Coverage Register
Every line of cover · Liability

Cyber

Your own costs after a security incident (forensics, notification, restoration, business interruption from a network outage, extortion) and your liability to others for the data and systems you failed to protect.

On the schedule

Also calledcyber liability, network security and privacy, data breach cover
FamilyLiability
Responds whenA ransomware event, a data breach, a business email compromise or a system outage caused by an attacker.

Which industries carry it

Usually held byProfessional services, Software and SaaS, Healthcare provider, Retail, Education, Financial services, Energy and utilities, Media and marketing, Public sector
Often needed, often lackingFood manufacturing, General manufacturing, Logistics and warehousing, Construction, Hospitality, Mining and resources, Agriculture, Non-profit, Property owner, Transport, Wholesale distribution

Standards this line engages

14 clauses

Clause text quoted from a human-verified compliance corpus under licence. Clauses marked for APRA-regulated buyers or US insurance licensees appear on a register only for those buyers.

ISO 31000 6.5.2 Selection of risk treatment options

Guidance: choosing treatment options balances the benefits for the objectives against the cost, effort and disadvantages of implementing them. Options are not mutually exclusive and not all fit every situation; they include avoiding the risk by not starting or continuing the activity, taking or increasing the risk to pursue an opportunity, removing the risk ...

Evidence an auditor accepts: Treatment option analysis per risk showing the options considered, their cost and benefit, and the one chosen; Insurance schedule, contracts and other risk-sharing arrangements tied to the risks they transfer; Documented retained and residual risk with the decision maker's acceptance
Common gap: Only mitigation considered; avoiding, taking or sharing never on the table
ISO 31000:2018 on compliance.theartofservice.com
ISO 31000 6.4.2 Risk identification

Guidance: risk identification finds, recognizes and describes the risks that might help or prevent the organization achieving its objectives, and depends on relevant, appropriate and current information. A range of techniques can be used to find the uncertainties that affect objectives, and the following factors and the relationships between them should be c...

Evidence an auditor accepts: Risk register entries with source, event, cause and consequence described; Identification techniques used (workshops, checklists, scenario analysis, indicators) and who took part; Opportunities recorded alongside threats
Common gap: Only threats identified, never opportunities
ISO 31000:2018 on compliance.theartofservice.com
Lloyd's cyber Risk Selection Cyber Risk selection and the cyber hygiene baseline before binding

Lloyds Cyber Insurance Requirements - Risk Selection and Cyber Hygiene Underwriting Criteria. Underwriters must conduct rigorous risk selection + due diligence assessing insured-cyber hygiene including: (a) Mandatory cyber hygiene requirements (insurance-grade baseline expectation): Multi-Factor Authentication (MFA) on all privileged accounts + all remote ac...

Evidence an auditor accepts: Mandatory hygiene requirements documented (MFA + EDR + backups); External attack surface scan reports (Bitsight/SecurityScorecard); Dark web monitoring
Common gap: No mandatory hygiene
Lloyd's cyber underwriting requirements on compliance.theartofservice.com
Lloyd's cyber Affirmative Coverage Property Affirmative cyber cover and the model clauses on property policies

Lloyds of London Cyber Insurance Requirements - Affirmative Cyber Coverage Mandate. Following Lloyds Market Bulletin Y5258 (issued 16 August 2022) all Property Policies underwritten by Lloyds market participants must clearly state from 31 March 2023 onwards whether cyber-related losses are covered + excluded + with no implicit ambiguity (silent cyber elimina...

Evidence an auditor accepts: Property policy wordings post-March 2023; LMA5400-5405 model clause incorporation; Coverholder binder LMA compliance evidence
Common gap: Property policies still silent
Lloyd's cyber underwriting requirements on compliance.theartofservice.com
Lloyd's cyber Claims Handling Standards Claims handling for cyber events, sanctions and ransomware payments

Lloyds Cyber Insurance Requirements - Claims Handling Standards for Cyber Events and Sanctions/Ransomware Compliance. Claims Handling Standards for Cyber Events: (a) Specialised cyber claims handling capability + Lloyds claims handler training in cyber-specific issues + Computer Forensics + Digital Forensics and Incident Response (DFIR) integration + Coaliti...

Evidence an auditor accepts: Cyber-specialised claims handler evidence; 24/7 incident response hotline; Pre-approved vendor panels
Common gap: No specialised cyber claims
Lloyd's cyber underwriting requirements on compliance.theartofservice.com
Lloyd's cyber War Cyber Operation War and state-backed cyber operation exclusions and their carve-backs

Lloyds Cyber Insurance Requirements - War, Cyber Operation, and State-Backed Exclusions. Following NotPetya 2017 + WannaCry 2017 + SolarWinds 2020 + Colonial Pipeline 2021 industry-wide reassessment of war + state-backed cyber exclusion language driven by Lloyds Market Bulletin Y5258. LMA5400-LMA5403 model exclusions for war + cyber operation provide tiered ...

