You Have Cyber Insurance. That Doesn’t Mean You’re Covered.

Having cyber insurance is not the same as being covered: a policy won’t stop the downtime, the lost contracts or the reputational damage, and insurers decline to pay more often than boards expect. The businesses that survive an attack treat insurance as a backstop, not a plan, and can answer the right questions long before they need to claim.

Picture a Monday morning where the whole operation grinds to a halt. The screens are locked, drivers are out on the road, but you can’t see them, and customers are calling about untraceable consignments. Within the hour the business is running on notepads. 

For many boards, it’s a reasonable assumption that cyber insurance will alleviate the stress of a morning like that. This is where many operational businesses get caught out, because having a policy and being covered aren’t the same thing. The gap between the two is where the real cost lands: the weeks of lost trading, the contracts that move to a competitor, and the claim that gets declined at the worst possible moment. 

Across more than 200+ ransomware recoveries, we see the same pattern: the business had cover, assumed that meant it was protected, and found out too late that a policy is only as good as what sits behind it. Here’s what that means for a transport or logistics business and the questions worth asking before you need the answers. 

 

The Real Cost Goes Beyond the Ransom  

The ransom demand is the number that makes the headlines, but it’s only ever part of an even bigger picture. For an operational business, most of the damage is in the standstill. When the systems go down, so does the ability to trade: no dispatch, no tracking, no invoicing, no way to tell a customer where their freight is. Every hour of that is revenue you don’t get back, and it stacks up alongside the ransom, the recovery bill and everything else that follows. 

The standstill also lasts longer than most boards expect. In our experience, getting the basics running again takes at least a week, and being fully back to where you were is more often a matter of months than days. When Jaguar Land Rover had to halt production after an attack, the disruption ran on for weeks and rippled out to the suppliers who depend on it. For a mid-sized logistics or manufacturing business, the first month alone, lost trading plus recovery, can run well into seven figures. 

None of this is unusual any more, with ransomware demands against UK businesses doubling last year. 

Here’s the part that matters for the rest of this piece: an insurance payout doesn’t cover most of what’s on that bill. It won’t win back the customer who moved their contract while you were offline, and it won’t repair a reputation for delivering on time. 

 

The Claim That Gets Declined 

There’s a harder limit than what a policy fails to reach, and it’s the one that catches boards off guard: the insurer can decline to pay altogether. It happens more often than most people expect, and it usually comes down to a mismatch between what a business declared when it took the policy out and what it actually had in place. 

Most cover is granted on a self-assessment. When you take the policy out, you typically confirm things like the following: 

  • Multi-factor authentication is in place across the business 
  • You hold Cyber Essentials or equivalent 
  • The security basics are covered 

Tick the boxes, pay the premium, and the policy is issued. The problem surfaces after an incident, when the insurer’s forensics team goes in and checks whether those answers were true. If the reality doesn’t match the declaration, the policy can be voided, and the timing could not be worse. 

We’ve seen a business part-way through recovery, with lawyers, a PR firm and forensic specialists all engaged, told to stop because the insurer had ruled the cover invalid. By that point they were already around £150,000 in and now on the hook for it themselves. The policy they were counting on had quietly stopped existing at the exact moment they needed it. 

Therein lies the real gap. A policy is only ever as good as the answers behind it, which is why the most useful thing a board can do has nothing to do with insurance at all. It’s to check that those answers are true before anyone else has a chance to. 

 

Five Questions Worth Asking Before You Need the Answers 

Here are five worth putting to your IT team or provider this week, just to check whether the business is as protected as the policy assumes. 

-If we were hit on a weekend, how long until we could operate again, even on the basics? If the answer is vague, or noticeably longer than you’d assumed, that gap is your real exposure, not the ransom.

-Do we keep backups off our main network, and where do we keep the key that unlocks them? This is the one that catches people out. Plenty of businesses keep encrypted backups, then store the key to unlock them on the very network that gets encrypted in an attack. When that happens, the backups are there but unreadable.

-If we needed those backups tomorrow, how long would it actually take to get the data back? Cheap or poorly configured backups can take days to restore, which for an operational business is days of standstill you hadn’t planned for.

-Do we have a recovery plan, and when did we last rehearse it with everyone in the room? A plan no one has practised tends to fall apart under pressure. Everyone should know their role before the day it matters, not on it. 

-When did someone independent last check all of this, rather than us marking our own homework? An internal team confirming its own setup is fine until it’s the thing standing between you and a voided insurance claim. 

If those questions are easy to answer with confidence, that’s genuinely reassuring. If a few of them give you pause, that’s the point of asking now, while it costs nothing but a conversation. 

 

Deciding Before the Day Comes 

The businesses that come through an attack in one piece are usually the ones that made the decision early. We worked with one logistics operator whose cyber insurance quote came in at £180,000 a year. Rather than treat that number as the answer, they took the view that the money was better spent making sure they didn’t get hit in the first place and containing the damage if they ever were. That’s the whole shift this piece is about: moving from hoping the policy holds to knowing the business can take a hit and keep moving. 

That starts with a conversation, not a contract. We’re running a session for leaders of operational businesses, it covers what an attack actually costs, where insurance stops short, and the questions worth asking of your own setup, all drawn from real recovery experience rather than vendor slides. Sign up today. 

Share the Post: