Cyber insurance

Cyber risk insurance in Nicosia: cover, costs, and how to choose a policy.

Protect your business against the financial impact of data breaches, ransomware and other covered cyber incidents. We compare suitable options from the insurers we work with.

Get a free quote See all business insurance
Person checking a VPN security app on a tablet

A cyber incident can interrupt your operations, compromise personal data and lead to recovery costs, legal claims or regulatory action. Cyber insurance helps your business respond quickly and manage the financial consequences of a covered event.

We help you compare policy limits, excesses, exclusions and incident-response services so you can choose cover that reflects your systems, data and day-to-day operations.

What can cyber insurance cover?

Cover varies between insurers, but a cyber policy may include the following protection.

Incident response and investigation

Covers specialist assistance to investigate a covered incident, identify what happened and help contain the damage.

Data recovery

Covers eligible costs involved in restoring data, software and computer systems following an insured event.

Business interruption

Covers loss of income and additional expenses when a covered cyber incident prevents your business from operating normally.

Ransomware and cyber extortion

May cover specialist negotiation, incident-response costs and cyber-extortion losses.

Privacy and network-security liability

Covers eligible claims from clients, employees or other affected parties following a failure to protect confidential information or network security.

Legal and regulatory support

Covers legal advice, regulatory investigation costs and defence expenses. Cover for fines or penalties applies only where legally insurable and expressly included in the policy.

What GDPR requires after a personal data breach

Cyprus applies the General Data Protection Regulation alongside Law 125(I)/2018. Compliance is supervised by the Commissioner for Personal Data Protection.

If your business is responsible for determining how personal data is processed, a reportable personal data breach must generally be notified to the relevant data protection authority without undue delay and, where feasible, within 72 hours of becoming aware of it.

Where a breach is likely to create a high risk for the people affected, they may also need to be informed without undue delay. Every personal data breach should be documented, including one that does not require notification.

Not every cybersecurity incident is a personal data breach. Whether notification is required depends on the information affected and the risk to individuals.

GDPR provides for maximum administrative fines of:

  • Up to €10 million or 2% of total worldwide annual turnover for certain infringements
  • Up to €20 million or 4% of total worldwide annual turnover for more serious infringements

The higher amount may apply in each tier. These are maximum limits rather than automatic penalties, and the circumstances of each case are considered.

Who should consider cyber insurance?

Cyber insurance is relevant to more businesses than technology companies alone. You should consider it if your business:

Stores personal, financial or confidential information

Accepts card payments or online orders

Depends on email, cloud services or computer systems

Provides customers with access to an online platform

Allows employees to work remotely

Could lose income if its systems became unavailable

Works with contracts or tenders that require cyber cover

Small businesses can also be targeted by phishing, ransomware, invoice fraud and data theft.

What affects the cost?

Cyber insurance does not have one standard price. Insurers normally assess several aspects of your business.

Business size and turnover
Larger businesses may face greater recovery, liability and business-interruption exposure.
Industry and information held
Healthcare, financial services and other businesses holding sensitive or high volumes of personal data may require more extensive cover.
Cybersecurity controls
Insurers may ask about multi-factor authentication, data backups, software updates, endpoint protection, staff training and access controls.
Dependence on technology
The cost of cover may be affected by how quickly your business would lose income if its own systems—or an important technology supplier—became unavailable.
Previous incidents and claims
Earlier cyber incidents, claims or known security problems can affect eligibility, terms and premiums.
Cover limit and excess
Higher limits and additional policy extensions generally increase the premium. Choosing a larger excess may reduce it, but also increases the amount your business must pay towards a claim.

Why arrange cover through an insurance agent?

Cyber policies can differ significantly between insurers. Important differences may include:

Ransomware restrictions and sublimits
Business-interruption waiting periods
Cover for cloud and technology suppliers
Social-engineering and funds-transfer fraud
Regulatory investigation costs
Approved incident-response providers
Policy excesses, exclusions and territorial limits

We review the options available through the insurers we work with and explain the principal differences before you decide.

Before choosing a policy

Use this checklist when comparing cyber insurance:

Identify the personal and confidential data your business holds
Estimate how an IT outage would affect your income
Check that both first-party costs and third-party claims are covered
Review the business-interruption waiting period
Ask whether cloud-provider and supplier outages are included
Check ransomware limits, conditions and approval requirements
Confirm whether social-engineering fraud requires an extension
Review the policy excess and any separate sublimits
Know which incident-response hotline to call
Maintain tested backups and a documented incident-response plan
Review your cover as your systems, turnover and data exposure grow

Your insurer should normally be contacted as soon as a possible claim is discovered. This is separate from any notification that may be required under GDPR.

Frequently asked questions

There is no general requirement for every Cyprus business to hold cyber insurance. It may nevertheless be required by a client contract, tender, lender or sector-specific arrangement.

Where notification is required, the relevant data protection authority must generally be notified without undue delay and, where feasible, within 72 hours of the business becoming aware of the breach.

No. The GDPR reporting rules concern personal data breaches that meet the relevant risk threshold. Businesses should still document personal data breaches and obtain appropriate legal advice when reporting obligations are unclear.

Not automatically. Some policies refer to regulatory fines or penalties, but cover applies only where legally insurable and subject to the policy's terms, limits and exclusions. Legal and regulatory defence costs may be covered separately.

Many policies can cover aspects of a ransomware incident, including forensic investigation, data restoration, business interruption and specialist negotiation. Ransom payments and related expenses are subject to policy conditions, insurer approval and legal restrictions.

Cyber insurance focuses on incidents involving computer systems, data, privacy and network security. Professional indemnity covers claims arising from mistakes or negligence in professional services or advice. Some incidents may involve both policies.

A small business may still depend heavily on email, cloud services, customer data and online payments. The decision should be based on the potential financial impact of an incident, rather than business size alone.

Follow your incident-response plan, take steps to contain the incident and contact the insurer's cyber-response service as soon as possible. Avoid appointing suppliers, admitting liability or making payments before checking the policy requirements.

Consider your potential recovery costs, lost income, legal expenses, data-notification obligations and exposure to third-party claims. We can help you assess these factors when comparing available limits.

Protect your business before an incident occurs

The right cyber policy provides more than financial protection, it gives you access to experienced specialists when time matters most.

We help you compare incident response, data recovery, business interruption and liability cover based on your business's actual exposure.

Request a free cyber insurance quote

This page provides general information and is not legal advice. Cover is subject to underwriting and the applicable policy's terms, conditions, limits, excesses and exclusions.

You might also need

Areas we serve