Cyber insurance, explained

Cyber insurance for churches and nonprofits

What it actually covers, what it quietly doesn't, and the questions worth asking before you sign anything. No insurance background assumed — every term is decoded the first time it appears.

Reading time about 20 minutes · Last reviewed August 2026 · Sources cited throughout

What's on this page

  1. What cyber insurance is
  2. The two halves of a policy
  3. What's inside, piece by piece
  4. The gap that matters most
  5. Two very different shapes
  6. The exclusions that bite
  7. What it never covers
  8. What insurers now require
  9. How to read your own policy
  10. Questions for your broker

1. What cyber insurance is, in one paragraph

Cyber liability insurance pays for the costs that follow a computer-related incident: someone breaks into your email, ransomware locks your files, a donor database leaks, or an employee is tricked into wiring money to a stranger. Depending on the policy, it can pay for the specialists who clean it up, the legal notices you're required to send, the income you lose while you're down, and the claims other people bring against you afterwards.

That is the whole idea. Everything else on this page is detail about which of those things a particular policy actually does, because the differences between policies are enormous.

The single most important thing to understand

There is no standard cyber policy. Property and general liability insurance are broadly standardised — a general liability policy from one insurer looks much like another. Cyber is not. Every insurer writes its own wording, the coverage parts have different names, and two policies both called "cyber liability" can cover almost entirely different things. Nothing on this page can tell you what your policy covers. Only your policy documents do that.

2. The two halves of a policy

Every cyber policy divides into two kinds of coverage, and the distinction runs through everything else.

First-party coverage pays you, for your losses. Your forensic investigators, your ransom payment, your lost income, your notification letters.

Third-party coverage pays other people who claim you harmed them — plus your legal defence. A congregant sues because their giving records leaked; a regulator opens an investigation; a vendor claims your compromised system infected theirs.

Small organisations almost always use the first-party half. The third-party half is what protects you from the rare, expensive event. A policy heavy on one and light on the other is a real gap, and the declarations page — the summary sheet at the front listing each coverage and its limit — is where you can see the balance.

3. What's inside a policy, piece by piece

A cyber policy is built from separate insuring agreements — individual promises to pay, each with its own trigger and often its own limit. You do not necessarily get all of them. Some are optional and must be bought deliberately.

Here are the agreements you're most likely to meet, what sets each one off, and what it pays for.

First-party

Breach response / incident response costs

Triggered by: discovering that personal information has been exposed.

Pays for: digital forensics to work out what happened, specialist legal counsel ("breach counsel") to determine what the law requires you to do, producing and mailing notification letters, a call centre for the people you notified, credit and identity monitoring for them, and public relations help.

This is the agreement small organisations use most, and for many incidents it is the entire claim. Notification is not optional goodwill — every US state, plus the District of Columbia and the territories, has a law requiring it in defined circumstances.

First-party

Business interruption

Triggered by: your own systems going down or being degraded by an incident.

Pays for: income you lose while you're down, plus "extra expense" — the extra money you spend to keep operating.

Read the definition of income closely. Forms typically measure loss as net profit before taxes plus continuing operating expenses. A church has no profit, and one broker analysis notes that payroll is often treated as a fixed cost and not reimbursed — which, for an organisation where salaries are most of the budget, can hollow out the value of this coverage. How a form measures loss for a nonprofit is a question worth putting directly to your broker, in writing.

First-party

Dependent (or contingent) business interruption

Triggered by: an outage at a provider you rely on, rather than at you.

This matters more than the previous one for most churches. You probably don't run a server; you run on a church management platform, a giving platform, and a hosted email service. The outage you will actually experience happens at one of those vendors.

Policies handle this three ways: scheduled (only providers you list by name), named-service (only certain types), and blanket (any outsourced provider). Even blanket forms commonly exclude infrastructure like internet providers and the power grid. And there are two different triggers — a security failure (an attack) versus a system failure (an accident or human error). System failure is less commonly covered and often carries a smaller limit.

