Before comparing cyber policies, map the accounts and data your agency handles. Ask how each policy treats incident response, your own losses and claims by others. Cyber insurance does not replace security controls.
Map what your agency can access
For each service, write down the platforms you access, the level of permission and who owns the account. Separate your business email and files from client advertising accounts, analytics properties and customer databases. This is a discussion worksheet, not a request to publish credentials or customer information.
Then identify the person who could explain each system to an insurer. In a small agency this may be the founder, an external IT provider or the freelancer responsible for account administration. Avoid guessing about technical controls on an application.
Use three concrete scenarios
- Account access: a staff login is compromised and used to change a client campaign.
- Data handling: a file containing client customer information is exposed.
- Operational interruption: the agency cannot access the systems needed to deliver work.
These are hypothetical briefing examples. For each one, ask which policy section could apply, what loss categories it addresses and what would be outside the scope. Avoid converting a reassuring sales conversation into an assumption that every scenario is insured.
Understand the response process
The NCSC highlights the value of understanding incident support and the security conditions associated with a policy. Ask for the contact process before there is an emergency. Record who may call, which suppliers the insurer expects you to use and what permission is needed before incurring costs.
A practical agency exercise is to imagine that your usual email is unavailable. Where would you find the policy, incident contact and account ownership records? Keep an accessible recovery plan that does not depend on the single system you may lose.
Discuss fraud and overseas work explicitly
The NCSC cautions that some cyber policies do not cover money lost through business email compromise. The ABI also highlights territorial and jurisdictional exclusions. Ask targeted questions about payment instructions, client funds, account misuse and US-connected work instead of treating the word “cyber” as an all-purpose answer.
Write each unresolved issue beside the applicable clause. Ask whether any endorsement is proposed, whether a separate policy should be considered and whether the answer changes for subcontractors. The objective is a clear record, not a list of speculative claims.
Make the application match reality
Check answers about access controls, backups and other security measures with the person responsible for them. If a question is ambiguous, ask the insurer how to answer it. Keep the final submitted application; do not rely on an early draft in which an intended control was described as already implemented.
Use our agency briefing framework to organise the wider conversation about professional services and contracts. Cyber cover should be reviewed alongside those exposures rather than in isolation.
Run a document-access rehearsal
Choose a harmless practice scenario: your normal email is unavailable and you need to find the incident contact. Without simulating an attack or using real client data, check whether the authorised person can locate the policy and the relevant response instructions.
Record only practical gaps, such as a contact list stored exclusively in the unavailable mailbox or uncertainty over which person may call. Resolve those organisational issues with your own team and adviser. Do not contact an emergency response line as a test unless the provider has agreed to that exercise.
This small rehearsal does not establish cyber resilience or insurance compliance. It simply makes the response documents easier to use when time matters.
Sources & further reading
Sources consulted 2026-10-06. Examples and worksheets are original illustrations, not accounts of actual claims.