Free Quote

What is cyber insurance and what does it cover in Ireland?

Cyber insurance covers the financial damage an Irish business suffers when its systems, its data or its money are attacked. A typical policy pays for the specialist help you need in the first hours of an incident, the cost of rebuilding data and getting back to trading, the income lost while you are down, and the legal and regulatory work that follows if customer information was exposed. It can be bought on its own or added to a wider commercial insurance programme.

For most Irish SMEs the point of the policy is not the money alone. It is that a phone number answers at 2am and a team of people who have done this before take over.

Why do Irish SMEs need to think about this now?

Small and medium businesses are attractive targets precisely because they are small. They hold customer data, they move money, and they rarely have a full time security team. The two attacks that hurt Irish firms most often are ransomware, where your systems are encrypted and held to ransom, and business email compromise, where a criminal gets into or imitates an email account and redirects a payment.

An Garda Síochána has repeatedly warned Irish businesses about invoice redirection and chief executive fraud, where a supplier bank account is quietly changed or a staff member is instructed to make an urgent transfer. These are ordinary looking emails, not dramatic hacks, and they succeed against well run companies.

There is a regulatory dimension too. Under GDPR, a personal data breach must be notified to the Data Protection Commission without undue delay and, where feasible, within 72 hours of you becoming aware of it. Separately, the EU NIS2 Directive raises cybersecurity duties across a range of sectors. Ireland is transposing NIS2 through national legislation and the National Cyber Security Centre publishes guidance and a scope checking tool. If you supply energy, transport, water, health, digital infrastructure or public bodies, it is worth checking whether you fall in scope, either directly or through your customers’ supply chain requirements.

What does a cyber policy actually pay for?

Cover is usually split into first party losses, meaning your own costs, and third party losses, meaning what you owe other people. The table below shows how a typical Irish SME policy is built. Wordings vary a great deal between insurers, so treat this as a map rather than a promise.

Section What it typically pays for A real world example
Incident response Forensic IT specialists, legal advice and a breach response manager from the first phone call Staff arrive on Monday and every file is encrypted
Data and system restoration Recovering or rebuilding corrupted data, software and systems Your booking system and customer database have to be rebuilt from scratch
Business interruption Income lost while you cannot trade normally, and extra costs of working An online shop is offline for nine days in December
Cyber crime and funds transfer Money taken by fraudulent payment instruction or invoice redirection, where the policy includes this section A spoofed supplier email sends a large payment to a criminal account
Privacy and network liability Claims brought by customers or suppliers, plus the cost of defending them Customer records are published online after a breach
Regulatory defence Legal costs of dealing with a regulator, and fines where they are insurable in law The Data Protection Commission opens an inquiry into how the breach happened
Extortion Managing a ransom demand, subject to insurer consent and sanctions law Criminals threaten to publish stolen files unless paid
Notification and reputation Telling affected individuals, public relations support, credit or identity monitoring where relevant You have to write to several hundred customers within days

What is usually not covered?

No cyber policy covers everything. The common exclusions and limitations to look for are:

  • Physical damage to hardware, which normally sits under your property or business insurance rather than cyber
  • Losses caused by known but unpatched vulnerabilities you were warned about and ignored
  • Betterment, meaning the cost of upgrading your systems to a better standard than before the attack
  • Failures at a supplier or cloud provider, unless dependent business interruption is specifically included
  • War and state backed attack exclusions, which have become much tighter across the market in recent years
  • Funds transfer fraud, if the crime section was not purchased or the required payment verification steps were not followed

That last one causes more disputes than any other. If your policy says a second person must verify bank detail changes by phone before payment, and nobody did, the insurer may decline. It is worth reading that condition out loud to your accounts team.

What do insurers ask before they will quote?

Cyber underwriting has become far stricter. Insurers now treat basic controls as a condition of entry rather than a discount. Expect questions about:

  • Multi factor authentication on email, remote access and administrator accounts
  • Backups that are separated from your main network and tested by actually restoring from them
  • How quickly you apply security patches
  • Endpoint protection and whether it is monitored
  • Staff training on phishing and payment verification
  • Your payment authorisation process for changes to supplier bank details

The practical upside is that the questions themselves are a free security review. Businesses that put multi factor authentication in place and test their backups usually find both that cover becomes available to them and that the underlying risk drops. Answer the proposal form accurately, because the answers form the basis of the contract.

