Cyber policies cover both the costs of responding to an incident and liability to others, and the two sides have different triggers.
First-party coverage. Incident response including forensics, legal counsel, notification, credit monitoring and public relations; business interruption and extra expense; data restoration; and, subject to conditions and sanctions law, extortion payments.
Third-party coverage. Liability for privacy and security failures, regulatory defence and, where insurable, fines; and media liability.
Panel requirements. Most policies require use of approved vendors and counsel, or prior consent. Engaging your own forensic firm before notifying the insurer can forfeit reimbursement.
Conditions precedent. Multi-factor authentication, endpoint detection, backup practices and patching are increasingly warranted in the application. Misstatements in the application are the leading cause of denial, and the application should be answered by people who know the actual configuration.
Waiting periods and sublimits on business interruption, and the distinction between the systems of the insured and those of a service provider, which requires contingent coverage.
Notice promptly on discovery, since incident response costs begin immediately.
Coordination with crime coverage, since funds transfer losses may fall under either or neither.