Cyber policies can look identical until a claim exposes the difference
Mismatched triggers make cyber cover hard to compare, and a soft market is pulling wordings further apart
Cyber policies can look identical until a claim exposes the difference
CYBER
By Bryony Garlick
07 Oct 2026

Two cyber policies can have the same core sections, similar exclusions and familiar optional extensions, yet respond differently to the same incident. The difference may only become clear at claims stage, when a client discovers that a loss is calculated on a basis they had not understood. The broker who placed the policy is likely to get the first call. 

Gülsah Dagdelen, head of cyber at Tokio Marine HCC International, said some brokers, particularly those with large SME portfolios, compare wordings by their lists of exclusions and choose the one with fewer. That is not necessarily the better policy, she said, because it depends on how broadly or tightly the triggers are defined. Brokers who deal with cyber every day tend to spot the differences faster, a point that matters as over half of UK brokers name cyber as their strongest growth opportunity among emerging products. 

Where the wording splits 

Cyber cover has three core elements: first-party loss, third-party loss and forensic costs, alongside exclusions and optional extensions. Insurers can define the triggers for each differently. Business interruption is one example. “A business interruption loss is a business interruption loss, but it can be triggered by different factors and by different threats such as system failure or a malicious act, human error,” she said. 

In practice, the argument is rarely over whether an interruption happened, but over the size of the loss. System failure cover can also vary, with some insurers using named perils and others taking a broader approach.  

“We see clauses that are being drafted on a named peril version or on an unnamed, unintentional, however-caused basis,” Dagdelen said, noting that each version of the definition can also trigger different exclusions. 

Crime extensions, which have become far more prominent in cyber policies since last year, show the same problem: some brokers check only whether the cover is included and how high the sub-limit is. "Some of them were just offering a limited part covered and caused by a cyber incident, and some e-crime elements were so broad that they actually became a real crime extension within the cyber policy limit," she said. 
 
Third-party cover varies in the same way, starting with what counts as a data breach, which documents are protected and how the breach has to be caused. 

"The need of an SME is a simple cyber product that covers their main exposures, which is a business interruption, it is the liability part of data breach, and the forensic costs," Dagdelen said. Extras are "nice to have", she said, but SMEs want to know whether their main exposure is covered, and hidden exclusions and carve-backs are not easy for them to spot. 

Much SME cyber business has been placed at scale without looking closely at where a client's exposure comes from, such as being the only supplier to one important client. Smaller suppliers to Jaguar Land Rover and Marks & Spencer were hit by attacks on businesses they depended on, rather than on their own systems. 

What standardisation could fix 

Asked what could be standardised without limiting insurers’ ability to innovate, Dagdelen pointed to the triggers for business interruption and third-party loss, and to how losses are calculated. Those definitions used to be more consistent, she said, but in a soft market insurers want to differentiate themselves, and standardised approaches to some coverages are disappearing again. 

The EU's NIS2 and DORA set minimum security requirements for critical infrastructure and financial institutions, rather than rules on how cover is drafted. Dagdelen said she did not expect regulators to have "a real power on cyber policies in the near future" and saw no need for them to intervene, since any minimum requirements for a policy would have to be realistic for the market to provide. 

Where regulators should focus, is security. "The cyber policy is actually covering the residual risk, or should be covering the residual risk, and should not replace any cybersecurity elements that are key to protect the clients," she said. Government figures put the share of UK businesses reporting a breach or attack in the past year at 43%, while the National Cyber Security Centre has increased its efforts to help smaller firms strengthen their defences. 

The calculation question is where the gap shows most. At claims stage, the loss a client believes it has suffered and the figure produced under the policy and by the forensic firm can differ widely, causing frustration on both sides. Until the market agrees how core triggers and losses are defined, policies that share the same labels will keep giving different answers to the same incident. 

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB UK.