Cyber Insurance

Cyber Insurance
21 July 2026Share
Get Your Quote

A Centurion parts distributor opens on a Monday to find every screen showing the same message: the files are encrypted, and payment is expected in a currency nobody in the building owns. The phones still ring. The orders can't be picked, invoiced, or delivered. The mechanism is simple: the business's systems are in someone else's hands, and every trading hour now has a price on it. Most businesses meet this moment with no plan and no cover.

What is cyber insurance?

What is cyber insurance?

Cyber insurance is a policy paying the costs a business faces when its systems, data, or funds are compromised. Your own recovery and lost income sit on one side, and claims from other people whose information was exposed sit on the other. It funds the response and the aftermath; it doesn't prevent the attack.

Key Takeaways

  • Cyber cover splits into first-party costs (your recovery, your lost income) and third-party liability (claims from the people whose data you kept).
  • POPIA, the Protection of Personal Information Act, turns a data breach into a legal event: the Information Regulator and every affected person must be notified, whatever the size of the breach.
  • Insurers now underwrite your security controls, so a wrong answer about MFA (the second code after your password) on the proposal form can sink the claim it was meant to fund.
  • Most South African incidents start with a person, not a firewall: phishing and payment redirection dominate the claim patterns.
  • Exclusions and sub-limits (smaller caps inside the overall limit) decide the payout, so the wording deserves a slower read than it usually gets.

Ransomware and cyber extortion cover

Ransomware cover is the part of the policy built for the worst Monday of your trading life. It buys a response rather than a rescue. When your files are encrypted and a countdown appears, the policy pays for the specialists who take over. Forensic investigators find how the attackers got in, negotiators who've spoken to this gang before handle the demand, and restoration teams rebuild from backups. Lawyers advise whether paying is lawful at all, since payment to a sanctioned group can turn a victim into an offender. Extortion has also grown a second act: attackers copy your data before encrypting it, then threaten to publish client records if the ransom stays unpaid. A clean backup no longer ends the conversation. The decision to pay or refuse is made in hours, under pressure, and most wordings require the insurer's consent first. Knowing who makes the call, and what the policy pays either way, is homework best done before the countdown starts.

What a POPIA data breach notification costs

A data breach in South Africa is a legal event before it is a technical one, and the legal half has invoices. Section 22 of the Protection of Personal Information Act requires you to notify the Information Regulator and every affected person as soon as reasonably possible after discovering a compromise. There's no minimum size: a stolen laptop with one spreadsheet qualifies. The duty sits in POPIA's full text; the practical costs arrive separately. You pay to work out whose information was taken, to write and send the notices, and to staff the phones when clients call in various states of calm. Often you also buy credit monitoring for the people exposed. Legal review sits on top, because a badly worded notice can invite the claims it was meant to defuse. Notification costs are a defined benefit in most cyber policies, capped by a sub-limit: a smaller ceiling inside the overall policy limit. That sub-limit is the number worth checking before you sign.

Business email compromise and payment redirection

The most common cyber loss in South Africa doesn't involve breaking into anything; it involves an email asking politely to be paid. Business email compromise works by patience. An attacker reads a genuine invoice thread, waits for the right moment, then sends new banking details from an address one letter away from the real one. The money leaves with full authorisation, which is what makes recovery so hard. SABRIC's annual crime statistics count digital banking fraud incidents rising from 31,612 in 2023 to 64,000 in 2024, with losses above R1.4 billion. The report puts the growth down to social engineering rather than broken systems. Policies treat this loss unevenly. Some cover it in full, some sub-limit it sharply, and some push it to a crime policy you may not own. Whether your wording pays for a payment you authorised is a question with an unsettling range of answers, and it deserves one before the invoice does.

Cyber insurance vs crime insurance

Cyber insurance and crime insurance overlap on exactly one square of the board, stolen money, and claims get contested on that square. A crime policy covers theft, including theft by electronic means; a cyber policy covers what happens to systems and data. When an attacker uses your email system to redirect a payment, both descriptions fit, and each insurer can read the loss as belonging on the other's policy. That argument is conducted slowly and at your expense. The two claims departments rarely compare notes unless someone makes them. The pattern repeats with employee fraud carried out through IT systems, and with funds moved after a password was phished. The fix isn't buying both policies and hoping but having both wordings read side by side, so the definitions meet without a gap between them. A loss falling between two policies pays out exactly what a loss with no policy pays.