First-party

Cyber extortion and ransomware

Triggered by: an extortion threat.

Pays for: the ransom itself and the costs around it — professional negotiators, and acquiring cryptocurrency if it comes to that.

There is a condition here that will void your claim if you get it wrong. Essentially every policy requires the insurer's prior written consent before you pay anything. One published form states that extortion monies "shall not be paid without prior consultation with us and with our express written consent." If a panicked staff member pays a ransom on a Saturday and you tell the insurer on Monday, you may have paid for nothing.

First-party

Data restoration

Triggered by: data or software being damaged, corrupted or destroyed.

Pays for: the cost of restoring or recreating it.

Two hard limits. It pays to get you back to where you were, not to somewhere better — see betterment below. And if the data was never backed up and cannot be recreated, there may be nothing for the policy to pay for. Insurance does not un-delete a membership database that existed in only one place.

Third-party

Network security liability

Triggered by: someone else suing you because your security failure hurt them — for example, malware spreading from your systems to theirs.

Third-party

Privacy liability

Triggered by: someone suing you over a privacy breach — congregants, donors, employees, counselling clients.

Some forms carry a separate employee privacy agreement. That matters for churches, because staff and volunteer records — with Social Security numbers, dates of birth and background-check results — are often the most sensitive data the organisation holds, ahead of the donor list.

Third-party

Media liability

Triggered by: content claims — defamation, copyright or trademark infringement, invasion of privacy — arising from your website, livestream, podcast, newsletter or social media.

This is disproportionately relevant to churches and is routinely overlooked. You stream services, project song lyrics, use images you found somewhere, and publish sermon audio. Every one of those is a content risk.

Third-party

Regulatory defence and fines

Triggered by: a regulator investigating you after a privacy incident.

Pays for: your defence costs, and fines or penalties — but almost always with the qualifier "to the extent insurable under applicable law." That phrase carries a great deal of weight. Whether a particular fine can lawfully be insured is often unsettled until a claim actually arises. Treat defence-cost coverage as the reliable part and fines as the uncertain part.

First-party

PCI fines and assessments

Triggered by: a breach involving payment card data.

If your church takes card donations — through a giving app, a website, or a lobby kiosk — you are a merchant and you have this exposure. Most churches do not know this.

Two different things sit here. Fines are penalties for not meeting the card industry's security standard. Assessments are the card brands recovering their own costs — fraud losses, reissuing cards — passed down to you through your bank. There is a mechanic worth knowing: when a breach happens, the card industry generally treats the merchant as non-compliant even if it had met every requirement. Many insurers exclude or reduce this coverage if you cannot prove compliance.

4. The gap that matters most

If you read one section, read this one. It is where the attack your organisation is most likely to suffer meets the part of the policy least likely to pay for it.

The scenario is familiar: an email that appears to come from your building contractor says their bank details have changed. Your bookkeeper updates the payee and sends the payment. The money is gone. Or a message that looks like it's from the pastor asks for an urgent transfer.

In insurance language, the first is funds transfer fraud, and the deception behind it is social engineering fraud. And there is a historical wrinkle that still shapes how policies respond.

Voluntary versus involuntary

Traditional crime insurance distinguishes between money taken from you involuntarily — a break-in, an unauthorised intrusion into your systems — and money you handed over voluntarily because you were deceived. Because a tricked bookkeeper transfers the money on purpose, older crime policies frequently denied these claims: nothing was stolen as the policy defined stealing.

The market has largely responded with specific social engineering coverage. But it is usually an optional add-on you must buy deliberately, not part of the base policy — and it is nearly always capped well below the main limit.

How big the gap can be

This is easiest to see in a real published example. One denominational insurance programme publishes a base policy that automatically includes $250,000 for losses from system attacks and $25,000 for cybercrime — scams, theft and fraud. At the higher optional tier those become $1 million and $100,000.

