyber extortion | Often expressly excluded |
| Business interruption | Usually absent |
| Funds transfer fraud | Usually absent |
| Network security liability | Usually absent |
In plain terms: a data-compromise endorsement is notification insurance. It handles the legal paperwork that follows a records breach. The three things a small church is most likely to actually face — ransomware that stops you operating, a wire that vanishes, and a lawsuit — are the three things it commonly does not address.
That is not an argument that endorsements are bad or that you should buy something else. It is an argument for knowing which one you have. Many organisations believe they have cyber insurance and have an endorsement; some need nothing more, and some would be badly surprised.
About 57% of the US cyber market by premium is written in the domestic surplus lines market, with a further 18% by non-US insurers. Surplus lines policies are written outside the standard admitted market, which among other things means they are generally not backed by state guaranty funds if the insurer fails. It is not a reason to avoid them — much of the best cyber coverage is written there — but it is worth asking which kind you are being offered.
Exclusions are where policies say what they will not pay for. Most are unremarkable. These are the ones that decide real claims.
This is the most dangerous provision in cyber insurance, and it is entirely avoidable.
When you apply for cyber coverage, you answer a questionnaire about your security: do you use multi-factor authentication, do you back up, do you patch. Many policies then contain an exclusion tying coverage to those answers. One published form excludes loss arising from failure to keep systems protected by practices "equal to or superior to those disclosed in the proposal."
Your application becomes a continuing promise. Whatever you told the underwriter you were doing, you must keep doing.
In Travelers Property Casualty Company of America v. International Control Services, Inc. (US District Court, Central District of Illinois, No. 22-cv-2145), the insurer sued after a ransomware incident, alleging the policyholder had misrepresented its use of multi-factor authentication — that MFA protected the firewall but not other systems. In August 2022 the parties jointly agreed to void the policy from its inception, with no coverage available for any past, present or future claim.
Not a reduced payout. The policy treated as though it had never existed.
Consider how easily a church lands in that position. Someone ticks "yes, we use multi-factor authentication" because it is switched on for the pastor's email — but not the finance workstation, not the file server, not the giving platform. The answer felt true when it was given.
What to do about it: ask for a copy of the completed application to be attached to your policy, keep it, and re-read every answer at each renewal to confirm it is still true. If something has changed, tell your broker before renewal rather than after a claim.
Since 31 March 2023, insurers at Lloyd's of London have been required to include an exclusion for state-backed cyber attacks in standalone cyber policies. The market bulletin setting this out (Lloyd's Y5381, issued 16 August 2022) requires clauses that exclude losses from war, and from state-backed attacks that "significantly impair the ability of a state to function" or "significantly impair the security capabilities of a state," together with a stated basis for attributing an attack to a state.
Several standard clause variants exist and they differ substantially in breadth. This matters because ransomware groups frequently have murky relationships with national governments.
You may have read that a policyholder beat a war exclusion in the Merck litigation over the NotPetya attack (New Jersey Appellate Division, No. A-1879-21, decided 1 May 2023; settled in January 2024 before a final ruling). That is true, and it is reassuring about older wording — the case concerned a legacy property policy. The industry's response was to write new wording designed to produce a different result. Merck is comforting about the past, not the present.
Most general liability insurance is occurrence-based: if the event happened while you were covered, you're covered whenever the claim shows up. Cyber policies are almost always claims-made: you're covered only if the claim arrives during the policy period.
Paired with that is the retroactive date — a date before which nothing is covered, no matter when the claim arrives.
This is where switching insurers can hurt. A cheaper quote from a new carrier may come with a retroactive date set at the new policy's start, wiping out coverage for anything that happened earlier. Intrusions routinely sit undetected for months. A cheaper renewal with a fresh retroactive date can be a very expensive saving. Ask what the retroactive date is, every time, and ask whether prior acts are covered.