Incident response and the first 72 hours

The first three days after discovery decide the size of the final bill. It's why insurers now sell a phone number as much as a policy. Most cyber policies include a breach response line answered around the clock, backed by a panel of forensic investigators, attorneys, and PR advisers, all pre-approved and pre-priced. Using them keeps costs inside the policy; appointing your own specialists without consent can leave those invoices outside it. The Information Regulator expects to hear from you early too. Its security compromise guidance says a compromise should be reported through its online portal as soon as you're reasonably sure one occurred, before the investigation is complete. The clock runs whether or not anyone answers your IT company's after-hours line. A rehearsed response with the hotline number printed somewhere findable beats an eloquent plan nobody can open because the server it lives on is encrypted.

The myth of being too small to hack

Small businesses get attacked because they're easier, not because they're glamorous, and the attackers' software doesn't check turnover before knocking. Automated scanning works like someone walking a parking lot testing car doors: the expensive car isn't the target, the unlocked one is. An eight-person accounting practice stores ID numbers, salaries, and banking details for hundreds of people. Those are the same categories of personal information a bank guards, with a security budget the practice can't match. POPIA doesn't scale its duties down for small responsible parties either; notification obligations apply whether you have a compliance department or a compliance afternoon. The belief in being too small to bother with survives because most SME incidents stay unreported and undiscussed. Each victim assumes they were unlucky rather than typical. Insurers see the pattern from the claims side, which is why SME proposal forms now arrive with pointed questions attached. The pointed questions deserve honest answers.

The underwriting questionnaire and MFA

The underwriting questionnaire and MFA

The proposal form has become part of the policy, and your answers about security controls can decide a claim years later. Insurers now ask whether you use multi-factor authentication (MFA, the second code from your phone after the password), and whether backups sit offline where ransomware can't reach them. They also ask how quickly you patch known software flaws. Answer yes when the honest answer is mostly, and the insurer may treat the difference as grounds to walk away at claim stage. The direction is regulatory as well as commercial: the FSCA and Prudential Authority's cybersecurity joint standard sets formal cyber resilience requirements for financial institutions. Commercial proposal forms increasingly echo its assumptions. We ask clients the awkward version of these questions before the insurer does, a habit we're told is tiresome right up until claim stage. Complete the form with your IT person in the room, and keep the evidence behind every answer.

First-party costs vs third-party liability

A cyber policy divides into two halves: money spent on your own recovery, called first-party costs, and money paid to people who suffered because of your breach, called third-party liability. The halves carry separate limits and separate exclusions, so a policy can be generous on one side and threadbare on the other. The table below shows where the common costs land.

Where common cyber losses sit in the policy.

[@portabletext/react] Unknown block type "table", specify a component for it in the `components.types` prop

A services firm keeping sensitive client files leans on the third-party half; a distributor trading through its systems leans on the first. Reading your limits against the shape of your business shows which half is doing the real work, and which half is decoration.

Business interruption from a system outage

Lost income while your systems are down is often the largest slice of a cyber claim, and the slice most owners misjudge. Cyber business interruption pays the profit you would have earned during the outage, after a waiting period. That's the number of hours you carry alone before cover starts, an excess measured in time instead of rand. A wholesaler taking orders through a portal loses revenue from the first dark hour, while a consultancy can invoice by hand for a week without bleeding. The same waiting period is trivial for one and ruinous for the other. Proving the loss takes records too. The insurer pays demonstrated profit, not estimated inconvenience, and the demonstration comes from management accounts kept somewhere the attackers didn't encrypt. Match the waiting period to how long you can genuinely trade on paper, and assume the honest answer is shorter than the confident one offered in meetings.

Cloud provider failure and dependent cover

When your cloud provider fails, your income stops, but a standard cyber policy may not respond, because the system in trouble was never yours. Cover for your own systems is the default. Cover for the systems you rent, the hosting platform, the accounting software, the booking engine, arrives through an extension usually called dependent or contingent business interruption. The cloud is someone else's computer, and someone else's computer can have a bad week. Wordings differ on which providers count, how long the outage must last before cover begins, and whether an attack on the provider is treated differently from the provider's own error. A business running entirely on rented software can discover its policy covers the one thing it doesn't have: servers of its own. Listing every service you rent, then reading the extension against the list, is a half-hour exercise with a large payoff. It beats discovering the gap in the middle of somebody else's outage.

