Cyber insurance responds to the incident. D&O insurance may become relevant when someone later questions how the company’s leaders prepared, decided, communicated or responded. Technology companies should understand both roles before an event occurs.
Review your cyber and D&O cover | Explore business insurance
A cyber incident usually begins as a technical problem.
A system becomes unavailable. An employee account is compromised. Customer information may have been accessed. A software supplier reports a vulnerability. The immediate priority is to understand what happened, contain it and restore normal operations.
That is primarily the job of the incident-response team and the cyber insurance policy.
The D&O question can come later. An investor, customer, employee or regulator may ask whether management understood the risk, acted on earlier warnings, escalated the incident quickly enough or communicated accurately.
At that point, the conversation is no longer only about the event. It is also about the decisions made by the people leading the company.
One incident, two different insurance jobs
Cyber and D&O insurance should not be treated as interchangeable.
What cyber insurance is designed to do
Depending on the policy, cyber insurance may provide access to:
- Incident-response specialists
- Computer-forensic investigation
- Specialist legal and privacy support
- Data recovery and system restoration
- Notification and communication services
- Business-interruption cover
- Defence against defined privacy or network-security claims
The exact services and costs covered vary. The practical value is that the company can activate an organised response rather than assemble one during the incident.
Where D&O may enter the picture
D&O insurance does not repair a server, investigate malware or restore lost data.
It may become relevant when a covered claim or investigation alleges that an insured director or officer acted improperly in managing the company’s cyber risk or response.
Examples might include allegations that leadership:
- Did not maintain reasonable oversight of a material cyber exposure
- Ignored repeated warnings or requests for resources
- Failed to escalate an incident appropriately
- Made an inaccurate or incomplete statement about the incident
- Continued operating without considering a known vulnerability
- Managed the commercial consequences poorly
An allegation is not proof that a director did anything wrong. Defence costs are one reason D&O cover matters even when a claim is ultimately dismissed.
How a technical event becomes a management issue
Not every cyber incident develops into a D&O matter. The transition usually occurs when attention moves from what happened to what the company’s leaders did about it.
Oversight before the incident
Boards do not need to perform the work of cybersecurity specialists. They do need enough reliable information to understand the company’s important exposures and the progress being made to manage them.
A practical reporting process should show more than the number of blocked attacks. It should help leadership understand critical systems, unresolved vulnerabilities, third-party dependencies, incident readiness and the business consequences of a prolonged outage.
Decisions during the response
Serious incidents create decisions under pressure. Systems may need to be isolated. Services may be suspended. Customers, partners or authorities may need information. External specialists may need to be appointed.
The decision-making route should be established in advance. The technical team should know when an incident moves beyond routine operations and who has authority to make business decisions.
Statements made after the event
Early information is often incomplete. That makes confident public statements risky.
Communications should be coordinated between the technical, management, insurance, communication and appropriate professional teams. Updates should distinguish confirmed facts from matters still being investigated.
Business and financial consequences
A technology incident may interrupt revenue, delay a product launch, affect a major customer or expose a dependency on one supplier.
When the commercial impact becomes significant, the board’s oversight of business continuity, liquidity and stakeholder communication can receive as much attention as the original technical cause.
What the board should have before an incident
Good cyber governance does not mean turning every director into a security engineer. It means creating a dependable route from technical information to business decisions.
A clear reporting rhythm
Agree what the board receives, who presents it and how often. Reporting should identify changes in exposure, overdue actions and decisions that require senior approval.
Defined escalation thresholds
The response plan should explain when the technical team must involve senior management.
Useful thresholds might include the sensitivity of affected data, disruption to a critical service, material customer impact or a significant supplier incident.
A tested response plan
A plan should be practised, not merely saved in a folder.
A tabletop exercise can test who joins the response, how decisions are recorded, how the cyber insurer is contacted and how public or customer communications are approved.
A decision record
Boards often make reasonable choices with incomplete information. A concise record can show what information was available, what advice was received and why a decision was taken.
The aim is not to create defensive paperwork. It is to support a disciplined response and preserve an accurate timeline.
Coordinated insurance
The cyber and D&O policies should be reviewed together. The company should understand where each policy begins, what it excludes and how notification works.
What to do when an incident occurs
1. Activate the response plan
Bring together the technical, operational and management roles identified in the plan.