Policies exclude the cost of improving your systems beyond where they were. One form excludes "any expenses to improve, restore, replace or update the Computer System and/or Data Asset(s) to a level beyond that which existed prior to" the incident.
In plain English: insurance pays to put you back on the insecure system you were attacked on. It does not pay to make you secure. Upgrading from an old on-premises server to a hosted platform, extending monitoring beyond the immediate response, rebuilding the network more sensibly — those are improvements, and improvements are yours to fund.
Business interruption coverage doesn't start the moment you go down. A waiting period — commonly somewhere between six and twelve hours, sometimes twenty-four — must pass first.
Two structures share that label and pay very differently. Under one, the waiting period is a time deductible: with a twelve-hour wait and a twenty-four-hour outage, you're paid for twelve hours. Under the other, it is only a trigger: cross twelve hours and coverage applies back to hour zero, so you're paid for all twenty-four. The declarations page may look identical in both cases. Ask which one you have.
Policies typically require the insurer's prior written consent before you spend on forensics, legal advice, credit monitoring or PR — and usually direct you to their approved panel of specialists.
This has a practical edge and a genuine upside. If you call your usual IT company first and run up a large bill, that bill may not be covered. But the carrier's breach counsel and forensics firm are generally far more experienced at this than a local provider. The constraint is often to your benefit — as long as you call the incident hotline before anyone else. Put that number somewhere you can find it without logging into a computer.
Some losses are outside every policy. Being clear-eyed about these is part of deciding how much coverage you actually need.
Insurance is a financial backstop for a bad event. It is not a security programme, and it does not make an incident not have happened. It restores; it does not improve. Everything on the "never covered" list is only addressed by not having the incident in the first place.
Cyber underwriting has tightened considerably. Applications now ask detailed technical questions, and the answers affect whether you can buy coverage at all — not just what it costs.
Drawn from an actual carrier application for organisations under $10 million in revenue, and from a US state government's cyber insurance toolkit, the controls asked about most consistently are:
Whether a given control is a hard requirement, a pricing factor, or a condition you must maintain depends entirely on where the insurer puts it — in its rating model, in an exclusion, or in a warranty. There is no universal answer, which is precisely why the application-and-renewal discipline described earlier matters so much.
You do not need to read the whole contract. Go to the declarations page — the summary at the front — and find these seven things.
Then find the completed application attached to the policy and check that every answer is still true today.
About this guide. MissionDefend is a cybersecurity readiness company. We are not an insurance company, agency, broker or producer. We do not sell, place, or arrange insurance, we are not compensated by any insurer, and nothing here is insurance advice, a recommendation of any insurer or product, or a solicitation.
Coverage terms vary materially between insurers and between policies from the same insurer. Descriptions here are drawn from publicly published policy wordings and regulatory sources and are offered to explain how this kind of coverage generally works. Only your own policy documents govern your coverage. Decisions about buying insurance should be made with a licensed insurance professional, and questions about your legal obligations with your own attorney.
Sources: National Association of Insurance Commissioners, Report on the Cybersecurity Insurance Market (2025); Lloyd's of London, Market Bulletin Y5381, Cyber-attack exclusions; Coalition 2026 Cyber Claims Report; National Conference of State Legislatures, Security Breach Notification Laws; Insurance Information Institute, Cyber insurance; Indiana Cybersecurity Hub, Underwriting Security Controls; Travelers Property Casualty Co. of America v. International Control Services, Inc., No. 22-cv-2145 (C.D. Ill.); Merck & Co. v. ACE American Insurance Co., No. A-1879-21 (N.J. App. Div. 2023).
The betterment exclusion says it plainly: a policy pays to put you back on the same system you were attacked on. Knowing where you actually stand is the part insurance can't do for you.
MissionDefend's free assessment asks plain-English questions about how your organization handles email, donations, member data and accounts, then returns a baseline score and a ranked list of what to fix first — including most of the controls insurers now ask about on their applications.
No spam and no sales calls — just one email when it's live.