What cyber policies exclude

The exclusions page settles more cyber claims than the cover page, and it rewards a slower read than it usually gets. The recurring names: attacks attributed to war or state-backed groups, an attribution argument the global market is still conducting. Losses flowing from a control you told the insurer you had but didn't maintain sit alongside incidents known about before the policy started. Unencrypted laptops and phones appear too, along with betterment, meaning the insurer restores the system you had, not the upgraded one you'd prefer. Fines sit in a category of their own, payable only where the law allows insurance to pay them. Each exclusion is an answer to a claim the market has already paid and regretted, which makes the page a history book as much as a contract. None of it is hidden; it's on page fourteen, where reading tends to stop. The time to disagree with an exclusion is before renewal, not after discovery.

What cyber insurance costs in South Africa

What cyber insurance costs follows your data, your controls, and your sector more closely than your turnover. Underwriters price the records you store, since ten thousand ID numbers cost more to expose than ten thousand delivery notes. They price the controls you can prove, with MFA and offline backups moving the premium the way a burglar alarm moves a house premium. And they price your industry, with professional services, healthcare, and finance paying for the sensitivity of what they keep. The excess structure does its own work too: ransomware sections often carry co-insurance, meaning you share a stated percentage of each loss. That detail has a talent for going unnoticed at signature. The cheapest quote on the table usually earns its price through thin sub-limits rather than efficient underwriting. Comparing premiums without comparing limits is how a business buys a certificate instead of a policy, and the difference between the two only shows up once.

Cyber liability insurance narrows the focus where it matters most

Cyber insurance is the broad umbrella; cyber liability insurance is the specific panel covering your legal exposure to third parties when their data, money, or systems are harmed by an incident on your side. The distinction matters because South African regulators and plaintiffs don't particularly care which policy you thought applied: POPIA imposes direct liability on the responsible party, and the Information Regulator can pursue enforcement regardless of whether your insurer agrees the claim sits in the right column. Evidence from comparable jurisdictions shows third-party liability claims, including regulatory penalties, customer notification costs, and civil damages, routinely exceed first-party recovery costs once a breach affects more than a few hundred records. For South African businesses holding customer data at scale, that exposure isn't theoretical — it's the part of the bill that arrives after you've already dealt with your own mess. Our cyber liability insurance guide unpacks the specific cover structures available locally, the liability triggers most policies recognise, and the exclusions worth reading before you assume the umbrella covers the panel beneath it.

The torch in the kitchen drawer

The torch in the kitchen drawer

Load-shedding taught South African businesses a useful habit: the torch lives in the kitchen drawer, bought once and findable in the dark, resented until the night it's needed. Cyber cover belongs to the same family of purchases. Nobody admires it, nothing about it photographs well, and in the year it goes unused it looks like money you spent on nothing. Yet the businesses recovering fastest from an attack aren't the ones with the best firewalls. They're the ones who knew, before the screens froze, whose number to dial and what the policy in the drawer would pay.

You shouldn't have to learn what your policy excludes from the person holding your files hostage. With Mont Blanc Financial Services you won't.

Contact Mont Blanc Financial Services to have your cyber cover read, questioned, and matched to the way your business trades online.

Share
Nicola Iozzo

Nicola Iozzo

Founder & CEO, Mont Blanc Financial Services

Nicola has spent his career reading the policy wording most people skip, and writes here so you don't discover at claim stage what page 14 meant.

This blog is here to inform, not advise. Think of it as a guidebook, not a contract. For decisions affecting your world, have a chat with your broker or financial professional.

Mont Blanc Financial Services (PTY) Ltd. is an authorised financial services provider. FSP 8271

Cyber liability insurance cover for South African businesses
Cyber liability insurance cover for South African businesses

Cyber liability insurance protects South African businesses from the financial fallout of data breaches, ransomware attacks, and third-party claims arising from cyber incidents.

Commercial Building Insurance in South Africa
Commercial Building Insurance in South Africa

Commercial building insurance in South Africa explained: replacement value, SASRIA, storm and fire cover, and the exclusions deciding claims before you do.

Computer and Electronic Equipment Insurance
Computer and Electronic Equipment Insurance

Computer insurance covers your hardware, data and downtime when surges, theft or lightning strike. See what it covers in South Africa, and where cyber begins.