Before an incident, cyber insurance often gets bought quickly: a short form, a few tick boxes, a policy document nobody reads. Afterwards, everything sharpens. You now know which systems actually matter, how long recovery really takes, and what an incident costs in management time as well as money. Insurers sharpen too — a declared incident takes you out of the fast lane and into underwritten business, where a human reads your answers and asks follow-ups.
That is not a punishment. Underwritten business is where context counts, and context is exactly what a post-incident risk needs. The general shape of the market is covered in our cyber insurance broker guide; this page is about what changes when there is an incident in your history.
Expect the proposal to ask what happened, when, how it was discovered, what it cost, whether data was taken, whether regulators or affected individuals were notified, and what has changed since. Expect your answers about security controls to be treated as statements the insurer is relying on — some policies condition cover on the controls you describe being genuinely in place. Answering optimistically is not a shortcut; it is a way of buying a policy that may not respond.
Across much of the current cyber market, certain controls have moved from pricing factors to entry requirements. The usual names on the list: multi-factor authentication on email, remote access and privileged accounts; backups that are tested and kept separated from the live network, so an attacker who gets in cannot encrypt them too; endpoint detection and response rather than bare antivirus; and disciplined patching of known vulnerabilities. Requirements vary by insurer and scale with the size of the risk — but after an incident, expect them to be verified, not assumed.
If the incident exposed a gap in one of these, closing that gap is the single most useful thing you can do before approaching the market.
The incident must be declared wherever a proposal asks — and cyber proposals ask directly. Under the Insurance Act 2015 you owe insurers a fair presentation of the risk, and a breach that surfaces after you have signed a form that denied it is the kind of thing that puts policies, and future claims, in jeopardy. The honest version is also the more persuasive one: “we had an incident, this is what it cost, this is what we changed” is a story underwriters hear regularly and can price. A discovered omission is a story that ends placements.
Remediation you can evidence. Not “we take security seriously now” but the specifics: the controls implemented, the dates, the invoices, the report from the incident response firm if one was engaged, and any lessons-learned document. Evidence converts a scare story into a managed risk.
Ongoing arrangements. An incident response retainer, a managed detection provider, or a named security lead all tell an underwriter that the next incident would be found and handled faster. So does staff training with a date on it, particularly where the incident began with a phishing email.
A presentation, not a form. A broker can put the incident, the remediation and the business context in front of insurers whose appetite fits, the way we describe in how brokers place hard risks. We will not promise terms — but we can make sure the market judges the risk you are now, not the risk you were.
If your incident involved someone being tricked — a diverted payment, a spoofed supplier, a fake instruction from a “director” — be aware that these losses sit at an awkward junction between policies. Cyber policies may cover them, sub-limit them or exclude them; crime policies have their own wordings; and where client money moves on a professional’s instruction, professional indemnity can be engaged. The conditions attached to this cover are strict and vary widely — we walk through them in social engineering cover conditions. After an incident is exactly the moment to map this boundary deliberately across everything you hold.
A previous incident does not make cyber cover unobtainable, but it changes the conversation. Insurers will want to understand what happened, how it was resolved and — above all — what has changed since. A business that can evidence its remediation is in a far stronger position than one that simply hopes the question will not come up. No broker can guarantee terms, but presenting the incident and the fixes properly is what gives the market a fair chance to say yes.
If a proposal asks about incidents, breaches or losses — and cyber proposals do — answer what is asked, fully and honestly, whether or not you claimed, reported it, or dealt with it in-house. Under the Insurance Act 2015 you owe insurers a fair presentation of the risk. An incident that surfaces later, undeclared, puts the whole policy in jeopardy.
Common minimums in the current market include multi-factor authentication on email and remote access, backups that are tested and kept separated from the live network, endpoint detection and response on devices, and timely patching. Exact requirements vary by insurer and by the size of the risk, and after an incident you should expect them to be checked rather than taken on trust.
It depends on the policies you hold and their wording. Social engineering losses can fall under a cyber policy, a crime policy, or in some professional scenarios a professional indemnity policy — and each may carry its own conditions, sub-limits or exclusions. It is one of the most common gaps we see, and it is worth mapping deliberately rather than assuming.
Not automatically, but related covers can be affected. A crime or PI insurer may ask about fraud or system incidents on their own proposals, and the same duty of honest disclosure applies there. Answer each insurer’s questions as asked, and keep the story consistent across every placement.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.