How much does cyber insurance cost in Ireland?

There is no single answer, and any figure quoted without knowing your business would be guesswork. Price is driven mainly by your turnover, your sector, the volume and sensitivity of the personal data you hold, whether you take card payments, the limit and excess you choose, and the quality of the controls above. A ten person consultancy and a hundred person online retailer are not in the same conversation.

What we can say plainly is that cyber is usually one of the smaller lines on a commercial insurance schedule relative to the size of loss it responds to, and that businesses with good controls are seen very differently by underwriters than those without.

Does it sit alongside your other cover?

Yes, and the joins matter. Your property policy covers the burnt server, not the lost data. Your public liability insurance covers a customer injured on your premises, not a customer whose data you leaked. Standard business interruption cover is usually triggered by physical damage, so a purely digital outage may fall outside it. Cyber insurance is designed to fill exactly those gaps, which is why it should be arranged with the rest of your programme in view rather than in isolation.

The bottom line

Cyber insurance is no longer an exotic purchase for technology companies. If your business runs on email, holds customer records, or pays suppliers by bank transfer, you carry cyber risk, and for most Irish SMEs the realistic worst case is a week of lost trading plus a data breach to manage in public. The policy buys you money and, more importantly, expert people on day one. Before you buy, get the basics in place, read the crime section and its conditions carefully, and make sure the cover lines up with the rest of your business insurance rather than overlapping or leaving a gap.

Breeze Insurance is an Irish insurance broker and we can search a panel of leading Irish insurers on your behalf and talk you through what a cyber policy would and would not do for your business. Give us a call on 0818 700 300, or request a quote online and we will come back to you.

Frequently asked questions

Is cyber insurance a legal requirement in Ireland?

No. There is no law obliging an Irish business to buy cyber insurance. What the law does require is that you protect personal data and report certain breaches, and increasingly your contracts may require it. Larger customers, public sector buyers and some professional bodies now ask suppliers to hold cyber cover as a condition of doing business.

Does my existing business insurance already cover a cyber attack?

Usually not in any meaningful way. Some commercial packages include a small cyber extension, but the limits are often modest and the incident response element, which is the most valuable part, is frequently missing. Check your schedule rather than assuming, and if you are unsure, ask your broker to show you the section in the wording.

Does cyber insurance cover invoice redirection fraud?

It can, but only if the policy includes a cyber crime or funds transfer fraud section, and only if you complied with the verification conditions attached to it. This is one of the most common losses for Irish SMEs and one of the most commonly missing covers, so raise it specifically when you are arranging the policy.

Do I still need cover if everything is in Microsoft 365 or Google Workspace?

Yes. Cloud providers secure their own infrastructure, but the data in your account, the accounts your staff log into and the payments your team makes are still your responsibility. Most business email compromise losses happen inside perfectly healthy cloud platforms, through a stolen password rather than a failure at the provider.

What is the first thing to do if we are attacked?

Call the incident response number on your policy before you start deleting things or paying anyone. Insurers typically require notification and consent before costs are incurred, and the response team will preserve the evidence you will need later. Then consider your GDPR notification duty to the Data Protection Commission, and report fraud to An Garda Síochána and to your bank immediately, because fast reporting occasionally allows a payment to be recalled.

Will an insurer refuse to pay if the breach was our own fault?

Cyber insurance is designed to respond to human error, so a staff member clicking a bad link is normally exactly what it is for. What can void a claim is something different: answering the proposal form inaccurately, ignoring a known vulnerability you told the insurer you had fixed, or breaching a specific policy condition such as the payment verification step. Honesty at proposal stage is the best protection you have.

Breeze Insurance Ltd. is regulated by the Central Bank of Ireland. Registered in the Republic of Ireland with registration number 109879 and registered address at 38/39 Fitzwilliam Square, Dublin 2, D02 NX53. Director: Colin Long.