In brief
A cyber-insurance review should consider:
- what personal, commercial and payment data the business holds;
- which systems are critical to operations;
- ransomware and business-interruption exposure;
- phishing and business email compromise;
- funds-transfer and social-engineering exposure;
- cloud and third-party providers;
- MFA, backups, endpoint security and privileged access;
- incident-response and breach-management arrangements;
- legal, forensic, notification and public-relations costs;
- cybercrime, business-interruption and system-failure wording;
- limits, deductibles and waiting periods; and
- overlap with professional indemnity or crime cover.
The useful question is not simply “do we have cyber insurance?” It is whether the controls, exposure and policy are aligned.
The Hong Kong cyber environment is becoming harder to ignore
HKCERT reported a record 15,877 cybersecurity incidents in Hong Kong in 2025, a 27% year-on-year increase. Phishing represented 57% of reported incidents. Those numbers should not be used to suggest that every company will suffer a cyber loss. They do show why cyber risk is now a mainstream management issue rather than a specialist IT topic. The rise of AI-assisted phishing, social engineering and supply-chain risk also makes it harder to rely on employee intuition alone to identify fraudulent communications.
Cyber loss is not only a data-breach problem
A company can suffer a material cyber loss without large volumes of consumer data being stolen. Examples include:
- ransomware stopping operations;
- business email compromise redirecting a payment;
- a cloud provider outage interrupting service;
- malicious deletion or corruption of data;
- fraudulent instruction impersonating a director or supplier;
- system restoration and forensic costs; or
- contractual claims following a technology incident.
That is why the review should begin with what would stop the business operating or cause money to leave the organisation, not just with privacy compliance.
What does cyber insurance typically try to address?
The exact scope varies by insurer, but modern cyber policies may include elements such as:
- incident-response costs;
- forensic investigation;
- legal advice;
- data-breach response and notification;
- restoration of systems or data;
- cyber business interruption;
- ransomware or cyber extortion subject to policy terms and law;
- privacy liability;
- network-security liability;
- cybercrime or social-engineering cover where included; and
- crisis communications.
Not every policy contains every feature, and sub-limits can be important. A headline cyber limit should therefore be read alongside the coverage grants, waiting periods, deductibles and cybercrime structure.
Business email compromise deserves separate attention
Business email compromise can create a direct financial loss when criminals impersonate senior executives, suppliers, customers or finance colleagues. The insurance position can be complicated because some cyber policies include limited social-engineering or funds-transfer protection, while some crime policies address similar losses differently. More importantly, insurers increasingly ask about payment controls. Useful controls can include independent call-back verification for changes in bank details, separation of duties, approval thresholds and restrictions on urgent payment changes. The best insurance discussion therefore connects control design and policy wording.
Ransomware and business interruption
Ransomware can create several costs at once: forensic response, system restoration, operational interruption, external advisers and potentially liability to customers or data subjects. When reviewing business-interruption cover, management should understand:
- what event triggers the cover;
- any waiting period;
- how loss is calculated;
- whether contingent or dependent business interruption is included;
- system-failure treatment;
- limits and sub-limits; and
- the period over which loss can be measured.
Backups also matter operationally and to underwriting. A backup strategy only works if restoration has been tested and critical systems can actually be recovered.
What we see in practice
Cyber applications can become an annual compliance exercise: tick MFA, tick backups, tick endpoint protection, submit form. That misses the point. If the finance team can still change supplier bank details based on a single email, or if backups have never been restored, the existence of a control on the questionnaire may not reflect the real exposure. A better renewal uses the underwriting questions as a prompt to test whether the control operates in practice.
Cyber and PI should be considered together
For technology, consulting and other service businesses, cyber and professional-indemnity exposures may overlap. A client may allege that a security failure was also a failure in professional services. A technology error may create both restoration costs and contractual liability. A data incident may trigger privacy obligations and a claim from a customer. Cyber and PI are not substitutes for one another. Reviewing both together can help identify gaps, duplication and how the policies are intended to respond.
Third-party and supply-chain exposure
Businesses increasingly rely on cloud infrastructure, managed service providers, payroll platforms, payment providers and other technology vendors. A disruption at one supplier can affect many insured businesses at once. Cyber review should therefore consider:
- critical third-party dependencies;
- contractual allocation of responsibility;
- access privileges granted to suppliers;
- data held by vendors;
- contingency plans; and
- whether dependent-business-interruption or related coverage is included.
For multinational groups, shared systems can turn one local incident into a regional event.
A practical management checklist
Management should be able to answer:
- Data – what sensitive information is held and where.
- Critical systems – what would stop revenue or operations if unavailable.
- MFA – whether it is enforced for email, remote access and privileged accounts.
- Backups – whether they are segregated and restoration has been tested.
- Payments – how bank-detail changes are independently verified.
- Vendors – which third parties could interrupt operations.
- Incident response – who leads legal, forensic, IT, insurer and communications response.
- Policy fit – whether cybercrime, business interruption, system failure and third-party dependencies are treated as expected.
- PI overlap and renewal – whether a cyber event could become a professional-services claim and what has changed since the last placement.
The Trusted Union perspective: use insurance underwriting to improve the risk conversation
Cyber insurance should not be positioned as a promise that technology failure can be outsourced. The placement process is useful because it forces management, IT, finance and advisers to discuss the same risk in practical terms. Trusted Union reviews the business’s data, operational dependencies, payment controls, cyber controls, contractual requirements and policy structure, then considers insurer appetite and available terms. The strongest outcome is not merely a policy. It is a clearer understanding of how the business intends to prevent, respond to and finance a cyber event.
Cyber insurance works best when the policy and the controls tell the same story.
Trusted Union helps businesses review cyber exposure, underwriting requirements, policy structure and insurer options with clearer management context.
Explore Business Protection