Look at the ratio. At both tiers, the cybercrime limit is one tenth of the breach limit. Now set that against the loss data: in one large cyber insurer's own claims for 2025, the average funds transfer fraud loss was $141,000, and business email compromise plus funds transfer fraud together accounted for 58% of all incidents. That figure comes from a single carrier's book rather than the whole market, but the direction is unambiguous, and it matches what the FBI reports.

The attack you are most likely to suffer is the one your policy is most likely to cap at a fraction of the loss. Finding that number on your declarations page takes two minutes and is probably the single most useful thing you can do with this page.

Where the coverage lives

It may sit in your cyber policy, in a separate commercial crime policy, in both, or in neither. Crime policies often offer higher limits for this than cyber policies do. If both respond, you need to know which pays first and whether the other is excess or excluded. These are questions for your broker, and they are worth asking in writing.

A control worth having anyway

Insurers increasingly require that changes to payment details be verified by phoning the payee on a number you already had — not a number in the email requesting the change. Adopt that rule regardless of what your policy says. It is the single most effective defence against this category of attack, it costs nothing, and you do not need an insurer's permission to start using it on Monday.

5. Two very different things share the name

Cyber coverage reaches small organisations in two quite different shapes, and they are not close to equivalent.

An endorsement is an add-on bolted to your existing package policy, often called something like "data compromise coverage." A standalone policy is a separate contract written specifically for cyber risk.

Regulator data shows how different they are. In the National Association of Insurance Commissioners' most recent market report, endorsements were 55.1% of all cyber policies in force but only 4% of premium. More than half the cyber policies in America are endorsements, and they collect roughly one twenty-fifth of the money. You cannot buy much coverage for one twenty-fifth of the premium.

Concretely, one nonprofit-focused package endorsement publishes a $50,000 limit with a $5,000 sublimit for legal and forensic review. A competent breach counsel and forensics engagement can exceed $5,000 in the first few days.

What a data-compromise endorsement typically does not include

CoverageTypically in an endorsement?
Notification, forensics, legal review, credit monitoring, PRYes — but sublimited, sometimes severely
Ransomware / cyber extortionOften expressly excluded
Business interruptionUsually absent
Funds transfer fraudUsually absent
Network security liabilityUsually absent

In plain terms: a data-compromise endorsement is notification insurance. It handles the legal paperwork that follows a records breach. The three things a small church is most likely to actually face — ransomware that stops you operating, a wire that vanishes, and a lawsuit — are the three things it commonly does not address.

That is not an argument that endorsements are bad or that you should buy something else. It is an argument for knowing which one you have. Many organisations believe they have cyber insurance and have an endorsement; some need nothing more, and some would be badly surprised.

Worth knowing

About 57% of the US cyber market by premium is written in the domestic surplus lines market, with a further 18% by non-US insurers. Surplus lines policies are written outside the standard admitted market, which among other things means they are generally not backed by state guaranty funds if the insurer fails. It is not a reason to avoid them — much of the best cyber coverage is written there — but it is worth asking which kind you are being offered.

6. The exclusions that actually bite

Exclusions are where policies say what they will not pay for. Most are unremarkable. These are the ones that decide real claims.

Failure to maintain the security you said you had

This is the most dangerous provision in cyber insurance, and it is entirely avoidable.

When you apply for cyber coverage, you answer a questionnaire about your security: do you use multi-factor authentication, do you back up, do you patch. Many policies then contain an exclusion tying coverage to those answers. One published form excludes loss arising from failure to keep systems protected by practices "equal to or superior to those disclosed in the proposal."

Your application becomes a continuing promise. Whatever you told the underwriter you were doing, you must keep doing.

What this looks like when it goes wrong

In Travelers Property Casualty Company of America v. International Control Services, Inc. (US District Court, Central District of Illinois, No. 22-cv-2145), the insurer sued after a ransomware incident, alleging the policyholder had misrepresented its use of multi-factor authentication — that MFA protected the firewall but not other systems. In August 2022 the parties jointly agreed to void the policy from its inception, with no coverage available for any past, present or future claim.

Not a reduced payout. The policy treated as though it had never existed.

