Clear guidance. Careful arrangements. Support when it matters.

Cornerstone guide · Cyber insurance

Cyber Insurance in South Africa: A Complete Business Guide

A detailed guide to cyber resilience, POPIA context, incident response, insurance sections and the controls businesses should understand.

In brief: Cyber insurance is one element of resilience. It can interact with data, systems, payment processes, third-party allegations and business continuity, but the policy wording and the organisation’s controls remain central.

Education onlyWritten by: Reviewed by: Reviewer pending verification

Map the digital services that keep trading moving

Identify email, cloud services, payment systems, customer data, backups, devices, privileged accounts and critical suppliers. The practical question is what fails first if access, confidentiality or availability is compromised.

Separate response cost from liability

A cyber event can create forensic, legal, restoration, communications and continuity costs for the business, as well as allegations by affected people. Ask which categories are contemplated and whether each has separate limits or conditions.

Understand POPIA response context

The Information Regulator describes a security compromise as a compromise of personal-information security and explains that responsible parties must report relevant compromises to the Regulator and affected data subjects. Legal obligations should be checked with appropriate advisers.

Treat ransomware, fraud and interruption as different

Ransomware, fraudulent payment instructions, social engineering, network interruption and data restoration can involve different definitions, approval requirements, exclusions and sources of loss. Do not assume one broad cyber label covers every digital event.

Controls are underwriting information

Multi-factor authentication, backups, patching, endpoint protection, supplier oversight, access reviews and incident testing can be relevant to a cyber-risk discussion. Keep a truthful record of what exists rather than overstating controls.

Prepare a practical incident plan

Decide who contains the event, preserves evidence, engages technical and legal specialists, communicates internally and checks notification duties. Document decisions and seek the policy’s prescribed notification route before incurring material costs where possible.

Compare sub-limits and retention carefully

Policy sections can have separate limits, waiting periods, retentions, service providers or obligations. Compare the trigger, cap, exclusion and approval wording—not just the headline aggregate limit.

Review after systems or supplier changes

A new payment platform, cloud provider, acquisition, data category, remote-work model or incident can alter the risk and underwriting information. Raise material changes before renewal or a loss.

A sensible next step

If you are reviewing a quote or existing cover, prepare the schedule and questions for an authorised adviser. Do not submit sensitive information through this first-contact website form.

Request an insurance review

Answer library

Common follow-up questions

Browse the full FAQ
Does every business need cyber insurance?

Need depends on systems, data, dependencies, contracts and the losses the business could absorb.

Does cyber cover replace backups and controls?

No. Controls and incident planning remain essential, and may be material to underwriting and claims.

Does cyber insurance cover ransomware?

It may address selected costs only where the wording, facts, controls and legal context allow. Read the relevant section carefully.

What is needed for a cyber quote?

Expect questions about systems, data, security controls, backups, suppliers, incidents and revenue dependencies.

Get help

Need to discuss the insurance question behind the guide?

Start with a short, secure enquiry. You can tell us what you need help with, how you prefer to be contacted and when to call.

Request a callback