Evidence an auditor accepts: LMA5400/5401/5402/5403 selection rationale; Attribution mechanism documentation; Government attribution monitoring
Common gap: No attribution mechanism
Lloyd's cyber underwriting requirements on compliance.theartofservice.com
NAIC 668 NAIC-2 Information Security Program (ISP) - Section 4 (US insurance licensees)

Develop, implement, and maintain a comprehensive written Information Security Program (ISP) based on the licensees risk assessment that includes administrative, technical, and physical safeguards for protecting Nonpublic Information and the licensees information systems. Scale the ISP commensurate with size + complexity + nature + scope of activities + sensi...

Evidence an auditor accepts: Written Information Security Program document; Section 4(D) control mapping (1-9); Annual program review
Common gap: No written program
NAIC Insurance Data Security Model Law (MDL-668) on compliance.theartofservice.com
NAIC 668 NAIC-3 Risk Assessment and Risk Management - Section 4(B) and 4(C) (US insurance licensees)

Conduct comprehensive risk assessments to identify reasonably foreseeable internal and external threats that could result in unauthorised access to or transmission, disclosure, misuse, alteration, or destruction of Nonpublic Information stored on the licensees information systems. Assess likelihood and potential damage. Reassess sufficiency of safeguards on ...

Evidence an auditor accepts: Annual risk assessment report; Threat modelling output; Risk register with treatment decisions
Common gap: No documented risk assessment
NAIC Insurance Data Security Model Law (MDL-668) on compliance.theartofservice.com
NAIC 668 NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 (US insurance licensees)

Establish a written Incident Response Plan to respond to and recover from a Cybersecurity Event. Investigate Cybersecurity Events to determine scope + Nonpublic Information involved + impact of the Event + reasonable measures to restore the security of the Information Systems compromised. Notify the state insurance commissioner of the state-of-domicile withi...

Evidence an auditor accepts: Written Incident Response Plan; Cybersecurity Event log; 72-hour Commissioner notification record
Common gap: No written IRP
NAIC Insurance Data Security Model Law (MDL-668) on compliance.theartofservice.com
CPS 230 P25 Information and Technology Capability and Asset Health (APRA-regulated buyers)

The entity must maintain sound information and technology capability to meet current and projected business requirements and to support critical operations and risk management, and in managing technology risk must monitor the age and health of its information assets and meet the information security requirements of CPS 234.

Evidence an auditor accepts: Technology capability assessment against current and projected requirements; Asset age and health monitoring records including end of life tracking; Evidence of CPS 234 compliance linkage
Common gap: Legacy asset age and health untracked
APRA CPS 230 on compliance.theartofservice.com
ISO 31000 6.4.3 Risk analysis

Guidance: risk analysis builds an understanding of the nature and characteristics of a risk, including its level where appropriate, by considering in detail uncertainties, sources, consequences, likelihood, events, scenarios, controls and how effective they are; one event can have several causes and consequences and touch several objectives. Analysis can be ...

Evidence an auditor accepts: Analysis record per risk: likelihood, consequence, existing controls and their effectiveness, level of risk; Statement of assumptions, exclusions, information quality and confidence attached to the analysis; Choice of qualitative or quantitative technique and the reason
Common gap: Control effectiveness assumed rather than assessed
ISO 31000:2018 on compliance.theartofservice.com
ISO 31000 6.3.4 Defining risk criteria

Guidance: the organization should specify the amount and type of risk it may or may not take relative to its objectives, and should define criteria for judging the significance of risk and supporting decisions. Risk criteria should align with the framework and be customized to the purpose and scope of the activity; they should reflect the organization's valu...

Evidence an auditor accepts: Documented risk criteria: consequence and likelihood scales, how level of risk is derived, time horizons, treatment of combined risks; Risk appetite or tolerance statement the criteria derive from; Review record showing criteria revisited when context changed
Common gap: A five-by-five matrix with no definition of what a consequence level means
ISO 31000:2018 on compliance.theartofservice.com
COSO ERM principle 13 Implements Risk Responses

The organization identifies and selects risk responses.

Evidence an auditor accepts: Risk treatment plans; Action owner assignments; Cost-benefit analyses
Common gap: Response chosen without analysis
COSO ERM 2017 on compliance.theartofservice.com
COSO ERM principle 11 Assesses Severity of Risk

The organization assesses the severity of risk.

Evidence an auditor accepts: Likelihood-impact matrix; Inherent vs residual risk ratings; Scenario analysis
Common gap: Subjective scoring only
COSO ERM 2017 on compliance.theartofservice.com

Do this for every line on your schedule

Paste the schedule and get this classification for every line at once, with the retained and transferred figures, the rate on line, the loss ratio, the findings and the questions for the broker. Six lines free, no account.

Build my coverage register

Clinical trials liability · Environmental and pollution liability