Use approved communication channels, particularly if company email or collaboration systems may be compromised.
2. Contact the cyber insurer early
Cyber policies often give access to an approved panel of incident-response specialists.
Contacting the insurer promptly can help the company use the available services correctly and avoid incurring costs without the required consent.
3. Keep a reliable decision log
Record key facts, advice, decisions and approvals. Keep the record factual and update it as the investigation develops.
4. Coordinate communications
Customer, employee, investor and public statements should be consistent with what is known at the time.
Avoid speculation and absolute assurances while the investigation remains incomplete.
5. Assess whether D&O notification is also needed
A cyber incident does not automatically produce a D&O claim.
However, a demand, investigation, allegation against management or circumstance that could lead to a claim may engage the D&O policy’s notification provisions.
The company should not assume that notifying the cyber insurer also notifies the D&O insurer. The broker should check the requirements of each policy.
Four D&O wording points to examine
Cyber exclusions
Some D&O policies contain cyber-related exclusions or limitations. Their wording and breadth vary.
Check whether the policy preserves cover for claims against directors and officers even where the underlying event involved technology or data.
Insured persons
Confirm which executives, directors and managers fall within the definition.
Cyber decisions may involve a chief technology officer, chief information-security officer or another senior employee who is not a statutory director.
Investigations
Check when investigation costs become covered. A policy may distinguish between a formal investigation, an interview request and an internal review.
Defence costs and limits
Determine whether defence and investigation costs reduce the total policy limit.
A complex incident can involve several insured people seeking separate advice, so the available limit should be understood in advance.
A practical example
Imagine a software company experiences a prolonged service outage following unauthorised access to a supplier account.
The cyber policy may support the forensic investigation, specialist response, data recovery, communication costs and covered business-interruption loss.
Several weeks later, an investor alleges that senior management had previously received warnings about the supplier dependency but failed to act or describe it accurately.
That later allegation is a different issue. It concerns management decisions and communications. The D&O policy may therefore need to be considered, subject to its definitions, exclusions, notification provisions and other terms.
One event has produced two insurance questions—but each policy still has a different job.
A quick cyber-to-D&O checklist
Before an incident
- Define the board’s cyber reporting process
- Set escalation thresholds
- Test the response plan
- Confirm who can contact the cyber insurer
- Compare cyber and D&O notification requirements
- Review cyber exclusions and investigation cover
During an incident
- Activate the response team
- Notify the cyber insurer promptly
- Record key decisions and advice
- Coordinate external communications
- Escalate any allegation or investigation involving management
After an incident
- Complete the technical and business review
- Record agreed improvements and owners
- Check whether any circumstance requires D&O notification
- Update the response plan
- Review limits, exclusions and insurer panels before renewal
Frequently asked questions
Does D&O insurance cover a cyberattack?
It is not the main policy for responding to the attack itself. Cyber insurance is designed for that role.
D&O may become relevant if a separate covered claim alleges that directors or officers acted improperly in their oversight, decisions, disclosures or response.
Should both insurers be notified after every incident?
Not necessarily. Notification depends on the facts and each policy’s wording.
A serious allegation, investigation or demand involving management should prompt an immediate review of the D&O notification provisions.
Does the board need a cybersecurity expert?
The board needs access to appropriate expertise and reliable reporting.
Directors do not need to perform the technical work themselves, but they should be able to understand the business exposure, ask informed questions and follow important actions.
Can a cyber exclusion remove D&O cover?
It may restrict cover, depending on its wording.
Some exclusions are broad while others preserve protection for individual directors or particular types of claims. The actual clause needs to be reviewed.
Is this relevant only to listed companies?
No. Private technology companies can also face allegations from investors, customers, employees, business partners and regulators after a serious cyber event.
Must the cyber and D&O policies use the same insurer?
No. The policies can be placed with different insurers.
What matters is understanding each policy’s role, exclusions, consent provisions and notification route.
Coordinate the cover before an incident
A cyber incident is easier to manage when the technical response, management responsibilities and insurance contacts have already been connected.
Cynosure helps Cyprus-based technology companies compare cyber and D&O options and examine how the policies work together—from incident response and investigations to management allegations and defence costs.
Request a cyber and D&O review
Cover is subject to the terms, limits, conditions and exclusions of the policy issued. This article provides general insurance information rather than legal or cybersecurity advice.




