Cyber insurance comes with a lot of jargon, and most of it shows up right when you’re trying to make a decision. This cyber insurance glossary explains 30 of the terms you’ll run into most often, in plain English, so you can read a quote or a policy without feeling lost. There’s no sales pitch here, just clear definitions written for small business owners rather than for actuaries.
Bookmark this page and come back to it whenever a word trips you up. If you want the bigger picture first, start with what cyber insurance actually covers, then use this cyber insurance glossary to fill in the details. Terms are grouped by theme, so related words sit next to each other.
Cyber insurance glossary: the basics
Start here. These five words show up on almost every policy, and once they click, the rest of the document reads a lot more easily.
Cyber insurance. A policy that helps your business recover after a hack, a data breach, a ransomware attack, or a costly online scam. It pays for things like forensic investigation, legal help, customer notification, lost income, and in some cases a ransom. It’s separate from your general liability and property coverage.
Cyber liability. The part of a cyber policy that deals with harm to other people, such as customers or business partners, when their data is exposed while in your care. If someone sues you or a regulator comes calling after a breach, this is the coverage that responds.
First party coverage. Pays for the losses your own business suffers directly. Think forensic investigation, data restoration, lost income while you’re down, and a ransom payment. It’s the money that helps you get back on your feet.
Third party coverage. Pays for claims made against you by other people, like the legal defense, settlements, and regulatory penalties tied to a breach of someone else’s data. The difference between these two is the single most useful idea in the whole policy, so it’s worth learning well.

Data breach. Any time private information gets exposed, stolen, or accessed by someone who shouldn’t have it. That includes customer records, payment details, employee files, and health data. A breach is usually what triggers a cyber claim in the first place.
What your policy pays for
These are the coverages that actually put money to work after an incident. Not every policy includes all of them, so this is a good checklist when you compare quotes.
Breach response costs. The bundle of first party expenses that kick in right after an incident: hiring a forensics team to find out what happened, notifying affected customers, setting up credit monitoring, and getting public relations help. On many small business policies this is the coverage you’ll actually use most.
Business interruption. Reimburses the income you lose when a cyber attack shuts down your systems and you can’t operate normally. It usually covers lost profit plus some of the extra costs of keeping the lights on while you recover.
Data restoration. Pays to rebuild, recover, or re enter data and software that was damaged, corrupted, or locked up in an attack. If ransomware scrambles your files, this is the coverage that funds getting them back.
Ransomware coverage (cyber extortion). Helps when a criminal locks your systems or threatens to leak your data and demands payment. It can cover the ransom itself, a professional negotiator, and the cleanup, though insurers now attach strict conditions. For the full picture, see our guide to ransomware insurance and what it excludes.
Social engineering coverage. Steps in when an employee is tricked into sending money or sensitive data to a scammer posing as a boss, vendor, or client. It’s one of the most common losses for small businesses, and it’s often capped by a sublimit, so check that number closely.
Regulatory defense and penalties. Covers the cost of responding to a government investigation after a breach, plus fines and penalties where the law allows them to be insured. Privacy rules exist in all 50 states, so this matters even for tiny companies.
The money words: limits, costs, and deductibles
Policy limit (aggregate limit). The most your insurer will pay in total during your policy period, usually one year. A common small business limit is $1 million. Once you hit it, anything above that comes out of your own pocket.
Sublimit. A smaller cap that sits inside your overall limit and applies to one specific type of loss. A policy with a $1 million limit might only offer $100,000 for social engineering fraud. Sublimits are where owners get caught out, so read them before you buy.

Retention (deductible). The amount you pay yourself on a claim before the insurer pays anything. On small business cyber policies it’s often around $2,500. A higher retention usually means a lower premium.
Premium. What you pay for the policy, normally billed once a year. Median cost for a small business runs near $1,740 a year in 2026, though your number depends on your size, industry, and security. You can check what coverage would cost your business to see real ranges.
Waiting period. The stretch of downtime that has to pass before business interruption coverage starts paying. It’s usually 8 to 12 hours. Short outages below that window come out of your own pocket, so it works a bit like a deductible measured in time.
Period of restoration. The window during which your lost income is covered while you recover, often 90 to 180 days. It ends when your systems are back to normal or the clock runs out, whichever comes first.
How insurers decide what to charge you
Your price is not random. It tracks the risk you carry and the security you have in place, so these terms are worth knowing before you apply.
Underwriting. The process an insurer uses to size up your risk and set your price. They look at your revenue, the kind of data you hold, your industry, and above all your security habits. Better security often means a lower premium.
Security controls. The specific protections insurers want to see before they’ll cover you, and often before they’ll pay a claim. The core set includes multifactor authentication, endpoint protection, tested backups, an incident response plan, and regular patching. Our cyber insurance requirements checklist walks through each one.