Consider how easily a church lands in that position. Someone ticks "yes, we use multi-factor authentication" because it is switched on for the pastor's email — but not the finance workstation, not the file server, not the giving platform. The answer felt true when it was given.

What to do about it: ask for a copy of the completed application to be attached to your policy, keep it, and re-read every answer at each renewal to confirm it is still true. If something has changed, tell your broker before renewal rather than after a claim.

War and state-backed attacks

Since 31 March 2023, insurers at Lloyd's of London have been required to include an exclusion for state-backed cyber attacks in standalone cyber policies. The market bulletin setting this out (Lloyd's Y5381, issued 16 August 2022) requires clauses that exclude losses from war, and from state-backed attacks that "significantly impair the ability of a state to function" or "significantly impair the security capabilities of a state," together with a stated basis for attributing an attack to a state.

Several standard clause variants exist and they differ substantially in breadth. This matters because ransomware groups frequently have murky relationships with national governments.

You may have read that a policyholder beat a war exclusion in the Merck litigation over the NotPetya attack (New Jersey Appellate Division, No. A-1879-21, decided 1 May 2023; settled in January 2024 before a final ruling). That is true, and it is reassuring about older wording — the case concerned a legacy property policy. The industry's response was to write new wording designed to produce a different result. Merck is comforting about the past, not the present.

Claims-made cover and the retroactive date

Most general liability insurance is occurrence-based: if the event happened while you were covered, you're covered whenever the claim shows up. Cyber policies are almost always claims-made: you're covered only if the claim arrives during the policy period.

Paired with that is the retroactive date — a date before which nothing is covered, no matter when the claim arrives.

This is where switching insurers can hurt. A cheaper quote from a new carrier may come with a retroactive date set at the new policy's start, wiping out coverage for anything that happened earlier. Intrusions routinely sit undetected for months. A cheaper renewal with a fresh retroactive date can be a very expensive saving. Ask what the retroactive date is, every time, and ask whether prior acts are covered.

Betterment — the exclusion that makes the case for prevention

Policies exclude the cost of improving your systems beyond where they were. One form excludes "any expenses to improve, restore, replace or update the Computer System and/or Data Asset(s) to a level beyond that which existed prior to" the incident.

In plain English: insurance pays to put you back on the insecure system you were attacked on. It does not pay to make you secure. Upgrading from an old on-premises server to a hosted platform, extending monitoring beyond the immediate response, rebuilding the network more sensibly — those are improvements, and improvements are yours to fund.

Waiting periods on business interruption

Business interruption coverage doesn't start the moment you go down. A waiting period — commonly somewhere between six and twelve hours, sometimes twenty-four — must pass first.

Two structures share that label and pay very differently. Under one, the waiting period is a time deductible: with a twelve-hour wait and a twenty-four-hour outage, you're paid for twelve hours. Under the other, it is only a trigger: cross twelve hours and coverage applies back to hour zero, so you're paid for all twenty-four. The declarations page may look identical in both cases. Ask which one you have.

Consent and panel vendors

Policies typically require the insurer's prior written consent before you spend on forensics, legal advice, credit monitoring or PR — and usually direct you to their approved panel of specialists.

This has a practical edge and a genuine upside. If you call your usual IT company first and run up a large bill, that bill may not be covered. But the carrier's breach counsel and forensics firm are generally far more experienced at this than a local provider. The constraint is often to your benefit — as long as you call the incident hotline before anyone else. Put that number somewhere you can find it without logging into a computer.

Others worth checking

7. What cyber insurance never covers

Some losses are outside every policy. Being clear-eyed about these is part of deciding how much coverage you actually need.

The honest summary

Insurance is a financial backstop for a bad event. It is not a security programme, and it does not make an incident not have happened. It restores; it does not improve. Everything on the "never covered" list is only addressed by not having the incident in the first place.

8. What insurers now require before they'll quote

Cyber underwriting has tightened considerably. Applications now ask detailed technical questions, and the answers affect whether you can buy coverage at all — not just what it costs.

