Cyber insurance is a contractual requirement. That’s because a successful attack can interrupt production, expose sensitive information, affect customers and generate recovery costs that suppliers may struggle to absorb.
Yet cyber insurance is often not treated as a priority, particularly by smaller suppliers. The biggest worry is that limits may be too low to cover a serious incident or that policy exclusions may make an attack ineligible for coverage.
If a supplier’s inadequate cybersecurity causes an incident that costs its prime contractor money, the prime’s insurance may initially cover the loss. The prime’s insurer could then seek to recover that money from the supplier or the supplier’s insurer.
Suppliers should begin by asking whether their coverage reflects the losses they could realistically experience. Those losses may include:
- Operational downtime and lost production
- Supply chain disruption
- Third-party liability
- Incident response and forensic investigation
- Legal and regulatory expenses
- System restoration and data recovery