Multifactor authentication (MFA). A login that needs a second step beyond your password, like a code from your phone. It’s the single control insurers ask about most, because it blocks the majority of account takeovers. Missing MFA can mean a higher price or a flat decline.
Endpoint detection and response (EDR). Software that watches the laptops, phones, and servers across your business for signs of an attack and can shut a threat down fast. Insurers increasingly treat it as a baseline, not a nice to have.
Incident response plan. A written, tested plan for what your team does in the first hours of a breach: who to call, how to contain it, and how to keep records. Having one can lower your premium and speed up a claim.
Immutable backups. Copies of your data that can’t be changed or deleted once written, kept separate from your main network. They’re what lets you recover from ransomware without paying, which is exactly why insurers ask about them.
Application (proposal form). The questionnaire you fill out to get a quote, covering your revenue, data, and security. Answer it carefully and honestly. If the answers turn out to be wrong, the insurer can reduce or deny a claim later, so accuracy protects you.
Exclusions and claims
Exclusion. Something your policy specifically will not cover, spelled out in writing. Common cyber exclusions include known problems you didn’t fix, unpatched systems, insider theft, and acts of war. Reading the exclusions tells you as much as reading the coverage.
Retroactive date (prior acts). The earliest date an incident can have started and still be covered. Anything that began before that date is usually excluded, even if you only discover it now. A recent retroactive date leaves a gap, so ask about it.
Claims made policy. A policy that only responds if both the incident and the claim happen while the coverage is active. Most cyber policies work this way, which is why letting one lapse can leave you exposed for past events.
Breach coach. A specialist lawyer your insurer connects you with to steer the response after a breach. They guide the legal, notification, and forensic steps and help keep things privileged. Calling the breach coach early is one of the smartest moves you can make.
Notice (notification). Telling your insurer about an incident, and telling affected people that their data was exposed. Policies set tight deadlines for reporting, and missing them is a top reason claims get denied. When in doubt, report early.
Subrogation. After your insurer pays your claim, it may go after whoever actually caused the loss to recover the money, like a vendor whose mistake led to the breach. It happens behind the scenes and doesn’t cost you anything.
Key takeaways
Most cyber policy confusion comes down to a handful of ideas. Keep this cyber insurance glossary handy and the rest of the language gets much easier to read:
| Term | The one line version |
|---|---|
| First vs third party | Your own losses vs claims from other people. |
| Limit vs sublimit | The overall cap vs a smaller cap on one type of loss. |
| Retention | What you pay before the insurer pays. |
| Waiting period | The downtime before lost income coverage starts. |
| Security controls | The protections that decide your price and your claim. |
When you’re comparing policies, the numbers that matter most are the limit, the sublimits, and the security controls the insurer expects. Get those right and you’ll have coverage that actually pays when you need it. For a full walkthrough built around small companies, see our guide to cyber insurance for small business.
Frequently asked questions
What is the difference between first party and third party cyber insurance? First party coverage pays for your own losses, like forensics, downtime, and data recovery. Third party coverage pays for claims other people bring against you, like lawsuits and regulatory penalties after their data is exposed. A good policy includes both.
What does cyber insurance not cover? It won’t cover problems you knew about and ignored, unpatched systems, most insider theft, or losses that started before your retroactive date. Anything listed under exclusions is off the table, which is why those pages are worth reading.
What is a sublimit in cyber insurance? A sublimit is a smaller cap inside your total limit that applies to one kind of loss, often social engineering fraud. Your policy might have a $1 million limit but only $100,000 for that fraud, so the sublimit is the number that really matters for that risk.
What is a waiting period on a cyber policy? It’s the amount of downtime, usually 8 to 12 hours, that must pass before business interruption coverage starts paying. Outages shorter than the waiting period aren’t covered, so it acts like a deductible measured in hours instead of dollars.