Drawn from an actual carrier application for organisations under $10 million in revenue, and from a US state government's cyber insurance toolkit, the controls asked about most consistently are:

Whether a given control is a hard requirement, a pricing factor, or a condition you must maintain depends entirely on where the insurer puts it — in its rating model, in an exclusion, or in a warranty. There is no universal answer, which is precisely why the application-and-renewal discipline described earlier matters so much.

9. How to read your own policy in fifteen minutes

You do not need to read the whole contract. Go to the declarations page — the summary at the front — and find these seven things.

  1. Is this a standalone policy or an endorsement? An endorsement will be attached to your package policy and will usually be short.
  2. The overall limit, and whether breach response costs sit inside it or on top of it.
  3. Every sublimit. Write them down. Look specifically for social engineering, funds transfer fraud, cybercrime, ransomware, and forensic and legal costs. This is where the surprises live.
  4. The retention or deductible — what you pay before the insurer pays.
  5. The waiting period on business interruption, and whether it is a time deductible or only a trigger.
  6. The retroactive date, and whether prior acts are covered.
  7. The incident hotline number. Print it. Put it somewhere reachable without a computer, because the day you need it your computers may be the problem.

Then find the completed application attached to the policy and check that every answer is still true today.

10. Questions worth asking your broker

Take these to the person who sells you insurance

  1. Do we have a standalone cyber policy or an endorsement? What does ours not include that the other would?
  2. What is our limit for social engineering or funds transfer fraud specifically? Is it in this policy, in a crime policy, or nowhere? If both, which pays first?
  3. How does this form measure business interruption loss for an organisation with no profit? Are lost donations included? Is payroll?
  4. Is our giving platform and church management software covered under dependent business interruption — and do we need to name them?
  5. What is our retroactive date, and if we move insurers, what happens to it?
  6. Which state-backed attack exclusion is in this policy, and what would it exclude in a ransomware event attributed to a foreign government?
  7. Does anything in this policy require us to maintain specific security controls? Can we have a copy of the application attached to the policy?
  8. Who do we call first, and what happens if we use our own IT provider instead of the panel?
  9. We take card donations. Are PCI fines and assessments covered, and what happens if we cannot prove compliance?
  10. Is this admitted or surplus lines coverage?

About this guide. MissionDefend is a cybersecurity readiness company. We are not an insurance company, agency, broker or producer. We do not sell, place, or arrange insurance, we are not compensated by any insurer, and nothing here is insurance advice, a recommendation of any insurer or product, or a solicitation.

Coverage terms vary materially between insurers and between policies from the same insurer. Descriptions here are drawn from publicly published policy wordings and regulatory sources and are offered to explain how this kind of coverage generally works. Only your own policy documents govern your coverage. Decisions about buying insurance should be made with a licensed insurance professional, and questions about your legal obligations with your own attorney.

Sources: National Association of Insurance Commissioners, Report on the Cybersecurity Insurance Market (2025); Lloyd's of London, Market Bulletin Y5381, Cyber-attack exclusions; Coalition 2026 Cyber Claims Report; National Conference of State Legislatures, Security Breach Notification Laws; Insurance Information Institute, Cyber insurance; Indiana Cybersecurity Hub, Underwriting Security Controls; Travelers Property Casualty Co. of America v. International Control Services, Inc., No. 22-cv-2145 (C.D. Ill.); Merck & Co. v. ACE American Insurance Co., No. A-1879-21 (N.J. App. Div. 2023).

Insurance restores. It doesn't prevent.

The betterment exclusion says it plainly: a policy pays to put you back on the same system you were attacked on. Knowing where you actually stand is the part insurance can't do for you.

MissionDefend's free assessment asks plain-English questions about how your organization handles email, donations, member data and accounts, then returns a baseline score and a ranked list of what to fix first — including most of the controls insurers now ask about on their applications.

Join the launch list →

No spam and no sales calls — just one email when it's live.