Insurance
Cyber liability insurance is a specialized business policy that covers the financial losses and legal liability from a data breach or cyberattack — incident response, customer notification, legal liability, regulatory fines, and sometimes ransomware and business interruption. Standard commercial policies typically exclude these digital risks. The policy lists the insurer, policy number, coverage limits, sublimits, and term, and is increasingly required for businesses handling sensitive data.
Written & maintained by the Granite team · Last updated June 2026
Overview
A cyber policy is issued to a business and renews annually, typically after a security questionnaire or assessment. Coverage splits into first-party (your own costs: forensics, notification, data restoration, crisis management, cyber extortion, lost income) and third-party (liability to customers, partners, and regulators whose data was exposed).
The details that matter most are the sublimits — many policies cap ransomware or social-engineering fraud well below the headline limit — and any required security controls, since failing to maintain a control you attested to on the application can void a claim.
These are the fields Granite reads and extracts automatically the moment you upload one.
How long to keep it
Keep each policy at least 6 years past its term, along with the security questionnaire you submitted.
A breach can be discovered long after it began, and claims hinge on which policy was in force and whether you maintained the required controls. Keeping the policy plus the application you signed protects you if an insurer later questions a representation you made.
Granite reads your cyber policy on upload — carrier, policy number, aggregate limit, sublimits, and term — and files it with your business insurance, alongside the security questionnaire you submitted. It keeps each renewed year so a later-discovered breach maps to the right policy, and reminds you before the term lapses.
FAQ
Sources
This page is checked against primary and authoritative sources:
Drop it in once. Granite reads it, files it, and makes it findable forever — by you today, and by the people who'll need it later.