← Texas Business Law Glossary

Texas Business Law · Glossary

Cyber Insurance

A specialized insurance product covering risks associated with cyber events, data breaches, ransomware, business interruption from cyber incidents, regulatory investigations, and third-party liability for cyber-related harm. Typically includes both first-party coverage (the insured's own losses, forensics, notification, business interruption, ransom payments) and third-party coverage (claims by others, customers, regulators, payment networks). Market has matured significantly; underwriting now requires substantial security controls.

Cyber insurance is a specialized insurance product covering risks associated with cyber events, data breaches, ransomware attacks, business interruption from cyber incidents, regulatory investigations, and third-party liability arising from cyber-related harm. The market has matured rapidly: from a niche product 15 years ago to a standard component of commercial insurance programs. Underwriting practices have tightened significantly with rising claim costs, particularly from ransomware. Modern policies typically require substantial security controls (multi-factor authentication, endpoint detection, backup discipline) as conditions of coverage.

Coverage structure, first-party

First-party cyber coverage addresses the insured's own losses arising from a cyber event: (1) incident response, forensic investigation, IT remediation, legal counsel; (2) notification costs, notifying affected individuals as required by breach laws; (3) credit monitoring for affected individuals (often 1-2 years); (4) public relations, crisis communications and reputation management; (5) business interruption, lost income from systems being unavailable; (6) contingent business interruption, losses from third-party providers (cloud, payment processors) experiencing cyber events; (7) data restoration, costs to recover lost or corrupted data; (8) cyber extortion, ransomware payments and negotiation costs (subject to OFAC sanctions compliance); (9) fraudulent funds transfer, coverage for social engineering/business email compromise (often sub-limited).

Coverage structure, third-party

Third-party cyber coverage addresses claims by others arising from a cyber event: (1) privacy liability, claims by individuals whose data was compromised; (2) regulatory defense, investigations and proceedings by regulators (FTC, state AGs, sectoral regulators); (3) regulatory fines and penalties, coverage where insurable (varies by jurisdiction; some fines uninsurable for public policy reasons); (4) PCI fines and assessments, penalties from payment card networks for breaches involving cardholder data; (5) media liability, defamation, copyright, trademark claims arising from online content; (6) network security liability, claims by parties whose networks or data were harmed by malware originating from the insured's systems.

Common exclusions and limitations

Modern cyber policies contain significant exclusions: (1) war and terrorism, particularly nation-state attribution exclusions, which have been heavily litigated post-NotPetya (Mondelez v. Zurich); (2) infrastructure failure not caused by cyber attack; (3) bodily injury and property damage, typically routed to other policies; (4) known incidents, events known prior to inception; (5) fraudulent acts of the insured; (6) contractual liability in some forms; (7) OFAC-prohibited ransom payments, coverage cannot fund payments to sanctioned actors. Sublimits and coinsurance are common: ransomware sub-limits, social engineering sub-limits, regulatory sub-limits.

Underwriting requirements (post-2021)

The cyber insurance market has tightened significantly post-2020 due to rising ransomware claim costs. Modern underwriting typically requires: (1) multi-factor authentication (MFA) on all remote access, email, and privileged accounts; (2) endpoint detection and response (EDR) deployment; (3) privileged access management (PAM); (4) email security with phishing protection; (5) backup discipline, offline or immutable backups; (6) incident response plan; (7) employee security training; (8) vulnerability management with regular patching; (9) network segmentation; (10) vendor risk management. Failure to maintain stated controls during the policy period can void coverage.

Texas regulatory exposure

Texas-based cyber insureds face several layered regulatory exposures: (1) Texas breach notification under Tex. Bus. & Com. Code § 521.053 (60-day notification requirement); (2) Texas Data Privacy and Security Act (TDPSA, effective July 1, 2024), sectoral compliance requirements with civil penalties up to $7,500 per violation; (3) federal sectoral laws, HIPAA (healthcare), GLBA (financial), COPPA (children); (4) FTC enforcement for unfair/deceptive data practices; (5) plaintiff class actions, Texas residents have state-law privacy claims and federal claims under various theories. Cyber insurance addresses defense and (in many cases) settlement costs across all these vectors.

Ransomware and OFAC

Ransomware payments raise OFAC compliance issues. The Treasury Department's Office of Foreign Assets Control (OFAC) maintains a sanctions list of designated individuals and entities. Payments to sanctioned actors are unlawful regardless of the urgency of the situation. OFAC's October 2020 advisory (and subsequent updates) emphasizes that ransomware payments may violate sanctions, with exposure for both the victim and any facilitating parties (insurers, ransomware negotiators, financial institutions). Cyber insurance policies typically condition ransom-payment coverage on OFAC compliance, payments to sanctioned actors are excluded. Best practice: engage OFAC-aware ransomware negotiation specialists who can run sanctions checks before any payment.

Coordination with other coverage

Cyber claims often implicate multiple insurance policies: (1) CGL, possible privacy injury coverage under Coverage B, though most modern CGLs exclude cyber; (2) D&O, securities and shareholder claims arising from cyber disclosure failures; (3) E&O, professional liability for technology providers; (4) crime/fidelity, employee theft and computer fraud; (5) kidnap and ransom, sometimes overlaps with cyber extortion. Sophisticated insurance programs coordinate cyber with these other coverages to avoid gaps and disputes among insurers.

Practical context

For Texas businesses, cyber insurance is increasingly essential. Best practice: (1) carry cyber insurance proportional to data sensitivity and business size, minimum $1M for small businesses with consumer data, often $5M-$25M for mid-market; (2) maintain underwriting-required security controls during the policy period (failures void coverage); (3) coordinate cyber with CGL, D&O, E&O, and crime policies to avoid gaps; (4) review war/nation-state exclusions carefully (recent litigation has narrowed coverage for state-sponsored attacks); (5) maintain incident response plans with pre-arranged forensic, legal, and PR resources; (6) for ransomware, engage OFAC-aware specialists before paying; (7) document security controls and policies to support claims. Common gap: many businesses still rely on CGL Coverage B for cyber exposure, most modern CGLs exclude cyber, so this approach leaves businesses uncovered. Standalone cyber insurance is the modern standard.

Companion article: Data Breach Response

Related Terms
Texas Data Privacy and Security Act· Commercial General Liability Insurance· Errors and Omissions Insurance· Directors and Officers Insurance· Representations and Warranties Insurance
Last updated: August 14, 2026